From predisclosure-applications-bounces@lists.xenproject.org Fri Nov 16 16:13:47 2018
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Fri, 16 Nov 2018 16:13:47 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.89)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1gNgkb-0005jX-T1; Fri, 16 Nov 2018 16:13:45 +0000
Received: from us1-rack-dfw2.inumbo.com ([104.130.134.6])
 by lists.xenproject.org with esmtp (Exim 4.89) (envelope-from
 <srs0=gvv7=n3=gmail.com=lars.kurth.xen@srs-us1.protection.inumbo.net>)
 id 1gNgka-0005jS-LJ
 for predisclosure-applications@lists.xenproject.org;
 Fri, 16 Nov 2018 16:13:44 +0000
X-Inumbo-ID: 960ad9b9-e9ba-11e8-9a16-bc764e045a96
Received: from mail-wm1-x32d.google.com (unknown [2a00:1450:4864:20::32d])
 by us1-rack-dfw2.inumbo.com (Halon) with ESMTPS
 id 960ad9b9-e9ba-11e8-9a16-bc764e045a96;
 Fri, 16 Nov 2018 16:13:43 +0000 (UTC)
Received: by mail-wm1-x32d.google.com with SMTP id f2-v6so21519001wme.3
 for <predisclosure-applications@lists.xenproject.org>;
 Fri, 16 Nov 2018 08:13:43 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
 h=from:message-id:mime-version:subject:date:in-reply-to:cc:to
 :references; bh=U1evVaLgReWHeTbCSlD+SQWdSE81L29CgCGncbh8Yc0=;
 b=mqT5/i1q8WTnfWIcBoV84gHVpUd/lptVBl5FsxC3ehSy+I3IsL7GDWhRFGpx75zKUF
 D7kfZnBtqCObODq90Gvzu1dal0hUonXOXRJwgwvapSSLks66oQx2CYNNh8fIqFimYh+F
 hWOU7ZG6d2Y3w6z0Tm1ydQDQ5DYVy8HHxZO3rJiCd/letXGsn41gTEfSsn/P3eptUxLH
 BgmjfA7lj6B5MJ/KjD0SOrchUgFtmvjrvJfG9m9jj91rXi7721TYXfWQJv6rBukc/6fu
 hANuV7en7xxEQgMhsyg7wn+HJGK8aBsh0q5WPcu1R0S33xONSHoOE7ycm6XnpAykyetR
 dtfQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:message-id:mime-version:subject:date
 :in-reply-to:cc:to:references;
 bh=U1evVaLgReWHeTbCSlD+SQWdSE81L29CgCGncbh8Yc0=;
 b=CxivWekWdKvwiI8QCuebmWCb/cT+acB1ATE7VRI3F6dQ1weT9s76cwm1KscZK7qRBe
 ZNKAX2IhCKZHOxi/KFtya7MuRq2z56ivVxMGsxq5avStYmwr0lHRArmB+bearFyqfiF9
 /kA9IrJC2Nm0QngVLdjIkF712CHqiLdzGIyM1a1TjCdb4316CcHQfMAID0Y/A6Gk5Awa
 TWoVluwfLlg1AViKvLVvhc5uUXADjZB95pwQKcfDZ//zNWSkcN1mTxs0aJcwJdMQmojY
 O3NH/UwkIO/MD+lbQ/WmYk0KxyaV9PMB5lhux8WfGCBI/d8D3vazPvJyc2rDiQEyG3rU
 v5JQ==
X-Gm-Message-State: AGRZ1gIY6DVn0sXpO946sCcem8hxt3fgVT1TgFZeUnLFstPoUizcP0an
 tSWVHv5+M4FylIiGhUzIatlVuKwd
X-Google-Smtp-Source: AFSGD/XExzFiBP87BKXvGbZGaCSaxk7Z5duaMuj10y79nkHPAnzy7+2eIh/2S0Uq1R+5qdyAZ+kTbg==
X-Received: by 2002:a1c:63c2:: with SMTP id
 x185-v6mr2817509wmb.27.1542384821892; 
 Fri, 16 Nov 2018 08:13:41 -0800 (PST)
Received: from [192.168.0.8] (bcdc6e31.skybroadband.com. [188.220.110.49])
 by smtp.gmail.com with ESMTPSA id k5-v6sm46375854wre.82.2018.11.16.08.13.40
 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
 Fri, 16 Nov 2018 08:13:41 -0800 (PST)
From: Lars Kurth <lars.kurth.xen@gmail.com>
X-Google-Original-From: Lars Kurth <lars.kurth@xenproject.org>
Message-Id: <1B743C07-8007-4950-A37C-BBDA2368520C@xenproject.org>
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Date: Fri, 16 Nov 2018 16:13:40 +0000
In-Reply-To: <1042-5bd85c80-f-78f3d800@197757784>
To: contact@xcp-ng.org
References: <1042-5bd85c80-f-78f3d800@197757784>
X-Mailer: Apple Mail (2.3445.9.1)
Subject: Re: [Predisclosure-applications] XCP-ng predisclosure list
 application
X-BeenThere: predisclosure-applications@lists.xenproject.org
X-Mailman-Version: 2.1.23
Precedence: list
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Cc: predisclosure-applications@lists.xenproject.org
Content-Type: multipart/mixed; boundary="===============8700129644243245246=="
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>


--===============8700129644243245246==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_61B5D1F6-7951-4583-946F-B98374E6DDCE"


--Apple-Mail=_61B5D1F6-7951-4583-946F-B98374E6DDCE
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hi Olivier,

thanks for the submission and apologies for the delay in responding. The =
application looks mostly in order, but there are a few gaps/questions. =
Looking at the application, it is not 100% clear whether you are =
applying , as

* service/software provider, to=20
* as an open-source project

because you specify both https://xcp-ng.com <https://xcp-ng.com/> & =
security@xcp-ng.com <mailto:security@xcp-ng.com> and https://xcp-ng.org =
<https://xcp-ng.org/> & security@xcp-ng.org <mailto:security@xcp-ng.org> =
in the application
I am assuming you are applying as an open source project. Please =
confirm.

For the application, we are missing=20

Information about your handling of security problems:
* Your invitation to members of the public, who discover security =
problems with your products/services, to report them in confidence to =
you;
* Specifically, the contact information (email addresses or other =
contact instructions) which such a member of the public should use.

You can find an example in =
https://lists.xenproject.org/archives/html/predisclosure-applications/2017=
-07/msg00000.html =
<https://lists.xenproject.org/archives/html/predisclosure-applications/201=
7-07/msg00000.html>

Thank you and Regards
Lars

> On 30 Oct 2018, at 13:27, contact@xcp-ng.org wrote:
>=20
> Hello everyone,
>=20
> I'm Olivier Lambert, project leader for XCP-ng project =
(https://xcp-ng.org). This project is aimed to deliver a turnkey Open =
Source virtualization platform. It's currently based on XenServer, and =
we started to contribute to Xen/XAPI and its ecosystem (and more will =
come). You can find all the public work done on it here: =
https://github.com/xcp-ng
>=20
> Since our first release, we are at about 15k+ unique downloads, and we =
can assume safely it starts to be used by thousand people and =
organizations now.
>=20
> This is why being included in this pre-disclosure list is important =
for the project: this way, we could be pro-active and deliver patches =
quickly (note that we deliver patching via a signed RPM repo, a simple =
`yum update` do the trick for our users).
>=20
> We already have a dedicated security contact email: =
security@xcp-ng.org so this is the one we'd like to have enabled for =
this pre-disclosure list.
>=20
> We (limited people having access to the security inbox) have read this =
pre-disclosure policy and agree to abide by the terms for inclusion in =
the list, including the requirements regarding confidentiality during an =
embargo period.
> Note: we also offer pro support for XCP-ng, cf https://xcp-ng.com
> We also have a security@xcp-ng.com but IDK if it's relevant to have =
both on the ML. Up to you, I don't mind having just the .org email =
there.
> =20
> Let me know if you need anything else for me to be registered there.
>=20
> Best,
>=20
> Olivier Lambert
> _______________________________________________
> Predisclosure-applications mailing list
> Predisclosure-applications@lists.xenproject.org
> =
https://lists.xenproject.org/mailman/listinfo/predisclosure-applications


--Apple-Mail=_61B5D1F6-7951-4583-946F-B98374E6DDCE
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><span=
 style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D"">Hi =
Olivier,</span><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><span style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D"">thanks for the submission and apologies for the delay =
in responding. The application looks mostly in order, but there are a =
few gaps/questions. Looking at the application, it is not 100% clear =
whether you are applying , as</span><br style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D""><br style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D""><span style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D"">* service/software provider, =
to&nbsp;</span><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><span style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D"">* as an open-source project</span><br =
style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D""><br =
style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D"">because =
you specify both&nbsp;</span><a href=3D"https://xcp-ng.com" =
style=3D"font-family: Menlo-Regular; font-size: 11px;" =
class=3D"">https://xcp-ng.com</a><span style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D"">&nbsp;&amp;&nbsp;</span><a =
href=3D"mailto:security@xcp-ng.com" style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">security@xcp-ng.com</a><span =
style=3D"font-family: Menlo-Regular; font-size: 11px;" =
class=3D"">&nbsp;and&nbsp;</span><a href=3D"https://xcp-ng.org" =
style=3D"font-family: Menlo-Regular; font-size: 11px;" =
class=3D"">https://xcp-ng.org</a><span style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D"">&nbsp;&amp;&nbsp;</span><a =
href=3D"mailto:security@xcp-ng.org" style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">security@xcp-ng.org</a><span =
style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D"">&nbsp;in=
 the application</span><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><span style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">I am assuming you are applying as an open =
source project. Please confirm.</span><br style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D""><br style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D""><span style=3D"font-family: =
Menlo-Regular; font-size: 11px;" class=3D"">For the application, we are =
missing&nbsp;</span><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><span style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D"">Information about your handling of security =
problems:</span><br style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D""><span style=3D"font-family: Menlo-Regular; font-size: =
11px;" class=3D"">* Your invitation to members of the public, who =
discover security problems with your products/services, to report them =
in confidence to you;</span><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><span style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">* Specifically, the contact information =
(email addresses or other contact instructions) which such a member of =
the public should use.</span><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><span style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">You can find an example in&nbsp;</span><a =
href=3D"https://lists.xenproject.org/archives/html/predisclosure-applicati=
ons/2017-07/msg00000.html" style=3D"font-family: Menlo-Regular; =
font-size: 11px;" =
class=3D"">https://lists.xenproject.org/archives/html/predisclosure-applic=
ations/2017-07/msg00000.html</a><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><br style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D""><span style=3D"font-family: Menlo-Regular; =
font-size: 11px;" class=3D"">Thank you and Regards</span><br =
style=3D"font-family: Menlo-Regular; font-size: 11px;" class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 11px;" =
class=3D"">Lars</span><br class=3D""><div style=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On 30 =
Oct 2018, at 13:27, <a href=3D"mailto:contact@xcp-ng.org" =
class=3D"">contact@xcp-ng.org</a> wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div class=3D""><div =
class=3D"msg-body"><div layout=3D"row" layout-wrap=3D"layout-wrap" =
class=3D"layout-wrap layout-row"><div ng-class=3D"::part.msgclass" =
class=3D"layout-wrap layout-row msg-attachment-other mailer_mailcontent" =
layout-wrap=3D"layout-wrap" layout=3D"row" ng-repeat=3D"part in =
viewer.message.$content()"><div ng-if=3D"::part.html" class=3D"md-flex =
sg-mail-part" ng-bind-html=3D"part.content | ensureTarget" =
ng-click=3D"viewer.filterMailtoLinks($event)" tabindex=3D"-1" =
role=3D"button"><div class=3D"SOGoHTMLMail-CSS-Delimiter =
mailer_htmlcontent"><p class=3D"">Hello everyone,<br class=3D""><br =
class=3D"">I'm Olivier Lambert, project leader for XCP-ng project (<a =
href=3D"https://xcp-ng.org" class=3D"">https://xcp-ng.org</a>). This =
project is aimed to deliver a turnkey Open Source virtualization =
platform. It's currently based on XenServer, and we started to =
contribute to Xen/XAPI and its ecosystem (and more will come). You can =
find all the public work done on it here: <a =
href=3D"https://github.com/xcp-ng" =
class=3D"">https://github.com/xcp-ng</a><br class=3D""><br =
class=3D"">Since our first release, we are at about 15k+ unique =
downloads, and we can assume safely it starts to be used by thousand =
people and organizations now.<br class=3D""><br class=3D"">This is why =
being included in this pre-disclosure list is important for the project: =
this way, we could be pro-active and deliver patches quickly (note that =
we deliver patching via a signed RPM repo, a simple `yum update` do the =
trick for our users).<br class=3D""><br class=3D"">We already have a =
dedicated security contact <a href=3D"mailto:security@xcp-ng.org" =
class=3D"">email: security@xcp-ng.org</a> so this is the one we'd like =
to have enabled for this pre-disclosure list.</p><pre class=3D""><span =
style=3D"font-family:Verdana,Geneva,sans-serif;" class=3D"">We (limited =
people having access to the security inbox) have read this =
pre-disclosure policy and agree to abide by the terms for inclusion in =
the list, including the requirements regarding confidentiality during an =
embargo period.</span></pre><div class=3D"">Note: we also offer pro =
support for XCP-ng, cf <a href=3D"https://xcp-ng.com" =
class=3D"">https://xcp-ng.com</a></div><div class=3D"">We also have a <a =
href=3D"mailto:security@xcp-ng.com" class=3D"">security@xcp-ng.com</a> =
but IDK if it's relevant to have both on the ML. Up to you, I don't mind =
having just the .org email there.</div><div class=3D"">&nbsp;</div><div =
class=3D"">Let me know if you need anything else for me to be registered =
there.<br class=3D""><br class=3D"">Best,<br class=3D""><br =
class=3D"">Olivier Lambert</div></div></div></div></div></div></div>
_______________________________________________<br =
class=3D"">Predisclosure-applications mailing list<br class=3D""><a =
href=3D"mailto:Predisclosure-applications@lists.xenproject.org" =
class=3D"">Predisclosure-applications@lists.xenproject.org</a><br =
class=3D"">https://lists.xenproject.org/mailman/listinfo/predisclosure-app=
lications</div></blockquote></div><br class=3D""></body></html>=

--Apple-Mail=_61B5D1F6-7951-4583-946F-B98374E6DDCE--


--===============8700129644243245246==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KUHJlZGlzY2xv
c3VyZS1hcHBsaWNhdGlvbnMgbWFpbGluZyBsaXN0ClByZWRpc2Nsb3N1cmUtYXBwbGljYXRpb25z
QGxpc3RzLnhlbnByb2plY3Qub3JnCmh0dHBzOi8vbGlzdHMueGVucHJvamVjdC5vcmcvbWFpbG1h
bi9saXN0aW5mby9wcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9ucw==

--===============8700129644243245246==--


From predisclosure-applications-bounces@lists.xenproject.org Fri Nov 16 21:19:53 2018
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Fri, 16 Nov 2018 21:19:53 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.89)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1gNlWp-0005fX-NC; Fri, 16 Nov 2018 21:19:51 +0000
Received: from us1-rack-dfw2.inumbo.com ([104.130.134.6])
 by lists.xenproject.org with esmtp (Exim 4.89) (envelope-from
 <srs0=u/r8=n3=bounce.vates.fr=bounce-md_30504962.5bef3472.v1-9db9b0830bf54799b45b29e0ce922174@srs-us1.protection.inumbo.net>)
 id 1gNlWo-0005fS-5n
 for predisclosure-applications@lists.xenproject.org;
 Fri, 16 Nov 2018 21:19:50 +0000
X-Inumbo-ID: 585ee130-e9e5-11e8-9a16-bc764e045a96
Received: from mail180-9.suw31.mandrillapp.com (unknown [198.2.180.9])
 by us1-rack-dfw2.inumbo.com (Halon) with ESMTPS
 id 585ee130-e9e5-11e8-9a16-bc764e045a96;
 Fri, 16 Nov 2018 21:19:47 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=mandrill; d=vates.fr; 
 h=From:Subject:To:Cc:Message-Id:In-Reply-To:References:Date:MIME-Version:Content-Type:Content-Transfer-Encoding;
 i=olivier.lambert@vates.fr; 
 bh=zD4pjMEMtpgvRICpyyB+8CmfmmAC9+veLgiBpTRuI2Y=;
 b=Y14iD/gzXjOsxmMwK+EWYRuxpnbmVizeu8SLDSpABWPS9VSfkT4x+1Ynq9Zsj3PyEoP1l0PpouOy
 WnSA5wVnbj4GT164tGs8iLTVUBaauBcEpglXrPySzi6bk3n0i5Kkl6xX5jGrvJHlh5B0iLYG+Jh7
 uxLeDl/wXU55jaeRKWQ=
Received: from pmta03.mandrill.prod.suw01.rsglab.com (127.0.0.1) by
 mail180-9.suw31.mandrillapp.com id htsq7822sc0l for
 <predisclosure-applications@lists.xenproject.org>;
 Fri, 16 Nov 2018 21:19:46 +0000 (envelope-from
 <bounce-md_30504962.5bef3472.v1-9db9b0830bf54799b45b29e0ce922174@bounce.vates.fr>)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandrillapp.com; 
 i=@mandrillapp.com; q=dns/txt; s=mandrill; t=1542403186; h=From : 
 Subject : To : Cc : Message-Id : In-Reply-To : References : Date : 
 MIME-Version : Content-Type : Content-Transfer-Encoding : From : 
 Subject : Date : X-Mandrill-User : List-Unsubscribe; 
 bh=zD4pjMEMtpgvRICpyyB+8CmfmmAC9+veLgiBpTRuI2Y=; 
 b=OdpmF40f5tNlK1rR2b4INkbZQQBI3V9ew0W6BlKz2aTk8l+9UfB7H1/LgWZSm5gGRR7pZe
 K4bVRLckQC0hKcbt2RMww2pRRcV9+MvcMN2Ten5+y7OhHvea3x+UIHHgJrXwPATCiKmDtc0R
 IqTsT8iSwLoPKnO+x8y304EfQ9L4w=
From: Olivier Lambert <olivier.lambert@vates.fr>
Received: from [212.129.1.64] by mandrillapp.com id
 9db9b0830bf54799b45b29e0ce922174; Fri, 16 Nov 2018 21:19:46 +0000
X-Virus-Scanned: amavisd-new at plam.fr
X-Originating-Ip: [212.129.1.64]
X-Mailer: Zimbra 8.8.10_GA_3713 (ZimbraWebClient - FF63 (Linux)/8.8.10_GA_3041)
To: Lars Kurth <lars.kurth.xen@gmail.com>
Message-Id: <1615907909.703.1542403173539.JavaMail.zimbra@vates.fr>
In-Reply-To: <1B743C07-8007-4950-A37C-BBDA2368520C@xenproject.org>
References: <1042-5bd85c80-f-78f3d800@197757784>
 <1B743C07-8007-4950-A37C-BBDA2368520C@xenproject.org>
X-Report-Abuse: Please forward a copy of this message, including all headers,
 to abuse@mandrill.com
X-Report-Abuse: You can also report abuse here:
 http://mandrillapp.com/contact/abuse?id=30504962.9db9b0830bf54799b45b29e0ce922174
X-Mandrill-User: md_30504962
Date: Fri, 16 Nov 2018 21:19:46 +0000
MIME-Version: 1.0
Subject: Re: [Predisclosure-applications] XCP-ng predisclosure list
 application
X-BeenThere: predisclosure-applications@lists.xenproject.org
X-Mailman-Version: 2.1.23
Precedence: list
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Cc: predisclosure-applications@lists.xenproject.org,
 contact <contact@xcp-ng.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>

