Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 13 Jan 2008 18:24:41 +0000
From:      Vince <jhary@unsane.co.uk>
To:        =?ISO-2022-JP?B?GyRCSjhEOxsoQg==?= <bunchou@googlemail.com>
Cc:        freebsd-questions@freebsd.org, Erik Cederstrand <erik@cederstrand.dk>
Subject:   Re: Secure update of /usr/src
Message-ID:  <478A5769.8000904@unsane.co.uk>
In-Reply-To: <cb5b777d0801130926j56a20c5bx2a19555edd7ff071@mail.gmail.com>
References:  <cb5b777d0801130217r6467751ay634d0111617afc05@mail.gmail.com>	<4789F7DE.9090905@cederstrand.dk>	<cb5b777d0801130414l1f1427cekb49ee29a46140bf7@mail.gmail.com>	<478A238A.4060106@cederstrand.dk> <cb5b777d0801130926j56a20c5bx2a19555edd7ff071@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi,
文鳥 wrote:
> 08/01/13 に Erik Cederstrand<erik@cederstrand.dk> さんは書きました:
>> 文鳥 wrote:
>>> 2008/1/13, Erik Cederstrand <erik@cederstrand.dk>:
>>>> 文鳥 wrote:
>>>>> Hello all,
>>>>>
>>>>> is there any way to securely follow the STABLE branch of FreeBSD, e.g.
>>>>> a cryptographically signed distribution method like portsnap? Afaik,
>>>>> the usual update methods (CVSup, etc.) do not include any
>>>>> authentication / integrity checking. Am I missing something here?
>>>> freebsd-update(8) is portsnap for the base system. However, you can only
>>>> follow RELEASE branches, not STABLE.
>>>>
>>>> Erik
<
<snip>

>> Erik
>>
> Yes, I am aware of that fact. However, 7.x STABLE is the only version
> apart from CURRENT that I was able to get working reliably on the
> hardware in question. And alas, even though the system in question is
> used for testing only,I am still bound by the company security policy
> in this matter... Guess I will have to wait until 7.0 is released.
> Thanks for your help in this matter.
>
I'm not suer how often its updated but you can to a limited degree
follow the RELENG_7_0 branch via freebsd-update already (see
http://www.daemonology.net/blog/2007-11-11-freebsd-major-version-upgrade.html)

However I'd say overall you may be better waiting for the release.

Vince

 _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?478A5769.8000904>