Roadmap

Differences between revisions 79 and 80
Revision 79 as of 2009-06-02 21:25:03
Size: 11141
Editor: pool-71-114-226-254
Comment:
Revision 80 as of 2009-06-02 21:34:07
Size: 11185
Editor: pool-71-114-226-254
Comment: add bug reference for automated Debian-security fetch/try/build system
Deletions are marked like this. Additions are marked like this.
Line 141: Line 141:
  * https://bugs.launchpad.net/bugs/382945

Karmic

Blueprints

Documentation

  • The Security Team FAQ needs to be filled with answers to the various questions Ubuntu gets about security.

  • The Security Team KnowledgeBase need more to be written. Many ideas have already been listed there.

Investigations

Several ideas for possible work come from investigating existing the installed set of packages.

  • setuid: which programs are setuid and what may be needed to improve them.

  • measure how many bits of randomness are actually being used in kernel ASLR, compared to other ASLR implementations.
  • review ideas from brainstorm.

AppArmor Confinement

The following profiles have been identified and prioritized as targets for AppArmor confinement. Please note that a high priority does not indicate a committment to develop the profile during the current development cycle.

  • Top priority
  • Secondary priority
    • nmbd
    • winbind
    • spamassassin (spamd)
    • acroread (likely not possible due to constraints of agreement with Adobe)
  • Tertiary priority
    • dnsmasq (possibly P2 due to libvirt (talk to soren))
    • squid (possibly P2 (talk to elmo))
    • awstats
    • analog (in progress)

    • mailman
    • asterisk (universe)
    • exim4
    • nagios/nrpe
    • openssh-server (not easy, as users can spawn anything)
    • pidgin
    • mail clients (thunderbird, kmail, evolution) -- difficult
    • eog
    • totem
    • skype (likely not possible due to constraints of agreement)
    • ekiga
    • rhythmbox
  • Unspecified priority
    • portmap (low-effort)
    • rpc.statd (low-effort)
    • scripts that people tend to give sudo access. For example: apache2ctl, initscripts
    • munin

Unscheduled Wishlist Items

This area can be used to list ideas for future security work, or link to bugs that describe "Wishlist" issues.

Not Interested

  • hardened default config (Bastille-like). Check the compatibility of debian-bastille. Status: reviewed. what can be done in a default install is already being done


CategorySecurityTeam

SecurityTeam/Roadmap (last edited 2022-01-04 22:38:06 by rodrigo-zaiden)