SGkgTGFycywKCjEuIEFzIGFuIE9wZW4gU291cmNlIHByb2plY3Qgd291bGQgbWFrZSBtb3JlIHNl
bnNlIEkgc3VwcG9zZSwgeWVzLgoyLiAiWW91ciBpbnZpdGF0aW9uIHRvIG1lbWJlcnMgb2YgdGhl
IHB1YmxpYywgd2hvIGRpc2NvdmVyIHNlY3VyaXR5IHByb2JsZW1zIHdpdGggeW91ciBwcm9kdWN0
cy9zZXJ2aWNlcywgdG8gcmVwb3J0IHRoZW0gaW4gY29uZmlkZW5jZSB0byB5b3U7IiBhbHJlYWR5
IGRvbmUgaGVyZTogY2hlY2sgdGhlICJTZWN1cml0eSBhbmQgbWlycm9ycyIgdGFiIGluIHRoZSB4
Y3Atbmcub3JnIHdlYnNpdGUsICJGb3VuZCBhIHNlY3VyaXR5IHByb2JsZW0gaW4gWENQLW5nPyBQ
bGVhc2UgZW1haWwgdXMgb24gc2VjdXJpdHkgYXQgeGNwLW5nIGRvdCBvcmciLiBJZiB5b3Ugd2Fu
dCBhIGJldHRlciAoYnV0IHN0aWxsIGNvbmNpc2UpIHdvcmRpbmcsIGxldCBtZSBrbm93IDopCgoK
QmVzdCwKCi0tCgpPbGl2aWVyIExhbWJlcnQKQ28tZm91bmRlciAtIENFTwpYQ1AtbmcgJiBYZW4g
T3JjaGVzdHJhIC0gVmF0ZXMgc29sdXRpb25zCgoKaHR0cHM6Ly94Y3AtbmcuY29tIGh0dHBzOi8v
eGVuLW9yY2hlc3RyYS5jb20KCi0tLS0tIE1haWwgb3JpZ2luYWwgLS0tLS0KRGU6ICJMYXJzIEt1
cnRoIiA8bGFycy5rdXJ0aC54ZW5AZ21haWwuY29tPgrDgDogImNvbnRhY3QiIDxjb250YWN0QHhj
cC1uZy5vcmc+CkNjOiBwcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9uc0BsaXN0cy54ZW5wcm9qZWN0
Lm9yZwpFbnZvecOpOiBWZW5kcmVkaSAxNiBOb3ZlbWJyZSAyMDE4IDE3OjEzOjQwCk9iamV0OiBS
ZTogW1ByZWRpc2Nsb3N1cmUtYXBwbGljYXRpb25zXSBYQ1AtbmcgcHJlZGlzY2xvc3VyZSBsaXN0
IGFwcGxpY2F0aW9uCgpIaSBPbGl2aWVyLAoKdGhhbmtzIGZvciB0aGUgc3VibWlzc2lvbiBhbmQg
YXBvbG9naWVzIGZvciB0aGUgZGVsYXkgaW4gcmVzcG9uZGluZy4gVGhlIGFwcGxpY2F0aW9uIGxv
b2tzIG1vc3RseSBpbiBvcmRlciwgYnV0IHRoZXJlIGFyZSBhIGZldyBnYXBzL3F1ZXN0aW9ucy4g
TG9va2luZyBhdCB0aGUgYXBwbGljYXRpb24sIGl0IGlzIG5vdCAxMDAlIGNsZWFyIHdoZXRoZXIg
eW91IGFyZSBhcHBseWluZyAsIGFzCgoqIHNlcnZpY2Uvc29mdHdhcmUgcHJvdmlkZXIsIHRvIAoq
