First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 201673
Alias:
Product:
Component:
Status: VERIFIED
Resolution: FIXED
Assigned To: Cédric Krier <cedk@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 201673 depends on: Show dependency tree
Bug 201673 blocks: 174759
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.





View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-12-08 14:38 0000
Installation of SSL certificates in src_install might expose the secret
keys when building binary packages (bug 174759).

Please update the package mentioned in this bug's title to use the new
"install_cert" function of ssl-cert.eclass, and use it only in
your pkg_postinst or pkg_config.

This bug is for keeping track of specific changes to your ebuilds
and stabling, general questions about this should be discussed in
bug 174759.

Our aim is to have fixed ebuilds in the tree by Dec. 23rd, otherwise
we will commit this minor change. Stabling should be done two weeks after the
commit, at last around Jan, 6th.

------- Comment #1 From Ulrich Müller 2007-12-23 11:15:54 0000 -------
> Our aim is to have fixed ebuilds in the tree by Dec. 23rd, otherwise
> we will commit this minor change.

Just a reminder; I would prefer if package maintainers fixed this for their
packages. So I'll wait for another week before committing the change myself.

------- Comment #2 From Cédric Krier 2007-12-23 11:47:57 0000 -------
Fix in cvs

------- Comment #3 From Ulrich Müller 2007-12-23 12:29:41 0000 -------
(In reply to comment #2)
> Fix in cvs

Not really... The final goal is that we remove docert() from ssl-cert.eclass.
So I guess it should be something like the following:

pkg_postinst() {
    install_cert /etc/nufw/{nufw,nuauth}
}

Reopening.

------- Comment #4 From Cédric Krier 2007-12-23 12:46:35 0000 -------
Fix again in cvs
Thanks

------- Comment #5 From Ulrich Müller 2007-12-23 13:04:01 0000 -------
> Fix again in cvs

Thank you.

@security: Package was never stable.

First Last Prev Next    No search results available      Search page      Enter new bug