Re: Suggestion to end support for legacy 1024-bit RSA root CAs in Fedora stable

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 2016-08-19 at 09:05 -0400, Stephen Gallagher wrote:
> Applying this to older releases would be a violation of the Stable Updates
> Policy[1] (though arguably it could be considered to fall under "The update
> fixes a security issue that would affect a large number of users.".

Although I currently assume the change is safe for stable Fedoras, 
getting it into future stable releases such as Fedora 25 has a higher priority.

Instead of a fixed schedule for updating to F23/F24, here's a more conservative
suggestion:

We start a new thread on this devel list, and ask all developers who use F23/F24
in a stable environment, to perform the configuration that is equivalent to the
suggested package change (which is, to run the "ca-legacy disable" command), and
ask them to report any regressions they notice.

We could adjust our plans based on the feedback (or lack thereof) we'll get.

If everything seems to work fine, in a second step, we could broaden our call
for testing, by sending an equivalent message to a fedora users mailing list.

> That said, I'm not saying "don't allow this in F25", personally. I'm saying
> "don't try to land it in the middle of an already-slipped Freeze". That's a
> different situation. I don't want this to potentially cause us to slip another
> week.

Understood, thanks.

Kai
--
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://lists.fedoraproject.org/admin/lists/devel@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux