/srv/irclogs.ubuntu.com/2023/06/02/#ubuntu-security.txt

=== JanC_ is now known as JanC
tewardsarnold: nice call on that 'security' nginx bug that wasnt a security issue OR a bug.01:48
tewardbad for you though i know you're around. you may or may not have incoming.01:49
* sarnold hides01:49
sarnoldteward: it might still be a bug of some sort if whatever tool requests those certs was busted on the upgrade and didn't run or something01:50
tewardsarnold: true, but Invalid for nginx and certbot/letsencrypt is a snap now so01:50
sarnoldah :)01:50
tewardserver team triage guideline for nginx when the issue is a non-package, local config issue is Invalid + general explanation based on the error in systemctl output01:51
tewardit irks me people file these as security bugs tho >.<01:51
=== JanC_ is now known as JanC
sarnoldyeah, you know how it goes, folks don't know if it is or isn't, and they want to do the right thing02:04
sarnoldwhat *really* grinds my gears is the guys reporting "hey ftp.ubuntu.com is open" "yes, thats how we distribute ubuntu, thanks" "surely my hard work deserves rewards"02:04
tewardsarnold: well we call those people certain unseemly words behind their backs so :p02:24
tewardversus me where I just torture you with the reminders of the mailman3 MIR that made you rage xD02:24
* sarnold flips a table02:25
teward**so which of us is worse :P**02:25
sarnoldteward: honestly, the *first* time hearing from any of these guys is one thing, they're looking for security problems and reporting them.. but some of these dudes have zero reading comprehension and keep reporting non-issues and demanding payment for it over and over again..02:25
=== JanC_ is now known as JanC
tewardsarnold: so reply to them with @canonical address saying "Canonical and Ubuntu do not have bug or security bounty programs, you will receive nothing if that is your intention."02:27
teward:P02:27
sarnoldteward: every. single. time. I copy-and-paste the paragraph from https://ubuntu.com/security/disclosure-policy and give them the link every time and it makes no difference.02:30
teward*leaves the button that says "Ban With Orbital Strikes" on the ground in front of sarnold*02:31
sarnoldhehe02:32
ebarrettoricotz, my colleague will be sponsoring it. Sorry for the delay on this, it has been a busy week, but hopefully monday it will be released. Thanks again for providing the debdiffs, it is very much appreciated! 12:27
ricotzebarretto, thank you, and don't worry; I can imagine the workload coming due to esm-apps12:55
ripaI want to Host a MEA2N  (Mongo + Express + A2+ Node) Stack app on aws free tier...16:41
ripaI came across SELinux and Apparmor.16:41
ripaI understand SElinux is harder to config16:41
ripaPlease advice16:41
sdezielripa: on Ubuntu, it will be simpler to stick with Apparmor as that's the default LSM17:44
ripathanks.. i feel you are right..17:45
ripai am reading up on apparmor profiles17:45
ripalearnt a new abbrev. LSM :)17:49
ripathanks sdeziel17:49
sdezielripa: np, FYI some packages come with ready made profiles but it's usually easy to create your own17:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!