Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 03 Jan 2002 13:07:27 -0700
From:      Brett Glass <brett@lariat.org>
To:        Joe Clarke <marcus@marcuscom.com>
Cc:        stable@FreeBSD.ORG
Subject:   Re: Please integrate OpenSSH 3.x
Message-ID:  <4.3.2.7.2.20020103130319.02a28af0@localhost>
In-Reply-To: <1010087964.86152.14.camel@shumai.marcuscom.com>
References:  <4.3.2.7.2.20020103124027.02a29860@localhost> <4.3.2.7.2.20020103124027.02a29860@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
At 12:59 PM 1/3/2002, Joe Clarke wrote:

>While I haven't been following the -security thread, I'm not sure if
>this is necessary.  The OpenSSH in FreeBSD has received specific FreeBSD
>"localizations" to fix bugs that may have arisen.  

If so, this amounts to a fork... which runs the risk of missing
or delaying subtle changes that might have implications for
security or functionality. Why create work by forking the code
rather than having the changes integrated?

>Also, the OpenSSH
>port in /usr/ports/security/openssh-portable now supports a 
>OPENSSH_OVERWRITE_BASE make option to replace the base SSH installation.

This is assuming that one is working from the ports and not
the packages. Very often, we don't install the ports on a system
because (a) they take up much space and (b) they become obsolete
quickly.

>Just add NO_OPENSSH=true in /etc/make.conf, and you'll be set.

We rarely do a "make world" on a production machine. But we do
need them to have the latest OpenSSH from the get-go!

--Brett


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4.3.2.7.2.20020103130319.02a28af0>