| … | |
… | |
| 6 | PEP, see http://www.python.org/peps/pep-0001.html for instructions and links |
6 | PEP, see http://www.python.org/peps/pep-0001.html for instructions and links |
| 7 | to templates. DO NOT USE THIS HTML FILE AS YOUR TEMPLATE! |
7 | to templates. DO NOT USE THIS HTML FILE AS YOUR TEMPLATE! |
| 8 | --> |
8 | --> |
| 9 | <head> |
9 | <head> |
| 10 | <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> |
10 | <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> |
| 11 | <meta name="generator" content="Docutils 0.3.0: http://docutils.sourceforge.net/" /> |
11 | <meta name="generator" content="Docutils 0.3.3: http://docutils.sourceforge.net/" /> |
| 12 | <title>GLEP 14 -- security updates based on GLSA</title> |
12 | <title>GLEP 14 -- security updates based on GLSA</title> |
| 13 | <link rel="stylesheet" href="tools/glep.css" type="text/css" /> |
13 | <link rel="stylesheet" href="tools/glep.css" type="text/css" /> |
| 14 | </head> |
14 | </head> |
| 15 | <body bgcolor="white"> |
15 | <body bgcolor="white"> |
| 16 | <table class="navigation" cellpadding="0" cellspacing="0" |
16 | <table class="navigation" cellpadding="0" cellspacing="0" |
| … | |
… | |
| 20 | <img src="http://www.gentoo.org/images/gentoo-new.gif" alt="[Gentoo]" |
20 | <img src="http://www.gentoo.org/images/gentoo-new.gif" alt="[Gentoo]" |
| 21 | border="0" width="150" height="35" /></a></td> |
21 | border="0" width="150" height="35" /></a></td> |
| 22 | <td class="textlinks" align="left"> |
22 | <td class="textlinks" align="left"> |
| 23 | [<b><a href="http://www.gentoo.org/">Gentoo Linux Home</a></b>] |
23 | [<b><a href="http://www.gentoo.org/">Gentoo Linux Home</a></b>] |
| 24 | [<b><a href="http://www.gentoo.org/proj/en/glep">GLEP Index</a></b>] |
24 | [<b><a href="http://www.gentoo.org/proj/en/glep">GLEP Index</a></b>] |
| 25 | [<b><a href="http://www.gentoo.org/proj/en/glep/glep-0014.txt">GLEP Source</a></b>] |
25 | [<b><a href="./glep-0014.txt">GLEP Source</a></b>] |
| 26 | </td></tr></table> |
26 | </td></tr></table> |
| 27 | <div class="document"> |
27 | <div class="document"> |
| 28 | <table class="rfc2822 field-list" frame="void" rules="none"> |
28 | <table class="rfc2822 field-list" frame="void" rules="none"> |
| 29 | <col class="field-name" /> |
29 | <col class="field-name" /> |
| 30 | <col class="field-body" /> |
30 | <col class="field-body" /> |
| … | |
… | |
| 33 | </tr> |
33 | </tr> |
| 34 | <tr class="field"><th class="field-name">Title:</th><td class="field-body">security updates based on GLSA</td> |
34 | <tr class="field"><th class="field-name">Title:</th><td class="field-body">security updates based on GLSA</td> |
| 35 | </tr> |
35 | </tr> |
| 36 | <tr class="field"><th class="field-name">Version:</th><td class="field-body">1.4</td> |
36 | <tr class="field"><th class="field-name">Version:</th><td class="field-body">1.4</td> |
| 37 | </tr> |
37 | </tr> |
| 38 | <tr class="field"><th class="field-name">Last-Modified:</th><td class="field-body"><a class="reference" href="http://www.gentoo.org/cgi-bin/viewcvs.cgi/xml/htdocs/proj/en/glep/glep-0014.txt?cvsroot=gentoo">2003/11/10 19:21:57</a></td> |
38 | <tr class="field"><th class="field-name">Last-Modified:</th><td class="field-body"><a class="reference" href="http://www.gentoo.org/cgi-bin/viewcvs/xml/htdocs/proj/en/glep/glep-0014.txt?cvsroot=gentoo">2003/11/10 19:21:57</a></td> |
| 39 | </tr> |
39 | </tr> |
| 40 | <tr class="field"><th class="field-name">Author:</th><td class="field-body">Marius Mauch <genone at genone.de>,</td> |
40 | <tr class="field"><th class="field-name">Author:</th><td class="field-body">Marius Mauch <genone at genone.de>,</td> |
| 41 | </tr> |
41 | </tr> |
| 42 | <tr class="field"><th class="field-name">Status:</th><td class="field-body">Accepted</td> |
42 | <tr class="field"><th class="field-name">Status:</th><td class="field-body">Accepted</td> |
| 43 | </tr> |
43 | </tr> |
| 44 | <tr class="field"><th class="field-name">Type:</th><td class="field-body">Standards Track</td> |
