Bug#571631: libapache2-mod-shib2: shib-keygen generates world-readable key file

Moritz Muehlenhoff jmm at inutil.org
Sun Mar 7 20:15:01 UTC 2010


On Fri, Mar 05, 2010 at 10:01:23AM -0800, Russ Allbery wrote:
> Ferenc Wagner <wferi at niif.hu> writes:
> 
> > How should we proceed with this bug?  I'm not sure it warrants a
> > security update, so I didn't want to push this patch.
> 
> It doesn't really warrant a security update, I think.  However, we should
> apply it to the unstable shibboleth-sp2 and do another upload.  I don't
> feel a strong need to fix it in stable, apart from the backports.org
> backport.

Ack. If you want to introduce a fix in Lenny, please do that through
a stable point update (or leave it as-is if everyone should be using
the backports.org version anyway).

Cheers,
        Moritz





More information about the Pkg-shibboleth-devel mailing list