[pkg-kolab] Bug#629350: Bug#629350: STARTTLS vulnerability in kolab-cyrus-imapd

Ondřej Surý ondrej at sury.org
Thu Jun 9 08:24:24 UTC 2011

On Thu, Jun 9, 2011 at 00:10, Mathieu Parent <math.parent at gmail.com> wrote:
> 2011/6/8 Moritz Muehlenhoff <jmm at inutil.org>:
> ...
>> Why is kolab-cyrus-imapd a separate source package? Can we fix it for Wheezy
>> to be built from a unified source package, i.e. a separate build target which
>> applies the seven Kolab patches?
> Yes, this is the way to go.
> Those 7 patches are not synced with upstream Kolab.
> [...]
> After those two, kolabd can
> depend on cyrus-imapd-2.4 and kolab-cyrus-imapd can be dropped. A
> README.kolab may be included in the cyrus-imapd pacjage to list the
> not-applied patches.

I don't think that's what Moritz had on the mind (although it would be
nice to have it).

The way to go now would be to override dh_auto_configure/build/install
to build the cyrus-imapd-2.x twice - once without kolab patches and
second time with them.

I'll try what I can do, but I'll need help from kolab team.

Ondřej Surý <ondrej at sury.org>

More information about the pkg-kolab-devel mailing list