oss-sec mailing list archives

Re: Another Python app (rhn-setup: rhnreg_ks) not checking hostnames in certs properly CVE-2015-1777


From: Kurt Seifried <kseifried () redhat com>
Date: Mon, 09 Mar 2015 14:39:38 -0600

On 09/03/15 12:52 PM, John Haxby wrote:

On 9 Mar 2015, at 16:47, Kurt Seifried <kseifried () redhat com> wrote:

If vendors want features in their rebranded RHEL they can add them. I
have no clue why you would need broad agreement from the community
including Red Hat to add a feature to Oracle Linux.

On the other hand, if two loosely compatible vendors want the same feature it makes sense to have the feature 
implemented in the same way.

For this python certificate validation, we could have as many different mechanisms as there are distros and chaos 
would rule.   Even worse, you might pick the mechanism from the wrong distro and it has no effect and we (people on 
this list) would be guilty of weakening security by confusion.

It’s not a question of lack of talent: all the distro vendors have talented people who can fix problems, it’s a 
question of doing the best by our joint customer base.

Does that make sense?

jch


I find this really hard to believe based on the past. So you're saying
Oracle is willing to work with Red Hat and the community in general now?
Can we get access to the MySQL security bugs and test cases for example?
This would be HUGELY helpful to the community.

I'll believe Oracle is willing to work with the community when I
actually see Oracle participate and help the community. Until then it's
just words from some random Oracle employee and most likely isn't
official policy.

So prove to us you want to work with us (e.g. by opening up the MySQL
security bugs/test cases) and we can definitely look at future cooperation.

-- 
Kurt Seifried -- Red Hat -- Product Security -- Cloud
PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: