Re: Github users

2016-04-14 Thread Paul Wise
On Fri, Apr 15, 2016 at 2:40 AM, jack wrote: > Has this subscriber (list-abuser) been de-listed and banned, or do I > need to take action on my own behalf? Please do not reply to spam and especially do not quote spam in your own mails. To report spam on the mailing lists, please click the "Repor

RE: remove email - unsuscribe

2016-04-14 Thread Philip Costello
Please remove my email from you system : nbe...@4gwireless.com -Original Message- From: sebastien wey [mailto:sebastien_...@yahoo.fr] Sent: Thursday, April 14, 2016 8:20 AM To: debian-security@lists.debian.org Subject: remove email - unsuscribe Please remove my email from you sy

Re: remove email - unsuscribe

2016-04-14 Thread Franck Ridel
Hi Philip. You can unsuscribe here : https://www.debian.org/MailingLists/unsubscribe Greetings On Thu, Apr 14, 2016, 20:03 Philip Costello wrote: > > > Please remove my email from you system : > > nbe...@4gwireless.com > > > > > > -Original Message- > From: sebastien wey [mailto:sebast

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Birgit Berger (UV Wien)
is it better to wait to update samba 4.1.17 to 4.2.10 on jessie? How do I revert to previous version if the update fails? Are there any instructions how to that? KR birgit Virgo Pärna schreibt: >On Thu, 14 Apr 2016 10:02:22 +0100, Chris Boot > wrote: >> >> When running a Samba 4 DC, the shift

Re: Call for testing: upcoming samba security update

2016-04-14 Thread oeh univie edv lists
This doesn't sound very reassuring. Is it better to wait to update samba 4.1.17 to 4.2.10 on jessie? How do I revert to previous version 4.1.17 if the update fails? Are there any instructions how do that? KR birgit Virgo Pärna schreibt: >On Thu, 14 Apr 2016 10:02:22 +0100, Chris Boot > wrote: >

remove email - unsuscribe

2016-04-14 Thread sebastien wey
Please remove my email from you system : sebastien_...@yahoo.fr

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Virgo Pärna
On Thu, 14 Apr 2016 10:02:22 +0100, Chris Boot wrote: > > When running a Samba 4 DC, the shift from 4.1 to 4.2 brings some major > changes with it and people's smb.conf will need changing. The "server > services" line needs "winbind" replacing with "winbindd", and the user > must ensure the winbi

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Chris Boot
On 14/04/16 10:02, Chris Boot wrote: > Firstly: > >> Finally, two important configuration options should be considered, >> that we were unable to silently change defaults for: >> - smb signing = required >> - ntlm auth = no >> >> Without smb signing = required, Man in the Middl

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Paul Wise
On Thu, Apr 14, 2016 at 6:03 PM, Vladislav Kurz wrote: > I have noticed that samba-common-bin now depends on samba. It didn't before > the upgrade. Is there any special reason for that? I just need nmblookup on > some servers (and smbclient/cifs) but not the server package. This has been fixed in

Re: [SECURITY] [DSA 3548-2] samba regression update [SA-DEBIAN #61116]

2016-04-14 Thread Vladislav Kurz
On Thursday 14 of April 2016 you wrote: > - > Debian Security Advisory DSA-3548-2 secur...@debian.org > https://www.debian.org/security/ Salvatore Bonaccorso > April 14, 2016

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Vladislav Kurz
Hi, I have noticed that samba-common-bin now depends on samba. It didn't before the upgrade. Is there any special reason for that? I just need nmblookup on some servers (and smbclient/cifs) but not the server package. -- Best Regards Vladislav Kurz

Re: Call for testing: upcoming samba security update

2016-04-14 Thread Chris Boot
On 12/04/16 21:27, Salvatore Bonaccorso wrote: > Hi > > The upcoming Samba update is bigger than usual since for Jessie an > update is needed to 4.2. We want to expose the package a bit more for > additional testing. Please test the packages found on [snip] Hi folks, So I missed the testing win

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-14 Thread Peter Palfrader
On Wed, 13 Apr 2016, Scott Blaydes wrote: > > (3) The scripts that automatically update the security rotation only > > check if a server is online and responds to http requests - it > > does not check if a mirror is current. > > Expanding mini-nag[1] to do something about (3) would be

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-14 Thread Peter Palfrader
On Wed, 13 Apr 2016, Alexander Neilson wrote: > > (4) The nagios warning was missed in all the noise, and the relevant > > teams are overworked and busy. > > With mention to the above. Specifically (4). Is there a mailing list / > group / volunteer place for people interested in helping with

Re: [SECURITY] [DSA 3547-1] imagemagick security update

2016-04-14 Thread Peter Palfrader
On Wed, 13 Apr 2016, Henrique de Moraes Holschuh wrote: > On Wed, Apr 13, 2016, at 02:32, Peter Palfrader wrote: > > There's also nothing inherently wrong with just having a single address > > in an RRSet. > > It means a single point of failure for that region: A desynchronized set isn't any bet