44 | <tr class="field"><th class="field-name">Type:</th><td class="field-body">Standards Track</td> |
| 45 | </tr> |
45 | </tr> |
| 46 | <tr class="field"><th class="field-name">Content-Type:</th><td class="field-body"><a class="reference" href="glep-0002.html">text/x-rst</a></td> |
46 | <tr class="field"><th class="field-name">Content-Type:</th><td class="field-body"><a class="reference" href="glep-0012.html">text/x-rst</a></td> |
| 47 | </tr> |
47 | </tr> |
| 48 | <tr class="field"><th class="field-name">Created:</th><td class="field-body">18 Aug 2003</td> |
48 | <tr class="field"><th class="field-name">Created:</th><td class="field-body">18 Aug 2003</td> |
| 49 | </tr> |
49 | </tr> |
| 50 | <tr class="field"><th class="field-name">Post-History:</th><td class="field-body">22-Aug-2003, 24-Aug-2003, 10-Nov-2003</td> |
50 | <tr class="field"><th class="field-name">Post-History:</th><td class="field-body">22-Aug-2003, 24-Aug-2003, 10-Nov-2003, 25-Oct-2004</td> |
| 51 | </tr> |
51 | </tr> |
| 52 | </tbody> |
52 | </tbody> |
| 53 | </table> |
53 | </table> |
| 54 | <hr /> |
54 | <hr /> |
| 55 | <div class="contents topic" id="contents"> |
55 | <div class="contents topic" id="contents"> |
| 56 | <p class="topic-title"><a name="contents">Contents</a></p> |
56 | <p class="topic-title first"><a name="contents">Contents</a></p> |
| 57 | <ul class="simple"> |
57 | <ul class="simple"> |
| 58 | <li><a class="reference" href="#abstract" id="id2" name="id2">Abstract</a></li> |
58 | <li><a class="reference" href="#abstract" id="id2" name="id2">Abstract</a></li> |
|
|
59 | <li><a class="reference" href="#status-update" id="id3" name="id3">Status Update</a></li> |
| 59 | <li><a class="reference" href="#motivation" id="id3" name="id3">Motivation</a></li> |
60 | <li><a class="reference" href="#motivation" id="id4" name="id4">Motivation</a></li> |
| 60 | <li><a class="reference" href="#proposed-change" id="id4" name="id4">Proposed change</a><ul> |
61 | <li><a class="reference" href="#proposed-change" id="id5" name="id5">Proposed change</a><ul> |
| 61 | <li><a class="reference" href="#update-tool" id="id5" name="id5">Update tool</a></li> |
62 | <li><a class="reference" href="#update-tool" id="id6" name="id6">Update tool</a></li> |
| 62 | <li><a class="reference" href="#glsa-format" id="id6" name="id6">GLSA format</a></li> |
63 | <li><a class="reference" href="#glsa-format" id="id7" name="id7">GLSA format</a></li> |
| 63 | <li><a class="reference" href="#glsa-release-process" id="id7" name="id7">GLSA release process</a></li> |
64 | <li><a class="reference" href="#glsa-release-process" id="id8" name="id8">GLSA release process</a></li> |
| 64 | <li><a class="reference" href="#portage-changes" id="id8" name="id8">Portage changes</a></li> |
65 | <li><a class="reference" href="#portage-changes" id="id9" name="id9">Portage changes</a></li> |
| 65 | </ul> |
66 | </ul> |
| 66 | </li> |
67 | </li> |
| 67 | <li><a class="reference" href="#rationale" id="id9" name="id9">Rationale</a></li> |
68 | <li><a class="reference" href="#rationale" id="id10" name="id10">Rationale</a></li> |
| 68 | <li><a class="reference" href="#implementation" id="id10" name="id10">Implementation</a></li> |
69 | <li><a class="reference" href="#implementation" id="id11" name="id11">Implementation</a></li> |
| 69 | <li><a class="reference" href="#backwards-compatibility" id="id11" name="id11">Backwards compatibility</a></li> |
70 | <li><a class="reference" href="#backwards-compatibility" id="id12" name="id12">Backwards compatibility</a></li> |
| 70 | <li><a class="reference" href="#copyright" id="id12" name="id12">Copyright</a></li> |
71 | <li><a class="reference" href="#copyright" id="id13" name="id13">Copyright</a></li> |
| 71 | </ul> |
72 | </ul> |
| 72 | </div> |
73 | </div> |
| 73 | <div class="section" id="abstract"> |
74 | <div class="section" id="abstract"> |
| 74 | <h1><a class="toc-backref" href="#id2" name="abstract">Abstract</a></h1> |
75 | <h1><a class="toc-backref" href="#id2" name="abstract">Abstract</a></h1> |
