Re: [Kolab-devel] Erlang security update breaks guam on Debian 10
Lennart Ackermans <[email protected]> Mon, 17 Jul 2023 22:13:15 +0000
| Newsgroups | gmane.comp.kde.devel.kroupware |
|---|---|
| Message-ID | <0102018965ea34ce-f28e464f-f9ca-4010-ba0e-48d9752cc74b-000000__42470.9240834758$1689632501$gmane$org@eu-west-1.amazonses.com> |
--===============7787150357730731211== Content-Type: multipart/alternative; boundary=Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1 Content-Transfer-Encoding: 7bit --Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Debian security packages are usually not in mirrors, so you should also add t= he official security repo: http://security.debian.org/debian-security/dists/buster/updates/main/ Lennart > On 17 Jul 2023, at 23:15, Christoph Erhardt <[email protected]= > wrote: >=20 > =EF=BB=BFHi Christian, >=20 > unfortunately I'm not familiar with the admin side of OBS. The most plausi= ble=20 > thing I have found would be this settings page: >=20 > https://obs.kolabsys.com/repositories/Debian:10.0 >=20 > The mirror URLs configured there lead to a 404, though. It seems there's a= =20 > path component (`/dists/`) missing in the middle. >=20 > Broken: https://mirror.switch.ch/ftp/mirror/debian/buster > Working: https://mirror.switch.ch/ftp/mirror/debian/dists/buster >=20 > Maybe this will suffice to trigger a download-on-demand [1] on the next=20= > package build. >=20 > Best, > Christoph >=20 > [1] https://openbuildservice.org/help/manuals/obs-user-guide/ > cha.obs.concepts.html#concept_dod >=20 >> On Monday, 17 July 2023 07:12:51 CEST Christian Mollekopf wrote: >>> On Saturday, 15 July 2023 00:04:21 CEST you wrote: >>> Hi all, >>>=20 >>> if my understanding is correct, CVE-2022-37026 allows an authentication >>> bypass by clients when using certificate-based authentication, while >>> 'normal' user/ password-based authentication is not affected. >>>=20 >>> If that is indeed the case, then I believe our quick fix doesn't entail a= n >>> immediate risk to Guam users. >>>=20 >>> Nevertheless, I do feel somewhat strongly about doing things the right >>> way. In our case this would mean: >>> 1. Make OBS pull the latest Debian 10 packages, including erlang-base. >>> 2. Revert the patch that enables ERTS bundling for Guam. >>> 3. Rebuild Guam. >>=20 >> I'd rather have it bundled than wake up to our packages no longer startin= g >> because the upstream erts package changed, so for unbundling we need to >> figure which erts version to pin first IMO. >>> I'm happy to take care of steps 2 and 3, but step 1 needs to be done by a= n >>> OBS admin. Christian? Jeroen? >>=20 >> Do you happen to know how to trigger such an update? >> I have access, but to me it seems the OBS mostly expects to build agains a= >> static repository. >>=20 >> Cheers, >> Christian >>=20 >>> Best, >>> Christoph >>>=20 >>> _______________________________________________ >>> users mailing list >>> [email protected] >>> https://lists.kolab.org/mailman/listinfo/users >>=20 >> _______________________________________________ >> devel mailing list >> [email protected] >> https://lists.kolab.org/mailman/listinfo/devel >=20 > _______________________________________________ > devel mailing list > [email protected] > https://lists.kolab.org/mailman/listinfo/devel --Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><div dir=3D"ltr"></div><div dir=3D"ltr">Deb= ian security packages are usually not in mirrors, so you should also add the= official security repo:</div><div dir=3D"ltr"><a href=3D"http://security.de= bian.org/debian-security/dists/buster/updates/main/">http://security.debian.= org/debian-security/dists/buster/updates/main/</a></div><div dir=3D"ltr"><br= ></div><div dir=3D"ltr">Lennart</div><div dir=3D"ltr"><br></div><div dir=3D"= ltr"><br><div dir=3D"ltr"></div><blockquote type=3D"cite">On 17 Jul 2023, at= 23:15, Christoph Erhardt <[email protected]> wrote:<br><b= r></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<sp= an>Hi Christian,</span><br><span></span><br><span>unfortunately I'm not fami= liar with the admin side of OBS. The most plausible </span><br><span>thing I= have found would be this settings page:</span><br><span></span><br><span> &= nbsp;https://obs.kolabsys.com/repositories/Debian:10.0</span><br><span></spa= n><br><span>The mirror URLs configured there lead to a 404, though. It seems= there's a </span><br><span>path component (`/dists/`) missing in the middle= .</span><br><span></span><br><span> Broken: https://mirror.switch.ch/f= tp/mirror/debian/buster</span><br><span> Working: https://mirror.switch.ch/f= tp/mirror/debian/dists/buster</span><br><span></span><br><span>Maybe this wi= ll suffice to trigger a download-on-demand [1] on the next </span><br><span>= package build.