security patches and release number question

Duane Winner dwinner at dwinner.net
Thu Oct 4 05:29:33 PDT 2007


Hi,

Question about patch numbers and applying patches:

Last night, I got the openssl security advisory, and this morning am 
starting to patch my servers.

I've always just done a "make build world; make build kernel; make 
install kernel; make install world" when I've need to patch.

Today, however, I thought I would just try to do the patch on the 
openssl libs as described in the advisory. I think it worked just fine, 
but my question is this:

How do I keep track of which systems I've patched if I just do a "patch 
< patchfile" instead of the whole world/kernel thing?

uname -an still shows 6.2-RELEASE-p7 instead of "p8"; I use this to keep 
track of which servers I've patched and which I haven't.

Is there a way to handle this?

Thanks,
DW



More information about the freebsd-questions mailing list