Re: [Security-Discuss] 2007.0 shorewall & ifw problem (bug?)
Antonio <[email protected]> Sun, 7 Jan 2007 17:44:08 +0100
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
First, thanks for you reply, and sorry for annoying you and this ml during this holiday days... > Our policy (with a few "special" exceptions) is to backport > bugfix/patches to the version released with a particular Mandriva > release. There is a "backports" media now where the maintainer is free > to put new versions of software, but it is unsupported. I know about mandriva policy, but I checked the shorewall rpm package I have and I see that it was built on 30 august 2006, so it can't contain bugfixes that have been released after that date. This mean that mandriva has a buggish firewall. I know that mandriva 2007 is a desktop user oriented distro, so someone can tell me that if I want a more security focused distro I can move to another one, but well it is another story: I'm not writing here to say hey, I have a problem, come here and solve it up, I'm writing here since I believe in the open source spirit, and since I see something I think is wrong, I want let you know; if mandriva isn't interested of my opinion, can simply redirect my mail to /dev/null. So, to say what I think, I think that a firewall is security related piece of software, and since mandriva has chosen shorewall, should keep it up to date as all the other security related software. In other words, shorewall should be considered like the "few special exceptions" to the backport policy, backporting changes for example from 3.2.7 to 3.2.3 is quite nonsensical. > Bugfix updates are initiated by the package maintainer, for the most > part. Posting a bug on the package in bugzilla should trigger the > activities that would lead to this happening. > > The security team generally initiates an update in response to specific > public or privately reported security issues in software, rather than > a general "this software doesn't work" scenario. In this case I'm not sure If the bug should be posted in mandriva bugzilla or directly to the shorewall ml, however before post a bug to shorewall ml I think is best to check if the bug is still there in the latest release. Should I post a bug to mandriva bugzilla and then if needed someone from mandriva will post a bug to shorewall ml? Should I post directly to shorewall ml? What to do? Could you please clarify this point? > I don't personally use shorewall or ifw, so I can't really comment on > the issues you're having with them. I'm curious about what firewall you use on your home machine, I'd like to have a real time alert notification, but actually ifw seem not working (probably kernel issues), and firestarter seem to me a bit dead (not updated since 2005). Antonio. ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________