| 75 | <p>There is currently no automatic way to check a Gentoo system for identified |
76 | <p>There is currently no automatic way to check a Gentoo system for identified |
| 76 | security holes or auto-apply security fixes. This GLEP proposes a way to deal |
77 | security holes or auto-apply security fixes. This GLEP proposes a way to deal |
| 77 | with this issue</p> |
78 | with this issue</p> |
| 78 | </div> |
79 | </div> |
|
|
80 | <div class="section" id="status-update"> |
|
|
81 | <h1><a class="toc-backref" href="#id3" name="status-update">Status Update</a></h1> |
|
|
82 | <p>Beta implementation in gentoolkit.</p> |
|
|
83 | </div> |
| 79 | <div class="section" id="motivation"> |
84 | <div class="section" id="motivation"> |
| 80 | <h1><a class="toc-backref" href="#id3" name="motivation">Motivation</a></h1> |
85 | <h1><a class="toc-backref" href="#id4" name="motivation">Motivation</a></h1> |
| 81 | <p>Automatic checking for security updates is a often requested feature for Gentoo. |
86 | <p>Automatic checking for security updates is a often requested feature for Gentoo. |
| 82 | Implementing it will enable users to fix security holes without reading every |
87 | Implementing it will enable users to fix security holes without reading every |
| 83 | security announcement. It's also a feature that is often required in enterprise |
88 | security announcement. It's also a feature that is often required in enterprise |
| 84 | environments.</p> |
89 | environments.</p> |
| 85 | </div> |
90 | </div> |
| 86 | <div class="section" id="proposed-change"> |
91 | <div class="section" id="proposed-change"> |
| 87 | <h1><a class="toc-backref" href="#id4" name="proposed-change">Proposed change</a></h1> |
92 | <h1><a class="toc-backref" href="#id5" name="proposed-change">Proposed change</a></h1> |
| 88 | <div class="section" id="update-tool"> |
93 | <div class="section" id="update-tool"> |
| 89 | <h2><a class="toc-backref" href="#id5" name="update-tool">Update tool</a></h2> |
94 | <h2><a class="toc-backref" href="#id6" name="update-tool">Update tool</a></h2> |
| 90 | <p>The coding part of this GLEP is a update tool that reads a GLSA, verifies its |
95 | <p>The coding part of this GLEP is a update tool that reads a GLSA, verifies its |
| 91 | GPG signature, checks if the system is affected by it and executes one of the |
96 | GPG signature, checks if the system is affected by it and executes one of the |
| 92 | following actions, depending on user preferences:</p> |
97 | following actions, depending on user preferences:</p> |
| 93 | <ul class="simple"> |
98 | <ul class="simple"> |
| 94 | <li>run all steps necessary to fix the security hole, including package updates and |
99 | <li>run all steps necessary to fix the security hole, including package updates and |
| … | |
… | |
| 98 | </ul> |
103 | </ul> |
| 99 | <p>Once this tool is implemented and well tested it can be integrated into portage. |
104 | <p>Once this tool is implemented and well tested it can be integrated into portage. |
| 100 | A prototype <a class="reference" href="#implementation">implementation</a> for this tool exists.</p> |
105 | A prototype <a class="reference" href="#implementation">implementation</a> for this tool exists.</p> |
| 101 | </div> |
106 | </div> |
| 102 | <div class="section" id="glsa-format"> |
107 | <div class="section" id="glsa-format"> |
| 103 | <h2><a class="toc-backref" href="#id6" name="glsa-format">GLSA format</a></h2> |
108 | <h2><a class="toc-backref" href="#id7" name="glsa-format">GLSA format</a></h2> |
| 104 | <p>The GLSA format needs to be specified, I suggest using XML for that to simplify |
109 | <p>The GLSA format needs to be specified, I suggest using XML for that to simplify |
| 105 | parsing and later extensions. See <a class="reference" href="#implementation">implementation</a> for a sample DTD. The format |
110 | parsing and later extensions. See <a class="reference" href="#implementation">implementation</a> for a sample DTD. The format |
| 106 | has to be compatible with the update tool of course. If necessary a converter |
