Bob McConnell wrote:
I'll go one further. We run commercial web sites on CentOS 5.3 which must also be PCI compliant. Because of the security issues, the auditors have been complaining for two months that we don't have PHP 5.2.11 installed yet, putting our PCI certification in jeopardy. When 5.2.12 is released, probably next month, we will have 30 days to get it installed.
If thats their requirement, then perhaps RHEL and its derivatives aren't the right platform for this. Or, you shouldn't be using PHP at all.