Security and Functional Flaw Reporting » History » Version 7

Andreas Steffen, 23.05.2013 13:09
Describe security flaw handling process

1 1 Andreas Steffen
h1. Security and Functional Flaw Reporting
2 1 Andreas Steffen
3 1 Andreas Steffen
h2. Security Flaws
4 1 Andreas Steffen
5 2 Andreas Steffen
 * Please email any security-relevant flaw to the special mail account **. Whenever possible encrypt your posting using the "PGP key": for the ** account.
6 1 Andreas Steffen
7 7 Andreas Steffen
 * For high and medium severity vulnerabilities we are going to apply for a CVE number first. Next we notify all known strongSwan customers and the major Linux distributions, giving them a time of about three weeks to patch their their software release. On predetermined date we officially issue a patch for the vulnerability and usually a new stable strongSwan release containing the security fix. Also the CVE entry will published.
8 7 Andreas Steffen
9 7 Andreas Steffen
 * Minor vulnerabilities usually will be fixed immediately and the corresponding patch will be posted on the strongSwan mailing list.
10 7 Andreas Steffen
11 6 Andreas Steffen
 * Here is the list of all reported strongSwan high and medium security flaws registered in the "CVE database": which were fixed by the following "security patches":
12 4 Andreas Steffen
13 1 Andreas Steffen
h2. Functional Flaws
14 1 Andreas Steffen
15 2 Andreas Steffen
 * Please report all non-security-related flaws and bugs by opening a "new issue": in our wiki. If you don't have a user account yet, please "register": first.
16 3 Andreas Steffen
17 3 Andreas Steffen
 * Our Redmine Tracker classifies user issues into the following three categories:
18 1 Andreas Steffen
19 4 Andreas Steffen
   * *Issue*:  Please choose this generic category if you are not sure whether your problem is caused by a strongSwan misconfiguration, an interoperability problem with third party VPN software or an actual bug in the strongSwan code. We are going to reclassify your report after a first analysis.
20 3 Andreas Steffen
21 1 Andreas Steffen
   * *Feature*:  Please choose this category for requesting new features that we might implement in future versions of the strongSwan software.
22 3 Andreas Steffen
23 4 Andreas Steffen
   * *Bug*:  Please post under this category only if you are quite sure that you identified a bug in the strongSwan code, e.g. if the charon daemon crashes which it shouldn't. Of course it is helpful if you can already pinpoint the code file where you suspect the bug or in the case of a crash to provide a backtrack analysis of the core dump. User patches fixing flaws are always welcome.