Koozali.org: home of the SME Server

Security?Is there any?

SalaTar

Security?Is there any?
« on: February 27, 2003, 05:39:35 AM »
Any one put together a site for "Errata" for sme (Mitel).
Kinada wondering how little security is left on the old 5.5( Copyright Mitel Networks 2002) box with all the latest bug alerts from Redhat. Seems the only info around here is "buy it" or "I dont see an issue" or "It Dosnt affect our product" (Is mitel bigger than Redhat? They can redo the redhat code to fix holes and not tell Redhat??I dont know. Must have some great coders maybe Redhat should hire em...Ohhh  wait most of the best coders for Mitel are the people that use the free SME )
I'm starting to trust these foriums less and less as time goes on.

I'm not trying to come off like an Ass and Busting Mitels chops, But I have fallowed and used sme for some time and it seems like the Public Ver. is getting the shaft.
The contribs get fewer as it seems they have snubbed a bit of the Old contributers.
Blades ...wwwelll  we used to have em(now we get "upgrade to the latest Beta OS" and lets hope it works)
I think a Major Security hole Like SSH should be adressed faster not "get the rpm from Redhat" reply thats Looming in forums as of late...
 

 sorry I started to rant
anyway where someone whos up to date with redhat security rpms that work on SME  ohh wait that would be redhat...Right?

Paul

Re: Security?Is there any?
« Reply #1 on: February 27, 2003, 10:07:54 AM »
"I'm not trying to come off like an Ass "

You are acting like an entire herd of donkeys.

Try posting a question without all the smart-ass comments, you might get a NON smart-ass answer!

Bill Talcott

Re: Security?Is there any?
« Reply #2 on: February 27, 2003, 05:32:59 PM »
The way SME is set up, some issues just don't affect it as they would on a default RH install. Running different processes as different users, default firewall rules, that sort of thing. It's not necessarily that the bug isn't in the SME code, it's that it can't be exploited due to the rest of the SME package.

And sometimes all it takes is the RH RPM to fix the problem (since SME is based on RH). Would you rather wait until Mitel copies the file to an Updates directory on their own server and says "Run 'rpm -Uvh xxxxx.rpm' to fix this problem."?

I'm no expert, but we haven't experienced any security problems yet...

As for the Blades, it's their service, it's their decision. If you want to be able to update your server via a Server Manager panel instead of downloading and installing RPMs, pay for it.

SalaTar

Re: Security?Is there any?
« Reply #3 on: March 01, 2003, 07:45:00 AM »
Paul,
"You are acting like an entire herd of donkeys.

Try posting a question without all the smart-ass comments, you might get a NON smart-ass answer!"
Yes I was.
I see the Mitel folks do the same daily.

I was being "Tongue in cheek"