Re: [Kolab-devel] Erlang security update breaks guam on Debian 10

Lennart Ackermans <[email protected]> Mon, 17 Jul 2023 22:13:15 +0000
Newsgroups gmane.comp.kde.devel.kolab
Message-ID <0102018965ea34ce-f28e464f-f9ca-4010-ba0e-48d9752cc74b-000000__7504.6766594582$1689632495$gmane$org@eu-west-1.amazonses.com>
--===============2099176986395533560==
Content-Type: multipart/alternative;
 boundary=Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1
Content-Transfer-Encoding: 7bit


--Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Debian security packages are usually not in mirrors, so you should also add t=
he official security repo:
http://security.debian.org/debian-security/dists/buster/updates/main/

Lennart


> On 17 Jul 2023, at 23:15, Christoph Erhardt <[email protected]=
> wrote:
>=20
> =EF=BB=BFHi Christian,
>=20
> unfortunately I'm not familiar with the admin side of OBS. The most plausi=
ble=20
> thing I have found would be this settings page:
>=20
>  https://obs.kolabsys.com/repositories/Debian:10.0
>=20
> The mirror URLs configured there lead to a 404, though. It seems there's a=
=20
> path component (`/dists/`) missing in the middle.
>=20
>  Broken: https://mirror.switch.ch/ftp/mirror/debian/buster
> Working: https://mirror.switch.ch/ftp/mirror/debian/dists/buster
>=20
> Maybe this will suffice to trigger a download-on-demand [1] on the next=20=

> package build.
>=20
> Best,
> Christoph
>=20
> [1] https://openbuildservice.org/help/manuals/obs-user-guide/
> cha.obs.concepts.html#concept_dod
>=20
>> On Monday, 17 July 2023 07:12:51 CEST Christian Mollekopf wrote:
>>> On Saturday, 15 July 2023 00:04:21 CEST you wrote:
>>> Hi all,
>>>=20
>>> if my understanding is correct, CVE-2022-37026 allows an authentication
>>> bypass by clients when using certificate-based authentication, while
>>> 'normal' user/ password-based authentication is not affected.
>>>=20
>>> If that is indeed the case, then I believe our quick fix doesn't entail a=
n
>>> immediate risk to Guam users.
>>>=20
>>> Nevertheless, I do feel somewhat strongly about doing things the right
>>> way. In our case this would mean:
>>> 1. Make OBS pull the latest Debian 10 packages, including erlang-base.
>>> 2. Revert the patch that enables ERTS bundling for Guam.
>>> 3. Rebuild Guam.
>>=20
>> I'd rather have it bundled than wake up to our packages no longer startin=
g
>> because the upstream erts package changed, so for unbundling we need to
>> figure which erts version to pin first IMO.
>>> I'm happy to take care of steps 2 and 3, but step 1 needs to be done by a=
n
>>> OBS admin. Christian? Jeroen?
>>=20
>> Do you happen to know how to trigger such an update?
>> I have access, but to me it seems the OBS mostly expects to build agains a=

>> static repository.
>>=20
>> Cheers,
>> Christian
>>=20
>>> Best,
>>> Christoph
>>>=20
>>> _______________________________________________
>>> users mailing list
>>> [email protected]
>>> https://lists.kolab.org/mailman/listinfo/users
>>=20
>> _______________________________________________
>> devel mailing list
>> [email protected]
>> https://lists.kolab.org/mailman/listinfo/devel
>=20
> _______________________________________________
> devel mailing list
> [email protected]
> https://lists.kolab.org/mailman/listinfo/devel

--Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div dir=3D"ltr"></div><div dir=3D"ltr">Deb=
ian security packages are usually not in mirrors, so you should also add the=
 official security repo:</div><div dir=3D"ltr"><a href=3D"http://security.de=
bian.org/debian-security/dists/buster/updates/main/">http://security.debian.=
org/debian-security/dists/buster/updates/main/</a></div><div dir=3D"ltr"><br=
></div><div dir=3D"ltr">Lennart</div><div dir=3D"ltr"><br></div><div dir=3D"=
ltr"><br><div dir=3D"ltr"></div><blockquote type=3D"cite">On 17 Jul 2023, at=
 23:15, Christoph Erhardt &lt;[email protected]&gt; wrote:<br><b=
r></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<sp=
an>Hi Christian,</span><br><span></span><br><span>unfortunately I'm not fami=
liar with the admin side of OBS. The most plausible </span><br><span>thing I=
 have found would be this settings page:</span><br><span></span><br><span> &=
nbsp;https://obs.kolabsys.com/repositories/Debian:10.0</span><br><span></spa=
n><br><span>The mirror URLs configured there lead to a 404, though. It seems=
 there's a </span><br><span>path component (`/dists/`) missing in the middle=
.</span><br><span></span><br><span> &nbsp;Broken: https://mirror.switch.ch/f=
tp/mirror/debian/buster</span><br><span> Working: https://mirror.switch.ch/f=
tp/mirror/debian/dists/buster</span><br><span></span><br><span>Maybe this wi=
ll suffice to trigger a download-on-demand [1] on the next </span><br><span>=
package build.</span><br><span></span><br><span>Best,</span><br><span>Christ=
oph</span><br><span></span><br><span>[1] https://openbuildservice.org/help/m=
anuals/obs-user-guide/</span><br><span>cha.obs.concepts.html#concept_dod</sp=
an><br><span></span><br><span>On Monday, 17 July 2023 07:12:51 CEST Christia=
n Mollekopf wrote:</span><br><blockquote type=3D"cite"><span>On Saturday, 15=
 July 2023 00:04:21 CEST you wrote:</span><br></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>Hi all,</span><br></blockquote></bloc=
kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br>=
</blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite=
"><span>if my understanding is correct, CVE-2022-37026 allows an authenticat=
ion</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot=
e type=3D"cite"><span>bypass by clients when using certificate-based authent=
ication, while</span><br></blockquote></blockquote><blockquote type=3D"cite"=
><blockquote type=3D"cite"><span>'normal' user/ password-based authenticatio=
n is not affected.</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b=
lockquote type=3D"cite"><blockquote type=3D"cite"><span>If that is indeed th=
e case, then I believe our quick fix doesn't entail an</span><br></blockquot=
e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>imm=
ediate risk to Guam users.</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Nevertheless=
, I do feel somewhat strongly about doing things the right</span><br></block=
quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span=
>way. In our case this would mean:</span><br></blockquote></blockquote><bloc=
kquote type=3D"cite"><blockquote type=3D"cite"><span>1. Make OBS pull the la=
test Debian 10 packages, including erlang-base.</span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>2. Revert t=
he patch that enables ERTS bundling for Guam.</span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>3. Rebuild G=
uam.</span><br></blockquote></blockquote><blockquote type=3D"cite"><span></s=
pan><br></blockquote><blockquote type=3D"cite"><span>I'd rather have it bund=
led than wake up to our packages no longer starting</span><br></blockquote><=
blockquote type=3D"cite"><span>because the upstream erts package changed, so=
 for unbundling we need to</span><br></blockquote><blockquote type=3D"cite">=
<span>figure which erts version to pin first IMO.</span><br></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span>I'm happy to take car=
e of steps 2 and 3, but step 1 needs to be done by an</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>OBS a=
dmin. Christian? Jeroen?</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><span></span><br></blockquote><blockquote type=3D"cite"><span>Do y=
ou happen to know how to trigger such an update?</span><br></blockquote><blo=
ckquote type=3D"cite"><span>I have access, but to me it seems the OBS mostly=
 expects to build agains a</span><br></blockquote><blockquote type=3D"cite">=
<span>static repository.</span><br></blockquote><blockquote type=3D"cite"><s=
pan></span><br></blockquote><blockquote type=3D"cite"><span>Cheers,</span><b=
r></blockquote><blockquote type=3D"cite"><span>Christian</span><br></blockqu=
ote><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=
=3D"cite"><blockquote type=3D"cite"><span>Best,</span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Christoph<=
/span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote ty=
pe=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span>_______________________________________=
________</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc=
kquote type=3D"cite"><span>users mailing list</span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>users@lists.=
kolab.org</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span>https://lists.kolab.org/mailman/listinfo/users</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><span></span><b=
r></blockquote><blockquote type=3D"cite"><span>_____________________________=
__________________</span><br></blockquote><blockquote type=3D"cite"><span>de=
vel mailing list</span><br></blockquote><blockquote type=3D"cite"><span>deve=
[email protected]</span><br></blockquote><blockquote type=3D"cite"><span>htt=
ps://lists.kolab.org/mailman/listinfo/devel</span><br></blockquote><span></s=
pan><br><span>_______________________________________________</span><br><spa=
n>devel mailing list</span><br><span>[email protected]</span><br><span>h=
ttps://lists.kolab.org/mailman/listinfo/devel</span></div></blockquote></bod=
y></html>=

--Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1--

--===============2099176986395533560==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
devel mailing list
[email protected]
https://lists.kolab.org/mailman/listinfo/devel
--===============2099176986395533560==--