Web Hosting Talk







View Full Version : New patches on Cobalt site... anyone has installed them?


jaime
08-22-2001, 07:34 PM
Hello,


there are new patches released on Cobalt Website.

Has anyone installed them?


Raq3: 1 update:
http://ftp.cobalt.com/pub/packages/raq3/eng/RaQ3-All-Security-4.0.1-10750.pk
g telnetupdate

Ra4: 2 updates:
2:
http://ftp.cobalt.com/pub/packages/raq4/eng/RaQ4-All-Security-1.0.1-10750.pk
g telnetupdate
1:
http://ftp.cobalt.com/pub/packages/raq4/eng/RaQ4-All-Security-1.0.1-10602.pk
g APACHE update to 1.3.20 GREAT.................

Come on Cobalt.... go for an Apache update for the Raq3 ......

mikeknoxv
08-22-2001, 07:46 PM
I believe my coworker installed them with no troubles. But don't take my word for it.

Starhost
08-23-2001, 04:59 AM
wHY DOESN'T THE RAQ 3 Get's an update for apache? We also want to update our apache version, because the one wich is installed on a Raq3 Really SUCKS!!

dutchie
08-23-2001, 07:12 AM
Whats wrong with it Starhost, it works fine for me, as far as i can tell..

jaime
08-23-2001, 07:50 AM
Originally posted by dutchie
Whats wrong with it Starhost, it works fine for me, as far as i can tell..

In cobalt.com they say that the PKG has been released to update Apache to 1.3.20 (Apache version 1.3.12 is the default in a raq4 if I am not wrong) due to various security fixes for issues that were found in prior releases of Apache for the Sun Cobalt Server Appliance.

So, do you think that the ancient Apache 1.3.6 installed in thousands of raq3 does not have those security bugs? ...

Version 1.3.6 is a "prior releare of Apache for the Sun Cobalt Server Appliance" as the state there...

Would be great to let raq3 customers to have the possibility to update Apache easily via a PKG and not to have to install it manually...

jaime
08-23-2001, 08:23 AM
Taken from Cobalt-Security mailing list:

> > Bug found in Security Update: Apache Update 1.0.1.
> >
> > Cobalt and Chilisoft are working on the problem, but are advising
everyone
> > to not install the update. Apache changed the way it gets files and
messed
> > up the publishing capabilities of the RaQ web manager.
>
> >From my understanding, this only effects users who are running 3.6.x of
> Chilisoft, which is not available to the general public for the Cobalt
> platform. This issue is currently being investigated with the Chilisoft
> team. Some users who have contacted Chilisoft support in the past may
> have version 3.6 running on their boxes, but most users have version
> 3.5.2, which doesn't seem to be effected.
>
> Jeff
>
> --
> Jeff Lovell
> Sun Microsystems Inc.

Marty
08-23-2001, 02:58 PM
Word is that rackshack has serveral customers with dead boxes due to the apache update.

Honu
08-23-2001, 03:01 PM
Originally posted by Marty
Word is that rackshack has serveral customers with dead boxes due to the apache update.

what kind of dead ???
is this on raq4 or the 3's

I installed the updates and no probs on a 4 ????

Marty
08-23-2001, 03:45 PM
What I have heard is rumor. It was posted on the rackshack forum. The only first hand reports I have are from people like you that said it went fine. But somebody posted that upon installation, apache would not restart, and that an uninstall did not help. I don't know if it is true, but this is the main reason that I wait a week or so after a patch is posted.

brandonk
08-23-2001, 03:46 PM
I have installed the telnet updates on both a RaQ3 and RaQ4 without any problems. (anyone actually using telnet should switch to SSH)

But, the apache update isn't something I'll be installing till I hear word from others. That's a big change, and we all know how cobalt throws those patches together...

broken
08-23-2001, 03:47 PM
It only affects users that have upgraded their Chilisoft ASP to version 3.6. Everyone else shouldn't have any problems at all.

Installed both on 4 RaQ4i's - no problems....PHEW!

Honu
08-23-2001, 05:12 PM
Aloha
well installed both packages
I have telnet disabled and use ssh
I rebooted puter and it came back up OK
on a raq41 at rackshack.net no problems with me for updates
so the apache update I had no prob with

Matthew.A
08-24-2001, 04:28 AM
Phew - I got Chilisoft ASP 3.6 glad I not donw the install yet - I'll wait and see what happens!!!!!

texasweb
08-24-2001, 10:17 AM
I did both packages on my Raq4 with no problems.

sbrad
08-24-2001, 02:45 PM
I have telnet disabled and use ssh
I have telnet and SSH installed. How do i disable telnet?

Marty
08-24-2001, 03:34 PM
Log into your admin panel. Click Control panel and then uncheck the check box next to telnet. Save settings. Try to telnet in and see what happens.

sbrad
08-24-2001, 03:44 PM
Log into your admin panel. Click Control panel and then uncheck the check box next to telnet. Save settings. Try to telnet in and see what happens.
I'm sorry. I guess I should re-phrase the question.
If I delete telnet in the admin control panel, does this remove the allow or disallow shell access from the individual users? Or, by checking allow shell access on accounts, does this just make them use ssh?

mikeknoxv
08-24-2001, 04:35 PM
If you disable telnet you will not be disabling SSH. As long as your users have /bin/sh in the /etc/passwd file they will have SSH access.

If you remove telnet access you are disallowing the use of telnet to obtain access to your server. I don't believe checking "Allow shell access" will work if your telnet server is disabled.

Help any?

nexzt
08-24-2001, 07:53 PM
5 out of 6 raq's went through the apache update.. the one that didn't come back up was never touched.. brand new out of the box.. Anyway they just powered it down and powered back up and it came back online.. other then that the patches were fine.. these were on RS raqs.

mikeknoxv
08-24-2001, 08:18 PM
Weird. The techs over at #Rackshack on irc.ev1.net I talked to didn't reccomend installing the update.

Honu
08-24-2001, 08:32 PM
Originally posted by mikeknoxv
Weird. The techs over at #Rackshack on irc.ev1.net I talked to didn't reccomend installing the update.

Aloha
did they say why or was this for a raq 3 or raq4 ???