From owner-freebsd-security@FreeBSD.ORG Sat Apr 17 17:53:57 2010 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 34DEE1065672 for ; Sat, 17 Apr 2010 17:53:57 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from mail2.fluidhosting.com (mx23.fluidhosting.com [204.14.89.6]) by mx1.freebsd.org (Postfix) with ESMTP id B7AAE8FC15 for ; Sat, 17 Apr 2010 17:53:56 +0000 (UTC) Received: (qmail 32349 invoked by uid 399); 17 Apr 2010 17:53:55 -0000 Received: from localhost (HELO foreign.dougb.net) (dougb@dougbarton.us@127.0.0.1) by localhost with ESMTPAM; 17 Apr 2010 17:53:55 -0000 X-Originating-IP: 127.0.0.1 X-Sender: dougb@dougbarton.us Message-ID: <4BC9F5B2.8080300@FreeBSD.org> Date: Sat, 17 Apr 2010 10:53:54 -0700 From: Doug Barton Organization: http://SupersetSolutions.com/ User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.9.1.9) Gecko/20100330 Thunderbird/3.0.4 MIME-Version: 1.0 To: Tim Gustafson References: <1576323409.700861271520073086.JavaMail.root@mail-01.cse.ucsc.edu> In-Reply-To: <1576323409.700861271520073086.JavaMail.root@mail-01.cse.ucsc.edu> X-Enigmail-Version: 1.0.1 OpenPGP: id=1A1ABC84 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Cc: freebsd-security@freebsd.org, APseudoUtopia Subject: Re: OpenSSL 0.9.8k -> 0.9.8l X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 17 Apr 2010 17:53:57 -0000 On 04/17/10 09:01, Tim Gustafson wrote: >> This isn't an answer to your question, but you could always use >> OpenSSL from the ports tree. > > I'm hesitant to do so because in the past I've had problem when I've > used the ports to upgrade base OS-level stuff, like OpenSSL or > Sendmail, then the buildworld cycle overwrites the ports library and > the ports library overwrites the OS-level stuff and so on, which in > the past has caused general mayhem. Read the src.conf man page for knobs to disable parts of the base that you install from ports. Doug -- ... and that's just a little bit of history repeating. -- Propellerheads Improve the effectiveness of your Internet presence with a domain name makeover! http://SupersetSolutions.com/