Secure update of /usr/src
文鳥
bunchou at googlemail.com
Sun Jan 13 09:26:42 PST 2008
08/01/13 に Erik Cederstrand<erik at cederstrand.dk> さんは書きました:
> 文鳥 wrote:
> > 2008/1/13, Erik Cederstrand <erik at cederstrand.dk>:
> >> 文鳥 wrote:
> >>> Hello all,
> >>>
> >>> is there any way to securely follow the STABLE branch of FreeBSD, e.g.
> >>> a cryptographically signed distribution method like portsnap? Afaik,
> >>> the usual update methods (CVSup, etc.) do not include any
> >>> authentication / integrity checking. Am I missing something here?
> >> freebsd-update(8) is portsnap for the base system. However, you can only
> >> follow RELEASE branches, not STABLE.
> >>
> >> Erik
> >>
> > Thanks for the reply. Unfortunately, I need to follow STABLE and (to
> > be policy-compliant) at the same time make sure that the code has not
> > been tampered with by, for example, checking the signature. Is there a
> > way to do this for STABLE?
>
> Just making sure; you are aware that STABLE only means "stable API" and
> is in fact the cutting edge for the 6.x line, right? If you want to
> follow a stable release branch, as in "is tested, supported by security
> team, and will not break in interesting ways", RELEASE is the branch to
> follow. freebsd-update(8) will fetch the security updates for you as
> they are applied to the RELEASE branch.
>
> Erik
>
Yes, I am aware of that fact. However, 7.x STABLE is the only version
apart from CURRENT that I was able to get working reliably on the
hardware in question. And alas, even though the system in question is
used for testing only,I am still bound by the company security policy
in this matter... Guess I will have to wait until 7.0 is released.
Thanks for your help in this matter.
More information about the freebsd-questions
mailing list