Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Lars Kurth
Agree with George On 19 Jan 2015, at 15:55, George Dunlap wrote: > On Mon, Jan 19, 2015 at 1:38 PM, Ian Jackson > wrote: >> Lars Kurth writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment >> with Security Team Permission"): >>> On 19 Jan 2015,

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread George Dunlap
On Mon, Jan 19, 2015 at 1:38 PM, Ian Jackson wrote: > Lars Kurth writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment > with Security Team Permission"): >> On 19 Jan 2015, at 10:20, Jan Beulich wrote: >> > On 16.01.15 at 20:52, wrote: >> >&

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Campbell
On Mon, 2015-01-19 at 13:38 +, Ian Jackson wrote: > Lars Kurth writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment > with Security Team Permission"): > > On 19 Jan 2015, at 10:20, Jan Beulich wrote: > > > On 16.01.15 at 20:52, wrote: > >

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Jan Beulich
>>> On 19.01.15 at 13:36, wrote: > On Mon, 2015-01-19 at 10:20 +, Jan Beulich wrote: >> >>> On 16.01.15 at 20:52, wrote: >> > --- a/security_vulnerability_process.html >> > +++ b/security_vulnerability_process.html >> > @@ -212,6 +212,17 @@ following: >> >The assigned XSA number >> >T

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Jackson
Lars Kurth writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission"): > On 19 Jan 2015, at 10:20, Jan Beulich wrote: > > On 16.01.15 at 20:52, wrote: > >> +List members may, if (and only if) the Security Team grants > >&g

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Campbell
On Mon, 2015-01-19 at 13:08 +, Ian Jackson wrote: > Ian Campbell writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment > with Security Team Permission"): > > On Fri, 2015-01-16 at 19:52 +, Ian Jackson wrote: > > > +List members may, if (and on

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Jackson
Ian Campbell writes ("Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission"): > On Fri, 2015-01-16 at 19:52 +, Ian Jackson wrote: > > +List members may, if (and only if) the Security Team grants > > +permission, deploy fixed ve

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Campbell
On Mon, 2015-01-19 at 10:20 +, Jan Beulich wrote: > >>> On 16.01.15 at 20:52, wrote: > > --- a/security_vulnerability_process.html > > +++ b/security_vulnerability_process.html > > @@ -212,6 +212,17 @@ following: > >The assigned XSA number > >The planned disclosure date > > > > +List

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Ian Campbell
On Fri, 2015-01-16 at 19:52 +, Ian Jackson wrote: > Permitting deployment during embargo seemed to have rough consensus on > the principle. We seemed to be converging on the idea that the > Security Team should explicitly set deployment restrictions for each > set of patches. > > Signed-off-b

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Lars Kurth
On 19 Jan 2015, at 10:20, Jan Beulich wrote: On 16.01.15 at 20:52, wrote: >> +List members may, if (and only if) the Security Team grants >> +permission, deploy fixed versions during the embargo. Permission for > > Better: List members may deploy fixed versions during the embargo, if (.

Re: [Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-19 Thread Jan Beulich
>>> On 16.01.15 at 20:52, wrote: > --- a/security_vulnerability_process.html > +++ b/security_vulnerability_process.html > @@ -212,6 +212,17 @@ following: >The assigned XSA number >The planned disclosure date > > +List members may, if (and only if) the Security Team grants > +permission,

[Xen-devel] [PATCH SECURITY-POLICY 3/9] Deployment with Security Team Permission

2015-01-16 Thread Ian Jackson
Permitting deployment during embargo seemed to have rough consensus on the principle. We seemed to be converging on the idea that the Security Team should explicitly set deployment restrictions for each set of patches. Signed-off-by: Ian Jackson Signed-off-by: Ian Jackson --- security_vulnerab