On 2017-06-27 21:02:21, Jens Korte wrote:
> On Tue, 27 Jun 2017 14:35:09 -0400
> Antoine Beaupré wrote:
>
>> On 2017-06-27 21:17:33, Apollon Oikonomopoulos wrote:
>> > On 20:08 Tue 27 Jun , Guido Günther wrote:
>> >> That sounds good to me especially if it's possible to toggle this so
>> >> o
On Tue, 27 Jun 2017 14:35:09 -0400
Antoine Beaupré wrote:
> On 2017-06-27 21:17:33, Apollon Oikonomopoulos wrote:
> > On 20:08 Tue 27 Jun , Guido Günther wrote:
> >> That sounds good to me especially if it's possible to toggle this so
> >> one
> >> can e.g. first update all clients then disa
On 2017-06-27 21:17:33, Apollon Oikonomopoulos wrote:
> On 20:08 Tue 27 Jun , Guido Günther wrote:
>> That sounds good to me especially if it's possible to toggle this so
>> one
>> can e.g. first update all clients then disable accepting YAML on the
>> server.
>
> My thoughts exactly, it will
On 2017-06-09 10:22:37, Rhonda D'Vine wrote:
> Dear Ola,
>
> this is on my board. The issue isn't that pressing, and I want to fix
> it for stretch and jessie too, and only do the update for wheezy after
> those got approved (which I expect). If it won't be approved for
> stretch and jessie
On 20:08 Tue 27 Jun , Guido Günther wrote:
> That sounds good to me especially if it's possible to toggle this so
> one
> can e.g. first update all clients then disable accepting YAML on the
> server.
My thoughts exactly, it will be great if there's a configuration option
for turning off YAM
For the record, I have marked this as "not-affected" in the security
tracker. During my tests in April, I wasn't able to reproduce the issue
in a Wheezy virtual machine. Furthermore, the fix is very intrusive and
would be quite difficult to backport.
A.
On 2017-04-26 12:23:16, Antoine Beaupre wro
On 2017-06-27 20:08:07, Guido Günther wrote:
> On Tue, Jun 27, 2017 at 12:52:52PM -0400, Antoine Beaupré wrote:
>> On 2017-06-27 11:53:24, Antoine Beaupré wrote:
>> > Are you sure of this? From what I can tell agents haven't been sending
>> > YAML in a long time. If I understand things correctly, f
On Tue, Jun 27, 2017 at 12:52:52PM -0400, Antoine Beaupré wrote:
> On 2017-06-27 11:53:24, Antoine Beaupré wrote:
> > Are you sure of this? From what I can tell agents haven't been sending
> > YAML in a long time. If I understand things correctly, facts are sent in
> > a format defined by the `pref
Hi,
Considering the [discussion][1] surrounding the possibility of
backporting the upstream patch for [CVE-2017-2295][2], I have made
Puppet packages available for testing at the [usual location][3]
(debdiff attached).
[1]: https://lists.debian.org/20170524095154.5ooj6inyeg643...@marvin.dmesg.gr
On 2017-06-27 11:53:24, Antoine Beaupré wrote:
> Are you sure of this? From what I can tell agents haven't been sending
> YAML in a long time. If I understand things correctly, facts are sent in
> a format defined by the `preferred_serialization_format`, which
> currently (in wheezy) defaults to `p
On 2017-05-24 12:51:54, Apollon Oikonomopoulos wrote:
> On 23:44 Mon 22 May , Apollon Oikonomopoulos wrote:
>> On 22:53 Sun 21 May , Ola Lundqvist wrote:
>> > Dear maintainer(s),
>> >
>> > The Debian LTS team would like to fix the security issues which are
>> > currently open in the Wheezy
On Tue, Jun 27, 2017 at 11:08:03AM -0400, Antoine Beaupré wrote:
>
> Oh, I can grok them alright - this apache update was easy compared to
> the previous ones (e.g. the Host: header hack was a nightmare). I'm just
> amazed that they *deprecate* an API in a patch release like this.
>
Yeah, that se
On 2017-06-27 10:24:26, Roberto C. Sánchez wrote:
> On Tue, Jun 27, 2017 at 10:17:46AM -0400, Antoine Beaupré wrote:
>> On 2017-06-25 16:56:46, Roberto C. Sánchez wrote:
>> > Hi all,
>> >
>> > I have prepared an update for apache2 and I would like to request some
>> > testing. The packages are her
On 2017-03-27 19:12:22, Michael Shuler wrote:
> On 03/25/2017 03:32 AM, Paul Wise wrote:
>> Hi all,
>>
>> I note that there have been some CA removals and additions that would
>> be nice to have in wheezy, in particular the ISRG Root for LE, thoughts?
>
> I need to fix up the jessie PU I have fil
On Tue, Jun 27, 2017 at 10:17:46AM -0400, Antoine Beaupré wrote:
> On 2017-06-25 16:56:46, Roberto C. Sánchez wrote:
> > Hi all,
> >
> > I have prepared an update for apache2 and I would like to request some
> > testing. The packages are here:
> >
> > https://people.debian.org/~roberto/apache2_2.2
On 2017-06-25 16:56:46, Roberto C. Sánchez wrote:
> Hi all,
>
> I have prepared an update for apache2 and I would like to request some
> testing. The packages are here:
>
> https://people.debian.org/~roberto/apache2_2.2.22-13+deb7u9.dsc
> https://people.debian.org/~roberto/apache2_2.2.22-13+deb7u9
16 matches
Mail list logo