Re: Re: security enhanced debian branch?
Javier Fernández-Sanguino Peña <[email protected]> Sun, 21 Dec 2003 10:39:36 +0100
| Newsgroups | gmane.linux.debian.devel.general,gmane.linux.adamantix.devel |
|---|---|
| Message-ID | <[email protected]> |
--+HP7ph2BbKc20aGI Content-Type: text/plain; charset=iso-8859-15 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Dec 19, 2003 at 01:03:17PM +0100, Peter Busser wrote: > > I'd be interested in hearing what the Adamantix people believed to be > > a reasonable approach for merging stuff back - but it does seem that > > they should be the people to write the plan, after all they know what > > they're working on - whereas outside Debian developers don't! >=20 > Ok, maybe we can write such a plan together? I mean, sure, I know what is > being worked on in Adamantix. That is simple technical stuff. But I hardl= y know (...) Ok. How about this (for the kernel changes): 1.- Upload packages for the kernel changes provided by Adamantix in a=20 kernel-patch-adamantix (DONE, sitting in NEW at the moment, and will be=20 included as soon as ftp-admins get around to do it) 2.- Upload the paxtest suite so people can test PaX-enabled kernels and=20 Exec-shield enabled kernels (DONE, same as above) 3.- Upload the rsbac utilities (DONE, same as above) 4.- Ask base-passwd to provide a 'debian-sec' (security officer) for=20 consistency between 1) and 3) in order to have a stable UID (not done) 5.- Upload sample RSBAC policies, rsbac-secpolicy and rsbac-adamantix are= =20 good candidates here (not uploaded, but I have packages built locally and= =20 I'm waiting for rsbac-adamantix to stabilise and would also like to audit= =20 the code, i.e. rsbacinit there) 6.- Have users test PaX-enabled kernels and RSBAC-enabled kernels. 7.- Fix bugs and contribute upstream those that belong there. 8.- Consider providing kernel-image packages with 6 enabled by default that= =20 could be used in a standard installation of Debian. How does it sound? Of course the SSP stuff can run in parallel, I'll leave= =20 Steve that. Javi --+HP7ph2BbKc20aGI Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/5WpXsandgtyBSwkRAjneAJ45i1Vtu9cCTx8uLReGsgoAMlwDCgCcDk0z TWTNUvloLsjNHiQymmXWYUU= =TQrZ -----END PGP SIGNATURE----- --+HP7ph2BbKc20aGI--