classpath
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Latest Savannah update (RCS + Friday restoration)


From: Mark Wielaard
Subject: Latest Savannah update (RCS + Friday restoration)
Date: Thu, 18 Dec 2003 21:26:57 +0100

Hi Classpath Hackers,

Attached is the latest Savannah update from Bradley Kuhn.
Looks like we will have access again this weekend.

But we still have to do our own audit of the Classpath sources.
Won't have much time till Saturday. So help in doing this is
appreciated.

Will try to answer some mail, but my backlog is rather large and my
GNU/hacking time is a bit limited.

Cheers,

Mark
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

                                        Thursday 18 December 2003, 10:00 EST

As most of you know, we have now provided the RCS files for the projects
for those of you that want to work independently.  For project FOO, you
can find the RCS files at:

    ftp://ftp.gnu.org/savannah/cvs/FOO-cvs-latest.tar.gz

And:
    ftp://ftp.gnu.org/savannah/cvs/md5sums.asc

has md5sums for all the files in that directory.

We are working today to finish securing various parts of the savannah
system infrastructure, and hope to have the software running again by the
end of the day on this Friday.  (Although there could be delays, we have
set this as a very serious deadline.)

We have discovered many possible ways that someone could have used to gain
root access illegitimately to the system.  These problems were primarily
due to configuration issues and bugs in various custom scripts installed
on the system.  We are completing now an audit of the Savannah software
before placing it back into production.  We have also used chroot
environments and other methods to tighten how much access is provided to
the system for project management.

We appreciate your patience and will work hard to meet our targeted roll
out for tomorrow.




Sincerely,

Bradley M. Kuhn
Executive Director, Free Software Foundation
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE/4c9x53XjJNtBs4cRAv5rAJ9EJmuGhSQJPzwvD4dmiyWyTFTHfwCaAkh8
FOQesuacZ1ZsKA/GcHMc7o8=
=XjE0
-----END PGP SIGNATURE-----

Attachment: signature.asc
Description: This is a digitally signed message part


reply via email to

[Prev in Thread] Current Thread [Next in Thread]