Re: Scalable Debian vulnerability tracking

2009-01-13 Thread Thomas Liske
Hi, you might have a look at apt-dater[1] (part of unstable [2]). It is uses SSH to retrieve package informations from client hosts using public key authentification and uses sudo to call apt-get/sudo. It is a ncurses based CLI, but it has a report function to retrieve distri name version,

Re: Scalable Debian vulnerability tracking [REDUX]

2009-01-10 Thread R. W. Rodolico
http://debianhelpdesk.com/sysinfo.tgz md5sum 0704c3016a64817f1d2dcee7af3b3fa1 This is not production ready. It is currently in production, but only on my clients sites, and I fix things as they pop up. As I say in the README, we're working on a major rewrite that should make it much more usable

Re: Scalable Debian vulnerability tracking [REDUX]

2009-01-07 Thread Holger Levsen
Hi Sheldon, this sounds like an interesting project, please keep us posted! On Mittwoch, 7. Januar 2009, Sheldon Hearn wrote: On Wednesday 07 January 2009 00:24:09 R. W. Rodolico wrote: I have a package that we have been working on for a while that might be a good starting point. This

Re: Scalable Debian vulnerability tracking [REDUX]

2009-01-07 Thread R. W. Rodolico
Give me a couple of days to find a version that is not totally unstable. I'll tar it up, get some brief explanation, and post the URL here. Right now, the best 1.x stuff is wrapped up in a .deb. I have 2.0b in testing (on a few machines), but it is showing some bugs. I don't trust my svn install

Scalable Debian vulnerability tracking

2009-01-06 Thread Sheldon Hearn
tracker for some time thereafter, until we're confident that things are running smoothly. So any suggestions on how to implement scalable Debian vulnerability tracking in the interrim would be greatly appreciated. Thanks, Sheldon. -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9 (GNU/Linux

Re: Scalable Debian vulnerability tracking

2009-01-06 Thread Michael Tautschnig
Hi folks, I work for an hosting provider, and am looking at how to improve visibility into vulnerability exposure. We have over 800 Debian hosts that we manage fore customers, and will have over 1,000 by the end of this quarter. A major problem we face is that our change

Re: Scalable Debian vulnerability tracking

2009-01-06 Thread R. W. Rodolico
I have a package that we have been working on for a while that might be a good starting point. It tracks information about several machines, storing them in a central repository. There is a client piece installed on each machine which runs on a cron job, and currently e-mails the results to one or

Re: Scalable Debian vulnerability tracking

2009-01-06 Thread Moritz Muehlenhoff
on the right track here? [..] So any suggestions on how to implement scalable Debian vulnerability tracking in the interrim would be greatly appreciated. Hi Sheldon, that sounds like an interesting project. Thanks for the intent to share and to provide your possible solution it to the public

Re: Scalable Debian vulnerability tracking

2009-01-06 Thread Jonas Andradas
are running smoothly. So any suggestions on how to implement scalable Debian vulnerability tracking in the interrim would be greatly appreciated. Thanks, Sheldon. -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9 (GNU/Linux) iD4DBQFJY8BUpGJX8XSgas0RAlrWAJ9/PubX5OTma2DwbPy+NfUcR8k7xQCVHR3w

Re: Scalable Debian vulnerability tracking

2009-01-06 Thread Luis Mondesi
Is there anything wrong with using cfengine for this? [1] I'd just have a very simple layout for cfengine files and a cf.packages.$distro [2] file for each distro we support. Then have cfengine maintain a list of known packages that needs to be on each. Reporting can be easily done from a module

Re: Scalable Debian vulnerability tracking [REDUX]

2009-01-06 Thread Sheldon Hearn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tuesday 06 January 2009 23:28:29 Erik Harrison wrote: actually, if you do find something that does this, dont publish anything. start a company. No thanks. Just got out of that game and am thoroughly enjoying being an employee in an