MESSAGE
DATE | 2014-09-15 |
FROM | Chris Knadle
|
SUBJECT | Re: [NYLXS - HANGOUT] Apache Security tips
|
On Monday, September 15, 2014 13:02:41 Ruben Safir wrote: > On Mon, Sep 15, 2014 at 09:10:27AM -0400, Paul Robert Marino wrote:
> > Rubin > > Are you still custom compiling your own copy of Apache? > > I would have hoped you would have stopped doing that by now. Its a > > lot of hassle and a massive security risk if you aren't keeping up > > with theCVE's
[...] > I can't read this, but just what I need for security is 10 levels of > chopped up httpd.conf files scattered in a remote directory > > > Fuck that ... > > In fact, the last debian installation totally fucked up embperl
Is this in the libembperl-perl package?
> and I have to not only do apache by hand, but I also had to install Perl > by hand and hack the systems version of perl to be linked into the admin > config. > > But just when I though debian juck sucked, then I saw opensuse had the > same trouble. I think there is a bugfix in the latest perl to address > the problems, if I understand what I read.
Yes while I was at DebConf14 in Portland there were several Debian Developers of the Perl packages working to figure out how to deal with some upstream changes to Perl that required packaging changes. I couldn't understand the specifics -- it sounded a bit complicated. If you file a bug in bugs.debian.org or via one of the 'reportbug' programs I'm sure they'll be happy to help if they can.
> If I was good, I'd be ablke to write my own package... > > I'm not that good.
Nobody is good enough to make their own package "cold"; there's work going on within Debian to try to get to the point where this is possible for /simple/ packages, but for non-trivial packages I don't know anybody that could start from scratch and make a good package. There are still a lot of pitfalls in learning how to do Debian packaging, but I think I've gotten through a lot of them -- but it took time and I needed help from other DDs to get there.
However... what is approachable is to download a Debian source package and update it for a newer version of the upstream source or to make own tweaks. /That/ isn't too bad. So for instance if you want to update the libembperl-perl package in some custom way, that's certainly possible. If the latest upload of this package on Aug 11th was a problem, then we should try to fix what's wrong with it.
-- Chris
--
Chris Knadle Chris.Knadle-at-coredump.us
|
|