HP3000-L Archives

April 2003, Week 1

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"BIXBY,MARK (HP-Cupertino,ex1)" <[log in to unmask]>
Reply To:
BIXBY,MARK (HP-Cupertino,ex1)
Date:
Fri, 4 Apr 2003 18:03:57 -0800
Content-Type:
text/plain
Parts/Attachments:
text/plain (51 lines)
Hi HP3000-L,

It appears I was overly optimistic in recommending that 6.0 and 6.5 users
simply replace the sendmail 8.9.1 NMPRG with the newer sendmail 8.12.1
NMPRGs.  The effort to get that kind of mixed environment working exceeds
the effort to just start from a clean slate with the full SMLGDT8A patch
which despite being officially for 7.0 will install just fine on 6.0 and
6.5.

So if you are running unsupported 8.9.1 and are sufficiently worried about
the recent sendmail bugs to be willing to change your sendmail environment,
here is what I recommend:

1) Back up any locally modified files in the SENDMAIL account

2) :PURGEACCT SENDMAIL

3) Unpack the SMLGDT8A patch bundle (sendmail 8.12.1 A.01.00) and copy
HFSSML to HFSSML.INSTALL.SYS

4) :STREAM IHFGDT8A

5) Unpack the SMLHD03A patch bundle (sendmail 8.12.1 A.01.01) and copy
SENDMAIL to SENDMAIL.A0100.SENDMAIL

6) :STREAM IHFHD03A

7) Reapply any local modifications from 1) above to the new config files in
/etc/mail.

8) :STREAM JDAEMON.PUB.SENDMAIL

I have personally tested this on a 6.0 machine.

Unfortunately SMLGDT8A has temporarily disappeared from the ITRC.  It should
reappear on Monday.  If you cannot wait until then, I have stashed an
unofficial copy at http://jazz.external.hp.com/src/sendmail/SMLGDT8A.store.

Note that 8.12.1 A.01.01 only fixes the first security problem announced at
the beginning of last month.

The second security problem announced a week ago is fixed by 8.12.1 A.01.02
which will soon be available (Monday?) as SMLHD15A for 7.0 and SMLHD16A for
7.5.  So you may want to wait a bit before doing the above procedure until
you can grab SMLHD15A instead of SMLHD03A.

- Mark B.

* To join/leave the list, search archives, change list settings, *
* etc., please visit http://raven.utc.edu/archives/hp3000-l.html *

ATOM RSS1 RSS2