Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 201675 - net-ftp/netkit-ftpd: use install_cert in pkg_postinst
Summary: net-ftp/netkit-ftpd: use install_cert in pkg_postinst
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords: SECURITY
Depends on: CVE-2007-5769
Blocks: 174759
  Show dependency tree
 
Reported: 2007-12-08 14:39 UTC by Robert Buchholz (RETIRED)
Modified: 2008-01-14 21:16 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-12-08 14:39:52 UTC
Installation of SSL certificates in src_install might expose the secret
keys when building binary packages (bug 174759).

Please update the package mentioned in this bug's title to use the new
"install_cert" function of ssl-cert.eclass, and use it only in
your pkg_postinst or pkg_config.

This bug is for keeping track of specific changes to your ebuilds
and stabling, general questions about this should be discussed in
bug 174759.

Our aim is to have fixed ebuilds in the tree by Dec. 23rd, otherwise
we will commit this minor change. Stabling should be done two weeks after the
commit, at last around Jan, 6th.
Comment 1 Ulrich Müller gentoo-dev 2007-12-23 11:15:55 UTC
> Our aim is to have fixed ebuilds in the tree by Dec. 23rd, otherwise
> we will commit this minor change.

Just a reminder; I would prefer if package maintainers fixed this for their packages. So I'll wait for another week before committing the change myself.
Comment 2 Ulrich Müller gentoo-dev 2007-12-30 20:39:47 UTC
Fixed in 0.17-r6.
Leaving this bug open, stabilisation will follow around 2008-W02.
Comment 3 Ulrich Müller gentoo-dev 2008-01-09 10:00:16 UTC
(In reply to comment #2)
> Leaving this bug open, stabilisation will follow around 2008-W02.

Postponing, owing to bug #199206.
Comment 4 Ulrich Müller gentoo-dev 2008-01-14 21:16:14 UTC
netkit-ftpd-0.17-r7 is stable on all relevant arches.
I have removed -r4 and -r5, so all is done here.