111 | has to be compatible with the update tool of course. If necessary a converter |
| 107 | tool or an editor could be written for people not comfortable with XML (update: |
112 | tool or an editor could be written for people not comfortable with XML (update: |
| 108 | a QT based editor for the GLSA format written by plasmaroo exists in the |
113 | a QT based editor for the GLSA format written by plasmaroo exists in the |
| 109 | gentoo-projects repository). Every GLSA has to be GPG signed by the responsible |
114 | gentoo-projects repository). Every GLSA has to be GPG signed by the responsible |
| 110 | developer, who has to be a member of the security herd.</p> |
115 | developer, who has to be a member of the security herd.</p> |
| 111 | </div> |
116 | </div> |
| 112 | <div class="section" id="glsa-release-process"> |
117 | <div class="section" id="glsa-release-process"> |
| 113 | <h2><a class="toc-backref" href="#id7" name="glsa-release-process">GLSA release process</a></h2> |
118 | <h2><a class="toc-backref" href="#id8" name="glsa-release-process">GLSA release process</a></h2> |
| 114 | <p>Additional to sending the GLSA to the gentoo-announce mailing list it has to be |
119 | <p>Additional to sending the GLSA to the gentoo-announce mailing list it has to be |
| 115 | stored on a HTTP/FTP server and in the portage tree. I'd suggest a script should |
120 | stored on a HTTP/FTP server and in the portage tree. I'd suggest a script should |
| 116 | be used to release a GLSA that will:</p> |
121 | be used to release a GLSA that will:</p> |
| 117 | <ul class="simple"> |
122 | <ul class="simple"> |
| 118 | <li>check the GLSA for correctness</li> |
123 | <li>check the GLSA for correctness</li> |
| … | |
… | |
| 122 | <li>put it on the rsync server (via cvs commit)</li> |
127 | <li>put it on the rsync server (via cvs commit)</li> |
| 123 | <li>notify the moderators on the forums to make an announcement</li> |
128 | <li>notify the moderators on the forums to make an announcement</li> |
| 124 | </ul> |
129 | </ul> |
| 125 | </div> |
130 | </div> |
| 126 | <div class="section" id="portage-changes"> |
131 | <div class="section" id="portage-changes"> |
| 127 | <h2><a class="toc-backref" href="#id8" name="portage-changes">Portage changes</a></h2> |
132 | <h2><a class="toc-backref" href="#id9" name="portage-changes">Portage changes</a></h2> |
| 128 | <p>Until the <a class="reference" href="#update-tool">update tool</a> is integrated into portage there will be no code changes |
133 | <p>Until the <a class="reference" href="#update-tool">update tool</a> is integrated into portage there will be no code changes |
| 129 | to portage. The update tool might require a few new configuration options, these |
134 | to portage. The update tool might require a few new configuration options, these |
| 130 | could be placed in make.conf or another config file in /etc/portage.</p> |
135 | could be placed in make.conf or another config file in /etc/portage.</p> |
| 131 | </div> |
136 | </div> |
| 132 | </div> |
137 | </div> |
| 133 | <div class="section" id="rationale"> |
138 | <div class="section" id="rationale"> |
| 134 | <h1><a class="toc-backref" href="#id9" name="rationale">Rationale</a></h1> |
139 | <h1><a class="toc-backref" href="#id10" name="rationale">Rationale</a></h1> |
| 135 | <p>The lack of automated security updates for Gentoo is one of the most often requested |
140 | <p>The lack of automated security updates for Gentoo is one of the most often requested |
| 136 | features for portage as it is one of the standard features of other distributions. |
141 | features for portage as it is one of the standard features of other distributions. |
| 137 | As Gentoo already provides GLSAs for important security bugs it is only natural |
142 | As Gentoo already provides GLSAs for important security bugs it is only natural |
| 138 | to use these to implement this feature.</p> |
143 | to use these to implement this feature.</p> |
| 139 | <p>To parse a GLSA in a program the format needs to be specified and a parser has |
