TaoSecurity.com Exclusive: Keeping FreeBSD Up-To-Date

I am happy to announce the publication at TaoSecurity.com of Keeping FreeBSD Up-To-Date. I wrote this article to answer questions I've received over the past few months on how to apply security fixes to a FreeBSD system. While the official Handbook is excellent, I thought a case-study approach would be enlightening for some readers.

I thought it would be interesting to see a box begin life as FreeBSD 5.2.1 RELEASE, and then progress through a variety of security fixes applied in different ways. The article's sections include:

  • Introduction

  • FreeBSD Versions

  • Learning About Security Issues

  • Starting with the Installation

  • Binary OS and Userland Updates with FreeBSD Update

  • Applying Kernel Patches Manually

  • Applying Userland Patches Manually, Part 1

  • Applying Userland Patches Manually, Part 2

  • CVSup to 5_2 Security Branch

  • Beyond the Security Branch

  • STABLE: The End of the Line

  • The "Next" STABLE

  • Conclusion

  • Acknowledgements

  • References


Sections show commands to run, explanations of what they do, sample output, uname versions, and pros and cons of each upgrade method. Please send feedback to taosecurity at gmail dot com.

I do not discussing optimizing the kernel, although this site does.

Comments

Anonymous said…
Just wanted to thank you for taking the time to write this article. I'm new to FreeBSD and had some problems grokking the handbook and man pages on this topic. This article squared me away and I can move forward on updating my system at home.

Only thing I can contribute is noting the typo in the first paragraph. I know you meant defensible instead of definisble.
Thanks for the typo fix!
Anonymous said…
This comment has been removed by a blog administrator.

Popular posts from this blog

Zeek in Action Videos

New Book! The Best of TaoSecurity Blog, Volume 4

MITRE ATT&CK Tactics Are Not Tactics