Debian Weekly News - November 8th, 2005

Debian Weekly News - November 8th, 2005

Welcome to this year's 45th issue of DWN, the weekly newsletter for
the Debian community. Nathanael Nerode [1]tried to solve some of the
problems in KDE packages in testing, due to various transitions and
fixes. In Florida 150 defendants perhaps will be acquitted because a
breathalyser company [2]refused to turn over the source code of their
device despite of a judge's order.

Participating in the GPLv3 Process. Florian Weimer [3]wondered if the
Debian project or [4]Software in the Public Interest, Inc. is
participating in the creation process for the new [5]General Public
License. He believes that Debian should be involved to ensure that
license compatibility does not decrease substantially, and that things
like the purported anti-DRM clauses remain practical.

Linux-Info-Tag Dresden Event Report. [6]Meike Reichle and
[7]Alexander Schmehl wrote reports about the [8]Linux-Info-Tag
exhibition and conference that took place in Dresden, Germany at the
end of last month. Members of the Debian project ran a booth and gave
several talks there. The booth was ran together with people from

Debian GNU/kFreeBSD Live CD. Robert Millan [10]announced version 1.0
of Ging, the only live distribution based on [11]Debian GNU/kFreeBSD.
[12]Ging is using [13]KDE 3.4 as its desktop environment and
[14]includes a mixture of KDE and GNOME applications such as
Konqueror, GIMP, KOffice, Gaim and others.

Creating SSL Certificates on Debian. A user [15]documented the
creation and use of self signed SSL certificates to prevent browsers
from complaining about the certificates and describes in detail how
SSL certificates and a certification authority (CA) are created.
Distributing the CA certificate and configuring Apache to use the
newly created key and certificate are also described.

Debian Conference: Call for Papers. Andreas Schuldei [16]called for
papers for potential presentation to be given at this year's
[17]Debian Conference which will take place from the 14 May to the
22th 2006 in Oaxtepec, Mexico. Proposals will be accepted until
December 6th, 23h59 UTC, reviewed by the committee and accepted talks
will be published on December 20th.

Debian at Systems Exhibition. Erich Schubert [18]reported about the
Debian presence at this year's [19]Systems exhibition which was
organised and staffed by only a small number of Debian people. A few
people stopped by at the booth the morning he was around and asked
high-quality questions. More project members are needed for next
year's event.

Closing Bugs as Submitter? Jan Nordholz [20]wondered if it is desired
and possible to close ones own bug reports if they have been dealt
with accidently by a new upstream version or similar. Jeroen van
Wolffelaar [21]proposed to write add an explanation to the bug report
and let the maintainer deal with it. Henning Makholm [22]explained
that closing the bug report with the proper version pseudo-header is
the preferred method since version tracking is implemented.

Popular Debian Architectures. Petter Reinholdtsen [23]reported about
an increased visibility of non-x86 architectures in the [24]popularity
contest. The list of packages used around the globe is relevant
information that helps ordering the packages on the CDs, to make sure
the most popular packages end up on the first CDs.

Digital Key Revocation. Roberto Sanchez [25]wondered when he should
revoke his old GnuPG key since he has created a new one but all of his
former Debian work is signed with the old one, of course. Christoph
Berg [26]explained that he doesn't need to care about the Debian
archive since his packages carry the sponsor's signatures as the old
key is not included in the Debian keyring.

Dealing with OpenSSL and GPL. Sean Finney [27]reported that he
maintains a package that uses the [28]GNU GPL but links against
[29]OpenSSL and would like to convert it to use [30]GnuTLS. Hendrik
Sattler [31]added a pointer to the [32]compatibility layer that
intends to ease GnuTLS' integration with existing applications.

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * DSA 879: [33]gallery -- Privilege escalation.
 * DSA 880: [34]phpmyadmin -- Several vulnerabilities.
 * DSA 881: [35]openssl096 -- Cryptographic weakness.
 * DSA 882: [36]openssl095 -- Cryptographic weakness.
 * DSA 883: [37]thttpd -- Insecure temporary file.
 * DSA 884: [38]horde3 -- Insecure default installation.
 * DSA 885: [39]openvpn -- Several vulnerabilities.
 * DSA 886: [40]chmlib -- Several vulnerabilities.
 * DSA 887: [41]clamav -- Several vulnerabilities.
 * DSA 888: [42]openssl -- Cryptographic weakness.
 * DSA 889: [43]enigmail -- Information disclosure.

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive [44]recently or contain important updates.

 * [45]b2evolution -- Multilingual, multiuser, multi-blog engine.
 * [46]bse-alsa -- ALSA plugin for BEAST.
 * [47]comix -- GTK Comic Book Viewer.
 * [48]dares -- Rescue files from damaged CDs and DVDs
 * [49]gddrescue -- GNU data recovery tool Ddrescue.
 * [50]geximon -- Monitor for the exim MTA.
 * [51]ktorrent -- BitTorrent client for KDE.
 * [52]monodevelop-java -- Java plugin for MonoDevelop.
 * [53]papercut -- Simple and extensible NNTP server.
 * [54]polyglot -- Chess engine protocol adaptor to connect UCI
   protocol engines.
 * [55]portreserve -- Port reservation program.
 * [56]postgresql-8.1 -- Object-relational SQL database, version 8.1
 * [57]ssmping -- Checks your multicast connectivity.
 * [58]tcpxtract -- Extracts files from network traffic based on file
 * [59]uruk -- Very small firewall script, for configuring iptables.
 * [60]yum -- Advanced front-end for rpm.

