Finish editorial review of Security Advisory section.

Sponsored by: iXsystems
This commit is contained in:
Dru Lavigne 2014-03-21 18:12:30 +00:00
parent 766e88e8a5
commit 2c1ea62fef
Notes: svn2git 2020-12-08 03:00:23 +00:00
svn path=/head/; revision=44315

View file

@ -3172,13 +3172,29 @@ You are advised to update or deinstall the affected package(s) immediately.</pro
<primary>&os; Security Advisories</primary>
</indexterm>
<para>Like many production quality operating systems, &os;
publishes <quote>Security Advisories</quote>. These
advisories are usually mailed to the security lists and noted
in the Errata only after the appropriate releases have been
patched. This section explains what an advisory is, how to
understand it, and what measures to take in order to patch a
system.</para>
<para>Like many producers of quality operating systems, the &os;
Project has a security team which is responsible for
determining the End-of-Life (<acronym>EoL</acronym>) date for each
&os; release and to provide security updates for supported
releases which have not yet reached their
<acronym>EoL</acronym>. More information about the &os;
security team and the supported releases is available on the
<link xlink:href="&url.base;/security">&os; security
page</link>.</para>
<para>One task of the security team is to respond to reported
security vulnerabilities in the &os; operating system. Once a
vulnerability is confirmed, the security team verifies the steps
necessary to fix the vulnerability and updates the source code
with the fix. It then publishes the details as a
<quote>Security Advisory</quote>. Security
advisories are published on the <link
xlink:href="&url.base;/security/advisories.html">&os; website</link>
and mailed to the &a.security-notifications.name;,
&a.security.name;, and &a.announce.name; mailing lists.</para>
<para>This section describes the format of a &os;
security advisory.</para>
<sect2>
<title>What Does an Advisory Look Like?</title>