Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn't so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
Thanks, -Drew
On Wed, Apr 02, 2008 at 08:13:06AM -0400, Drew Weaver enlightened us:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn't so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
Only upstream knows for sure, but generally they only rebase if it becomes extremely difficult to backport the fixes. It was done with samba, so it's possible it could be done with dovecot, but you'll have to ask them...
Matt
On 02/04/2008, at 10:43 PM, Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn’t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
I don't know what version of CentOS you're using, however, with the version of Dovecot that comes with CentOS 4.x if you want to use a more recent package, there is a suitable one in the ATrpms repository.
That's what I use, and I haven't had any issues with it. I'm not sure about CentOS 5.x though.
Cheers,
Michael
on 4-2-2008 3:56 PM Michael Kratz spake the following:
On 02/04/2008, at 10:43 PM, Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn�t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
I don't know what version of CentOS you're using, however, with the version of Dovecot that comes with CentOS 4.x if you want to use a more recent package, there is a suitable one in the ATrpms repository.
That's what I use, and I haven't had any issues with it. I'm not sure about CentOS 5.x though.
The CentOS 5 version seems to be in testing, but probably because enough people haven't tested it to release it yet.
Hi,
On Wed, Apr 02, 2008 at 04:04:14PM -0700, Scott Silva wrote:
on 4-2-2008 3:56 PM Michael Kratz spake the following:
On 02/04/2008, at 10:43 PM, Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn�t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
I don't know what version of CentOS you're using, however, with the version of Dovecot that comes with CentOS 4.x if you want to use a more recent package, there is a suitable one in the ATrpms repository.
That's what I use, and I haven't had any issues with it. I'm not sure about CentOS 5.x though.
The CentOS 5 version seems to be in testing, but probably because enough people haven't tested it to release it yet.
no, it's in testing as every package updating something in CentOS' own package is and it will remain there forever. There are many people that don't want the stable part of ATrpms to touch any vendor provided package.
The name "testing" is very misleading, but that was the infratsruture that existed and I just abused it. When rpmrepo.org comes to life the package will be in a better named repo instead of "testing".
Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn’t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
Thanks,
-Drew
Drew,
Upstream V5.2 should include V1.0.7. We just upgraded to it on our RH boxes at their recommendation after some nasty startup issues. They were even nice enough to give us the RPMs and are supporting it them.
Best Regards, Camron
Camron W. Fox Hilo Office High Performance Computing Group Fujitsu America, INC. E-mail: cwfox@us.fujitsu.com
Camron W. Fox wrote:
Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn’t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
Thanks,
-Drew
Drew,
Upstream V5.2 should include V1.0.7. We just upgraded to it on our
RH boxes at their recommendation after some nasty startup issues. They were even nice enough to give us the RPMs and are supporting it them.
I can confirm that the version in 5.2beta is dovecot-1.0.7-1.el5.src.rpm ... not sure what the release will be, but it will probably be at least that version.
on 4-4-2008 1:11 PM Johnny Hughes spake the following:
Camron W. Fox wrote:
Drew Weaver wrote:
Does anyone know if upstream ever plans on updating the dovecot package to a non RC version or to even one of the RC versions that isn�t so insecure,
And by insecure, I of course refer to the recent rash of bugs which have been found.
Thanks,
-Drew
Drew,
Upstream V5.2 should include V1.0.7. We just upgraded to it on our
RH boxes at their recommendation after some nasty startup issues. They were even nice enough to give us the RPMs and are supporting it them.
I can confirm that the version in 5.2beta is dovecot-1.0.7-1.el5.src.rpm ... not sure what the release will be, but it will probably be at least that version.
That should at least cut a small amount of "upgrade" traffic on the dovecot list.
On Wednesday, April 02, 2008 8:13 AM -0400 Drew Weaver drew.weaver@thenap.com wrote:
And by insecure, I of course refer to the recent rash of bugs which have been found.
Can you give Red Hat bugzilla numbers for these? If none exist, they should be entered in the system.