From owner-freebsd-questions@FreeBSD.ORG Mon Mar 29 11:30:09 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E74F616A4CE for ; Mon, 29 Mar 2004 11:30:09 -0800 (PST) Received: from muse.calarts.edu (muse.calarts.edu [198.182.157.5]) by mx1.FreeBSD.org (Postfix) with ESMTP id AB6D943D1F for ; Mon, 29 Mar 2004 11:30:09 -0800 (PST) (envelope-from smurphy@calarts.edu) Received: from [172.24.0.68] (rfc1918-address.calarts.edu [172.24.0.68] (may be forged)) by muse.calarts.edu (8.11.7p1+Sun/8.11.7) with ESMTP id i2TJUY321591 for ; Mon, 29 Mar 2004 11:30:34 -0800 (PST) Mime-Version: 1.0 (Apple Message framework v613) Content-Transfer-Encoding: 7bit Message-Id: <38632096-81B7-11D8-A410-00039352A78A@calarts.edu> Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed To: freebsd-questions@freebsd.org From: Sean Murphy Date: Mon, 29 Mar 2004 11:28:13 -0800 X-Mailer: Apple Mail (2.613) Subject: Security Updates and Patching Two Choices? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 29 Mar 2004 19:30:10 -0000 I would like to stay patched with the latest security advisories. However usually I wait until the next release iso becomes available and do a fresh install that includes all the known exploites. My reason behind this is the "makeworld", "CVSup", and "mergemaster" is very time consuming/complicated. "Mergemaster" especially when I'm merging /etc files that I have no clue what they do. I also don't want "all" sources compiled on my system. I like a minimized OS. I don't want to build "all" sources when I just need these on my system (bin, man, and crypto). The same selection I use from a new install from /stand/sysinstall. Is that possible? However in the "security advisories" the second option is to download this file and patch the existing source and do a "makeworld" here is an excerpt of the latest advisory --- a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-04:05/openssl.patch # fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-04:05/ openssl.patch.asc b) Execute the following commands as root: # cd /usr/src # patch < /path/to/patch c) Recompile the operating system as described in . --- It seem the "makeworld" process is the only way to keep the system patched. If a tag just the 4_9 Release in the CVSupfile can i just ignore the mergemaster? also can I just CVSup the sources and build the ones I want? (see above) Thanks in advance Sean Murphy smurphy@calarts.edu