Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Nov 2012 00:28:12 +0000 (UTC)
From:      Gavin Atkinson <gavin@FreeBSD.org>
To:        doc-committers@freebsd.org, svn-doc-all@freebsd.org, svn-doc-head@freebsd.org
Subject:   svn commit: r40132 - head/en_US.ISO8859-1/htdocs/news
Message-ID:  <201211230028.qAN0SCxW099819@svn.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: gavin
Date: Fri Nov 23 00:28:12 2012
New Revision: 40132
URL: http://svnweb.freebsd.org/changeset/doc/40132

Log:
  Add an update to the security incident page for November 22nd, 2012.
  
  Approved by:	core, bcr (mentor, implicit)

Modified:
  head/en_US.ISO8859-1/htdocs/news/2012-compromise.xml

Modified: head/en_US.ISO8859-1/htdocs/news/2012-compromise.xml
==============================================================================
--- head/en_US.ISO8859-1/htdocs/news/2012-compromise.xml	Fri Nov 23 00:00:23 2012	(r40131)
+++ head/en_US.ISO8859-1/htdocs/news/2012-compromise.xml	Fri Nov 23 00:28:12 2012	(r40132)
@@ -62,6 +62,7 @@
 
     <ul>
       <li><a href="#announce">Announcement</a></li>
+      <li><a href="#update20121122">Update: 22nd November 2012</a></li>
       <li><a href="#update20121118">Update: 18th November 2012</a></li>
       <li><a href="#details">Initial Details: 17th November 2012</a></li>
       <li><a href="#impact">What is the Impact?</a></li>
@@ -71,6 +72,27 @@
 
     <p>More details will be added here as they become available.</p>
 
+    <h1><a name="update20121122">Update: November 22nd, 2012</a></h1>
+
+    <p>Although not mentioned in the original report,
+      <a href="/doc/handbook/ctm.html">CTM</a> (another mechanism for
+      retrieving FreeBSD source) uses the master trusted Subversion
+      repository as the source of its data.  Additionally, verification of
+      CTM-sourced trees has been completed against the Subversion tree,
+      confirming that there are no differences between the two.  Our
+      experimental Git repository has been similarly verified.</p>
+
+    <p>Work continues on rebuilding internal infrastructure and reinstating
+      services taken down during the incident.  Web interfaces to the old
+      CVS repositories (CVSweb), and to GNATS (our bug-tracking database)
+      have been restored amongst other services, and other internal hosts
+      are being examined and rebuilt where necessary.  A full audit of the
+      package building infrastructure is ongoing.</p>
+
+    <p>The FreeBSD Project is investing significant effort into looking
+      into both medium and long term infrasture improvements to increase
+      security of the FreeBSD cluster.</p>
+
     <h1><a name="update20121118">Update: November 18th, 2012</a></h1>
 
     <p>Newer portsnap(8) snapshots are once again available.  The



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201211230028.qAN0SCxW099819>