Re: [CentOS] Determine security updates

2010-01-20 Thread Markus Falb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 19/01/2010 11:49, John Doe wrote: Try the yum-security package... Since when does it work for centos ? - -- best regards, markus -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.10 (Darwin) Comment: Using GnuPG with Mozilla -

Re: [CentOS] Determine security updates

2010-01-20 Thread Dave
On Wed, Jan 20, 2010 at 11:36 AM, Markus Falb markus.f...@fasel.at wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 19/01/2010 11:49, John Doe wrote: Try the yum-security package... Since when does it work for centos ? I've been using it for at least 6 months. Sure hope it works!

[CentOS] Determine security updates

2010-01-19 Thread Frank . Brodbeck
Hi, is there a way / software to find out which security patches my different CentOS systems are missing? Maybe with the according CESA announcement displayed? TIA, Frank. ___ CentOS mailing list CentOS@centos.org

Re: [CentOS] Determine security updates

2010-01-19 Thread Karanbir Singh
On 01/19/2010 10:32 AM, frank.brodb...@klingel.de wrote: is there a way / software to find out which security patches my different CentOS systems are missing? Maybe with the according CESA announcement displayed? I am working on a bit of code that would make something like this possible in

Re: [CentOS] Determine security updates

2010-01-19 Thread John Doe
From: frank.brodb...@klingel.de frank.brodb...@klingel.de is there a way / software to find out which security patches my different CentOS systems are missing? Maybe with the according CESA announcement displayed? Try the yum-security package... JD

Re: [CentOS] Determine security updates

2010-01-19 Thread James Hogarth
Or I can highly recommend configuring a local spacewalk server It is certainly usable right now overall (even if still under development in some areas) and the Redhat guys are very quick to squash reported bugs. Getting it runnign here has made my life much easier in provisioning, configuring

Re: [CentOS] Determine security updates

2010-01-19 Thread Geoff Galitz
is there a way / software to find out which security patches my different CentOS systems are missing? Maybe with the according CESA announcement displayed? I'll put in a plug for a software project that I am developer/contributor for, OpenVAS (Open Vulnerability Assessment Scanner).

Re: [CentOS] Determine security updates

2010-01-19 Thread Frank . Brodbeck
Karanbir Singh mail-li...@karan.org schrieb am 19.01.2010 11:48:54: On 01/19/2010 10:32 AM, frank.brodb...@klingel.de wrote: is there a way / software to find out which security patches my different CentOS systems are missing? Maybe with the according CESA announcement displayed? I am

Re: [CentOS] Determine security updates

2010-01-19 Thread Karanbir Singh
On 01/19/2010 11:08 AM, Geoff Galitz wrote: I'll put in a plug for a software project that I am developer/contributor for, OpenVAS (Open Vulnerability Assessment Scanner). http://www.openvas.org I look at this a while back, well over a year i think now. And the problem was that openvas does

Re: [CentOS] Determine security updates

2010-01-19 Thread Karanbir Singh
On 01/19/2010 11:07 AM, frank.brodb...@klingel.de wrote: I am working on a bit of code that would make something like this possible in the near future ( ~ a month or so ). However, till then I'd recommend going with just yum list and if you want, some mangling with yum-changelog will give you

Re: [CentOS] Determine security updates

2010-01-19 Thread Geoff Galitz
I look at this a while back, well over a year i think now. And the problem was that openvas does not actually test for the Vuln but it tries to use content to assume the exploits will not work. That is a very risky situation to get into. In terms of a proper security assessment; this is a