IGFzIGFuIG9wZW4tc291cmNlIHByb2plY3QKCmJlY2F1c2UgeW91IHNwZWNpZnkgYm90aCBodHRw
czovL3hjcC1uZy5jb20gPGh0dHBzOi8veGNwLW5nLmNvbS8+ICYgc2VjdXJpdHlAeGNwLW5nLmNv
bSA8bWFpbHRvOnNlY3VyaXR5QHhjcC1uZy5jb20+IGFuZCBodHRwczovL3hjcC1uZy5vcmcgPGh0
dHBzOi8veGNwLW5nLm9yZy8+ICYgc2VjdXJpdHlAeGNwLW5nLm9yZyA8bWFpbHRvOnNlY3VyaXR5
QHhjcC1uZy5vcmc+IGluIHRoZSBhcHBsaWNhdGlvbgpJIGFtIGFzc3VtaW5nIHlvdSBhcmUgYXBw
bHlpbmcgYXMgYW4gb3BlbiBzb3VyY2UgcHJvamVjdC4gUGxlYXNlIGNvbmZpcm0uCgpGb3IgdGhl
IGFwcGxpY2F0aW9uLCB3ZSBhcmUgbWlzc2luZyAKCkluZm9ybWF0aW9uIGFib3V0IHlvdXIgaGFu
ZGxpbmcgb2Ygc2VjdXJpdHkgcHJvYmxlbXM6CiogWW91ciBpbnZpdGF0aW9uIHRvIG1lbWJlcnMg
b2YgdGhlIHB1YmxpYywgd2hvIGRpc2NvdmVyIHNlY3VyaXR5IHByb2JsZW1zIHdpdGggeW91ciBw
cm9kdWN0cy9zZXJ2aWNlcywgdG8gcmVwb3J0IHRoZW0gaW4gY29uZmlkZW5jZSB0byB5b3U7Ciog
U3BlY2lmaWNhbGx5LCB0aGUgY29udGFjdCBpbmZvcm1hdGlvbiAoZW1haWwgYWRkcmVzc2VzIG9y
IG90aGVyIGNvbnRhY3QgaW5zdHJ1Y3Rpb25zKSB3aGljaCBzdWNoIGEgbWVtYmVyIG9mIHRoZSBw
dWJsaWMgc2hvdWxkIHVzZS4KCllvdSBjYW4gZmluZCBhbiBleGFtcGxlIGluIGh0dHBzOi8vbGlz
dHMueGVucHJvamVjdC5vcmcvYXJjaGl2ZXMvaHRtbC9wcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9u
cy8yMDE3LTA3L21zZzAwMDAwLmh0bWwgPGh0dHBzOi8vbGlzdHMueGVucHJvamVjdC5vcmcvYXJj
aGl2ZXMvaHRtbC9wcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9ucy8yMDE3LTA3L21zZzAwMDAwLmh0
bWw+CgpUaGFuayB5b3UgYW5kIFJlZ2FyZHMKTGFycwoKPiBPbiAzMCBPY3QgMjAxOCwgYXQgMTM6
MjcsIGNvbnRhY3RAeGNwLW5nLm9yZyB3cm90ZToKPiAKPiBIZWxsbyBldmVyeW9uZSwKPiAKPiBJ
J20gT2xpdmllciBMYW1iZXJ0LCBwcm9qZWN0IGxlYWRlciBmb3IgWENQLW5nIHByb2plY3QgKGh0
dHBzOi8veGNwLW5nLm9yZykuIFRoaXMgcHJvamVjdCBpcyBhaW1lZCB0byBkZWxpdmVyIGEgdHVy
bmtleSBPcGVuIFNvdXJjZSB2aXJ0dWFsaXphdGlvbiBwbGF0Zm9ybS4gSXQncyBjdXJyZW50bHkg
