Re: [Security-Discuss] 2007.0 shorewall & ifw problem (bug?)

Antonio <[email protected]> Sun, 7 Jan 2007 17:44:08 +0100
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
First, thanks for you reply, and sorry for annoying you and this ml during 
this holiday days...

> Our policy (with a few "special" exceptions) is to backport
> bugfix/patches to the version released with a particular Mandriva
> release. There is a "backports" media now where the maintainer is free
> to put new versions of software, but it is unsupported.
I know about mandriva policy, but I checked the shorewall rpm package I have 
and I see that it was built on 30 august 2006, so it can't contain bugfixes 
that have been released after that date. This mean that mandriva has a 
buggish firewall.
I know that mandriva 2007 is a desktop user oriented distro, so someone can 
tell me that if I want a more security focused distro I can move to another 
one, but well it is another story: I'm not writing here to say hey, I have a 
problem, come here and solve it up, I'm writing here since I believe in the 
open source spirit, and since I see something I think is wrong, I want let 
you know; if mandriva isn't interested of my opinion, can simply redirect my 
mail to /dev/null.
So, to say what I think, I think that a firewall is security related piece of 
software, and since mandriva has chosen shorewall, should keep it up to date 
as all the other security related software. In other words, shorewall should 
be considered like the "few special exceptions" to the backport policy, 
backporting changes for example from 3.2.7 to 3.2.3 is quite nonsensical.

> Bugfix updates are initiated by the package maintainer, for the most
> part.  Posting a bug on the package in bugzilla should trigger the
> activities that would lead to this happening.
>
> The security team generally initiates an update in response to specific
> public or privately reported security issues in software, rather than
> a general "this software doesn't work" scenario.
In this case I'm not sure If the bug should be posted in mandriva bugzilla or 
directly to the shorewall ml, however before post a bug to shorewall ml I 
think is best to check if the bug is still there in the latest release. 
Should I post a bug to mandriva bugzilla and then if needed someone from 
mandriva will post a bug to shorewall ml? Should I post directly to shorewall 
ml? What to do? Could you please clarify this point?

> I don't personally use shorewall or ifw, so I can't really comment on
> the issues you're having with them.
I'm curious about what firewall you use on your home machine, I'd like to have 
a real time alert notification, but actually ifw seem not working (probably 
kernel issues), and firestarter seem to me a bit dead (not updated since 
2005).

Antonio.
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________