Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-13 Thread jere
still limited to be widely accepted in large production environments. j. Ivan Voras wrote: Tobias Roth wrote: >> On Wed, Oct 12, 2005 at 12:09:53PM +0200, jere wrote: And you cannot expect the port maintainers to backport security fixes if the upstream provider chose to release the fix only to

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-12 Thread jere
a clear chioce to manage only ports security issues but I think it's primarily due to lack of port maintainers. Does anyone have other thoughts about this? j. Timothy Smith wrote: jere wrote: unfortunately, this is the dark side of FreeBSD security patch management :) and I think also

Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

2005-10-11 Thread jere
unfortunately, this is the dark side of FreeBSD security patch management :) and I think also the main reason FreeBSD isn't so widely deployed into enterprise environments. It's ok for hacking or managing few boxes but try to imagine how to manage security on hundreds of them this way. :( on