</span><br><span></span><br><span>Best,</span><br><span>Christ= oph</span><br><span></span><br><span>[1] https://openbuildservice.org/help/m= anuals/obs-user-guide/</span><br><span>cha.obs.concepts.html#concept_dod</sp= an><br><span></span><br><span>On Monday, 17 July 2023 07:12:51 CEST Christia= n Mollekopf wrote:</span><br><blockquote type=3D"cite"><span>On Saturday, 15= July 2023 00:04:21 CEST you wrote:</span><br></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>Hi all,</span><br></blockquote></bloc= kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br>= </blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite= "><span>if my understanding is correct, CVE-2022-37026 allows an authenticat= ion</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot= e type=3D"cite"><span>bypass by clients when using certificate-based authent= ication, while</span><br></blockquote></blockquote><blockquote type=3D"cite"= ><blockquote type=3D"cite"><span>'normal' user/ password-based authenticatio= n is not affected.</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b= lockquote type=3D"cite"><blockquote type=3D"cite"><span>If that is indeed th= e case, then I believe our quick fix doesn't entail an</span><br></blockquot= e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>imm= ediate risk to Guam users.</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Nevertheless= , I do feel somewhat strongly about doing things the right</span><br></block= quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span= >way. In our case this would mean:</span><br></blockquote></blockquote><bloc= kquote type=3D"cite"><blockquote type=3D"cite"><span>1. Make OBS pull the la= test Debian 10 packages, including erlang-base.</span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>2. Revert t= he patch that enables ERTS bundling for Guam.</span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>3. Rebuild G= uam.</span><br></blockquote></blockquote><blockquote type=3D"cite"><span></s= pan><br></blockquote><blockquote type=3D"cite"><span>I'd rather have it bund= led than wake up to our packages no longer starting</span><br></blockquote><= blockquote type=3D"cite"><span>because the upstream erts package changed, so= for unbundling we need to</span><br></blockquote><blockquote type=3D"cite">= <span>figure which erts version to pin first IMO.</span><br></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span>I'm happy to take car= e of steps 2 and 3, but step 1 needs to be done by an</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>OBS a= dmin. Christian? Jeroen?</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><span></span><br></blockquote><blockquote type=3D"cite"><span>Do y= ou happen to know how to trigger such an update?</span><br></blockquote><blo= ckquote type=3D"cite"><span>I have access, but to me it seems the OBS mostly= expects to build agains a</span><br></blockquote><blockquote type=3D"cite">= <span>static repository.</span><br></blockquote><blockquote type=3D"cite"><s= pan></span><br></blockquote><blockquote type=3D"cite"><span>Cheers,</span><b= r></blockquote><blockquote type=3D"cite"><span>Christian</span><br></blockqu= ote><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type= =3D"cite"><blockquote type=3D"cite"><span>Best,</span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Christoph<= /span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote ty= pe=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span>_______________________________________= ________</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc= kquote type=3D"cite"><span>users mailing list</span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>users@lists.= kolab.org</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span>https://lists.kolab.org/mailman/listinfo/users</= span><br></blockquote></blockquote><blockquote type=3D"cite"><span></span><b= r></blockquote><blockquote type=3D"cite"><span>_____________________________= __________________</span><br></blockquote><blockquote type=3D"cite"><span>de= vel mailing list</span><br></blockquote><blockquote type=3D"cite"><span>deve= [email protected]</span><br></blockquote><blockquote type=3D"cite"><span>htt= ps://lists.kolab.org/mailman/listinfo/devel</span><br></blockquote><span></s= pan><br><span>_______________________________________________</span><br><spa= n>devel mailing list</span><br><span>[email protected]</span><br><span>h= ttps://lists.kolab.org/mailman/listinfo/devel</span></div></blockquote></bod= y></html>= --Apple-Mail-F53BA13A-8A60-4211-96B1-BDB3CC6318F1-- --===============7787150357730731211== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ users mailing list [email protected] https://lists.kolab.org/mailman/listinfo/users --===============7787150357730731211==--