Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20120128011857.GA10720@openwall.com>
Date: Sat, 28 Jan 2012 05:18:57 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: non-Linux advance notification list

Hi,

I would definitely like OpenBSD to be represented on the distros list.
Not only OpenBSD ports, but also OpenBSD base.

On Sat, Jan 28, 2012 at 12:39:19AM +0000, Stuart Henderson wrote:
> Could you add myself for OpenBSD ports please? If acceptable I'll send a
> public key out of band. Thanks.

Probably yes, but I (and maybe others) would like some info first:

Is there any web page (or something else) specifying the OpenBSD ports
security team (not all committers, but just those the project vouches
for as it relates to handling of non-public security vulnerabilities)?
Or a port-security@ exploder that you're on.  Or explicit approval
(vouching for you) by a key OpenBSD person for this specific occasion.

(For NetBSD and FreeBSD, the folks subscribed were "visibly" on security
teams.)

Is there any place where we can see past security issues in OpenBSD
ports handled (which issues, when fixed)?  Something like a changelog
with security fixes marked specially, or advisories?

Would advance notifications result in you actually preparing OpenBSD
port updates in time for public disclosure?

How would you handle notifications that happen to pertain to components
that are in OpenBSD base tree rather than ports?

BTW, note how my current approach differs from what was used on
vendor-sec: I ask projects themselves (known and reputable) to vouch for
folks to be added on their behalf, whereas on vendor-sec some existing
list members would vouch for a new member.  I'd appreciate any comments
anyone might have on this.

Thanks,

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.