144 | <p>To parse a GLSA in a program the format needs to be specified and a parser has |
| … | |
… | |
| 151 | <p>To verify the signatures of the GLSAs the public keys of the developers should be |
156 | <p>To verify the signatures of the GLSAs the public keys of the developers should be |
| 152 | available in the portage tree and on the HTTP server. The verification is necessary |
157 | available in the portage tree and on the HTTP server. The verification is necessary |
| 153 | to prevent exploits by fake GLSAs.</p> |
158 | to prevent exploits by fake GLSAs.</p> |
| 154 | </div> |
159 | </div> |
| 155 | <div class="section" id="implementation"> |
160 | <div class="section" id="implementation"> |
| 156 | <h1><a class="toc-backref" href="#id10" name="implementation">Implementation</a></h1> |
161 | <h1><a class="toc-backref" href="#id11" name="implementation">Implementation</a></h1> |
| 157 | <p>A prototype implementation (including the update tool, a DTD and a sample |
162 | <p>A prototype implementation (including the update tool, a DTD and a sample |
| 158 | XMLified GLSA) exists at <a class="reference" href="http://gentoo.devel-net.org/glsa/">http://gentoo.devel-net.org/glsa/</a> and in the |
163 | XMLified GLSA) exists at <a class="reference" href="http://gentoo.devel-net.org/glsa/">http://gentoo.devel-net.org/glsa/</a> and in the |
| 159 | gentoo-projects/gentoo-security/GLSA repository. This GLEP is based |
164 | gentoo-projects/gentoo-security/GLSA repository. This GLEP is based |
| 160 | on that implementation, though it can be changed or rewritten if necessary.</p> |
165 | on that implementation, though it can be changed or rewritten if necessary.</p> |
| 161 | </div> |
166 | </div> |
| 162 | <div class="section" id="backwards-compatibility"> |
167 | <div class="section" id="backwards-compatibility"> |
| 163 | <h1><a class="toc-backref" href="#id11" name="backwards-compatibility">Backwards compatibility</a></h1> |
168 | <h1><a class="toc-backref" href="#id12" name="backwards-compatibility">Backwards compatibility</a></h1> |
| 164 | <p>The current <a class="reference" href="#glsa-release-process">GLSA release process</a> needs to be replaced with this proposal. It |
169 | <p>The current <a class="reference" href="#glsa-release-process">GLSA release process</a> needs to be replaced with this proposal. It |
| 165 | would be nice if old GLSAs would be transformed into XML as well, but that is |
170 | would be nice if old GLSAs would be transformed into XML as well, but that is |
| 166 | not a requirement for this GLEP.</p> |
171 | not a requirement for this GLEP.</p> |
| 167 | </div> |
172 | </div> |
| 168 | <div class="section" id="copyright"> |
173 | <div class="section" id="copyright"> |
| 169 | <h1><a class="toc-backref" href="#id12" name="copyright">Copyright</a></h1> |
174 | <h1><a class="toc-backref" href="#id13" name="copyright">Copyright</a></h1> |
| 170 | <p>This document has been placed in the public domain.</p> |
175 | <p>This document has been placed in the public domain.</p> |
| 171 | </div> |
176 | </div> |
| 172 | </div> |
177 | </div> |
| 173 | |
178 | |
| 174 | <hr class="footer"/> |
179 | <hr class="footer" /> |
| 175 | <div class="footer"> |
180 | <div class="footer"> |
| 176 | <a class="reference" href="glep-0014.txt">View document source</a>. |
181 | <a class="reference" href="glep-0014.txt">View document source</a>. |
| 177 | Generated on: 2003-11-10 19:22 UTC. |
182 | Generated on: 2004-10-25 17:01 UTC. |
| 178 | Generated by <a class="reference" href="http://docutils.sourceforge.net/">Docutils</a> from <a class="reference" href="http://docutils.sourceforge.net/rst.html">reStructuredText</a> source. |
183 | Generated by <a class="reference" href="http://docutils.sourceforge.net/">Docutils</a> from <a class="reference" href="http://docutils.sourceforge.net/rst.html">reStructuredText</a> source. |
| 179 | </div> |
184 | </div> |
| 180 | </body> |
185 | </body> |
| 181 | </html> |
186 | </html> |
| 182 | |
187 | |