dCache security bulletin 20090822

Short security bulletin (22 Aug 2009)

In the aftermath of the most recent SRM/dCache code vulnerability (reported 27 July 2009) dCache.org created a mailling-list, dedicated to security related information :
security at dcache dot org
 dCache administrators are supposed to use this mailing-list to report issues
  • which may be related to security problems (code vulnerabilities, attacks, etc)
  • where the e-mail may contain confidential information of the reporting site (passwords, firewall configuration, etc)
The membership of the mailing list is very restricted. Members don't have any obligations except to dCache.org and are familiar with LCG and OSG security mechanisms.

In this context I would like to thank Linda Cornwall, Ake Sandgren and Eygene Ryabinkin from GSVG and Mine Altunay from OSG for their fast and thoughtful help.



Patrick Fuhrmann, DESY Hamburg, dCache.org, patrick.fuhrmann@desy.de