Re: apache2 DSA considerations for etch

2006-11-14 Thread Steinar H. Gunderson
On Wed, Nov 15, 2006 at 12:46:41AM +0100, Moritz Muehlenhoff wrote: > Is this ready for a stable release? Despite the description; yes, I believe so. We've been running the Apache 2.0 version in production for over a year now, and so does NTNU (serving millions of hits every week). I'm not willin

Re: apache2 DSA considerations for etch

2006-11-14 Thread Moritz Muehlenhoff
Hi Steinar, > assuming the hole isn't specific to -mpm-itk, of course). > > Would this be OK for the security team? (I do not know of any objections from > the debian-apache team; after all, apache2-src was added explicitly to > support apache2-mpm-itk, as the debian-apache team currently does not

Re: user-mode-linux too [was: Re: apache2 DSA considerations for etch]

2006-11-14 Thread Mattia Dongili
On Tue, Nov 14, 2006 at 08:09:37PM +0100, Martin Schulze wrote: > Mattia Dongili wrote: > > On Tue, Nov 14, 2006 at 08:06:38AM +0100, Joey Schulze wrote: > > [...] > > > *sigh* That would've been the best solution. > > > > > > I'd say this is ok, however, please watch security updates as the secu

Re: user-mode-linux too [was: Re: apache2 DSA considerations for etch]

2006-11-14 Thread Martin Schulze
Mattia Dongili wrote: > On Tue, Nov 14, 2006 at 08:06:38AM +0100, Joey Schulze wrote: > [...] > > *sigh* That would've been the best solution. > > > > I'd say this is ok, however, please watch security updates as the security > > team will probably forget to update apache2-mpm-itk when apache2 ha

user-mode-linux too [was: Re: apache2 DSA considerations for etch]

2006-11-14 Thread Mattia Dongili
On Tue, Nov 14, 2006 at 08:06:38AM +0100, Joey Schulze wrote: [...] > *sigh* That would've been the best solution. > > I'd say this is ok, however, please watch security updates as the security > team will probably forget to update apache2-mpm-itk when apache2 has been > updated. (->Murphy) Ehrm

Re: apache2 DSA considerations for etch

2006-11-14 Thread Steinar H. Gunderson
On Tue, Nov 14, 2006 at 08:06:38AM +0100, Joey Schulze wrote: > I assume that you are part of the Debian Apache Maintainers and hence > should notice when the security team updates Apache 2/2.2. No, I am not. > Why isn't apache2-mpm-itk built as part of the Apache 2 package? Because the Apache t

Re: apache2 DSA considerations for etch

2006-11-13 Thread Joey Schulze
I assume that you are part of the Debian Apache Maintainers and hence should notice when the security team updates Apache 2/2.2. Why isn't apache2-mpm-itk built as part of the Apache 2 package? Steinar H. Gunderson wrote: > I was asked to check this with you before the RMs would let apache2-mpm-i

apache2 DSA considerations for etch

2006-11-13 Thread Steinar H. Gunderson
Hi, I was asked to check this with you before the RMs would let apache2-mpm-itk into etch. apache2-mpm-itk is an unofficial MPM for Apache 2.0 and up (although it has only ever existed in Debian for 2.2). It basically builds by depending on apache2-src, extracting that, patching itself in, buildi