看板FB_security
標 題Re: FreeBSD's heartbleed response
發信站NCTU CS FreeBSD Server (Wed Apr 9 07:18:21 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--dntjKxN5hicMLjcjRIhnP0RjwabLoA6os
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable
Do we need to fetch them from the Internet?
Local packages can do the job, nope? But it will lead to kind of
bootstrapping=85 or everything as packages bootstrapped once for all.
And yes, it will not be some pie (a french stock phrase meaning it will
be hard, translated word for word :) ).
On 08/04/2014 21:26, John-Mark Gurney wrote:
> Florent Peterschmitt wrote this message on Tue, Apr 08, 2014 at 20:39 +=
0200:
>> On 08/04/2014 19:46, Mark Boolootian wrote:
>>> While it may not be quite what you're looking for, ports contains
>>> OpenSSL 1.0.1g.
>>
>> Why not moving critical parts of the basesystem to ports, that will be=
>> installed at system installation of course?
>=20
> Because we have programs in base that depend upon OpenSSL... so,
> moving OpenSSL out of base is not really an option, unless you want
> to remove fetch, hostapd, pkg, and wpa_supplicant from the base system,=
> we are stuck w/ OpenSSL in base...
>=20
> yes, there is pkg there, how are you going to fetch packages to install=
> if you don't have that?
>=20
> btw, all found w/ ldd /usr/bin/* /usr/sbin/* 2>/dev/null | less and
> searching for libssl...
>=20
--dntjKxN5hicMLjcjRIhnP0RjwabLoA6os
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Using GnuPG with Icedove -
http://www.enigmail.net/
iQIcBAEBAgAGBQJTRGedAAoJEFr01BkajbiBIPoP/RkdZ6kwv5w4z/WDGLmwk6Yp
fLpDxRuzF4Z/7Qt4BBWmf5wMjAJZieJmO3QGfQwIuPVwjLAIWMbWdEX0eOCMWZDh
1Y3PiCrKJZYCHNSSpEBtZScwpi/RgEBbF30Jq7ZW5W0s2/veqQLB4/ChcSqcF6Y3
SR2CfsV3DaEQ8rs3LN2mDq5LUJ6tzub70UbOT8fW53ufm4PleTQjcsiBGj6uCV78
mfM8bJSn/FgvPpoSDfn/8/eOOXrz9KUT4xP5rfrxgNEmNfPTTEDv8kC7ItFvOj/w
CLllkDJOXjgJoCBzVd6Mi3GyiwxDuZ4vrrjoC2DckeWwRYwABAjJuIr40Om8jI4q
8TNC7Ol9Sbu3b90VRufgXx+cyqMXxEVQzVUtJI0uJnYLdu/sTxLc6oiqAM+ayQTz
G61lVcFZkcrnipj8w6fO4yD4OlFCLEzAxgAFu3mkwXzoKBPsiFi2FZkLLvRIPjFT
Fxe3U3wq5ne0lG7MIXKH592L/RCPUm5p+WYEovYyhrGC3CCJOYCx7nMoFff1JAQm
v6W67hetnonh6k2cd59PABlVyUM+wKdhmDFxKPuXy6/0nmn/7fmbTG9KOc/BlBa3
onuarPsNTe3ngQvnOQscof/e+gUb2Ed6Bi2OE6WaawdzR1LS/jotLcbH09h3fgK0
CrkqK2HxpXxtTqa7c5im
=iyg9
-----END PGP SIGNATURE-----
--dntjKxN5hicMLjcjRIhnP0RjwabLoA6os--