YmFzZWQgb24gWGVuU2VydmVyLCBhbmQgd2Ugc3RhcnRlZCB0byBjb250cmlidXRlIHRvIFhlbi9Y
QVBJIGFuZCBpdHMgZWNvc3lzdGVtIChhbmQgbW9yZSB3aWxsIGNvbWUpLiBZb3UgY2FuIGZpbmQg
YWxsIHRoZSBwdWJsaWMgd29yayBkb25lIG9uIGl0IGhlcmU6IGh0dHBzOi8vZ2l0aHViLmNvbS94
Y3AtbmcKPiAKPiBTaW5jZSBvdXIgZmlyc3QgcmVsZWFzZSwgd2UgYXJlIGF0IGFib3V0IDE1aysg
dW5pcXVlIGRvd25sb2FkcywgYW5kIHdlIGNhbiBhc3N1bWUgc2FmZWx5IGl0IHN0YXJ0cyB0byBi
ZSB1c2VkIGJ5IHRob3VzYW5kIHBlb3BsZSBhbmQgb3JnYW5pemF0aW9ucyBub3cuCj4gCj4gVGhp
cyBpcyB3aHkgYmVpbmcgaW5jbHVkZWQgaW4gdGhpcyBwcmUtZGlzY2xvc3VyZSBsaXN0IGlzIGlt
cG9ydGFudCBmb3IgdGhlIHByb2plY3Q6IHRoaXMgd2F5LCB3ZSBjb3VsZCBiZSBwcm8tYWN0aXZl
IGFuZCBkZWxpdmVyIHBhdGNoZXMgcXVpY2tseSAobm90ZSB0aGF0IHdlIGRlbGl2ZXIgcGF0Y2hp
bmcgdmlhIGEgc2lnbmVkIFJQTSByZXBvLCBhIHNpbXBsZSBgeXVtIHVwZGF0ZWAgZG8gdGhlIHRy
aWNrIGZvciBvdXIgdXNlcnMpLgo+IAo+IFdlIGFscmVhZHkgaGF2ZSBhIGRlZGljYXRlZCBzZWN1
cml0eSBjb250YWN0IGVtYWlsOiBzZWN1cml0eUB4Y3Atbmcub3JnIHNvIHRoaXMgaXMgdGhlIG9u
ZSB3ZSdkIGxpa2UgdG8gaGF2ZSBlbmFibGVkIGZvciB0aGlzIHByZS1kaXNjbG9zdXJlIGxpc3Qu
Cj4gCj4gV2UgKGxpbWl0ZWQgcGVvcGxlIGhhdmluZyBhY2Nlc3MgdG8gdGhlIHNlY3VyaXR5IGlu
Ym94KSBoYXZlIHJlYWQgdGhpcyBwcmUtZGlzY2xvc3VyZSBwb2xpY3kgYW5kIGFncmVlIHRvIGFi
aWRlIGJ5IHRoZSB0ZXJtcyBmb3IgaW5jbHVzaW9uIGluIHRoZSBsaXN0LCBpbmNsdWRpbmcgdGhl
IHJlcXVpcmVtZW50cyByZWdhcmRpbmcgY29uZmlkZW50aWFsaXR5IGR1cmluZyBhbiBlbWJhcmdv
IHBlcmlvZC4KPiBOb3RlOiB3ZSBhbHNvIG9mZmVyIHBybyBzdXBwb3J0IGZvciBYQ1AtbmcsIGNm
IGh0dHBzOi8veGNwLW5nLmNvbQo+IFdlIGFsc28gaGF2ZSBhIHNlY3VyaXR5QHhjcC1uZy5jb20g
YnV0IElESyBpZiBpdCdzIHJlbGV2YW50IHRvIGhhdmUgYm90aCBvbiB0aGUgTUwuIFVwIHRvIHlv
dSwgSSBkb24ndCBtaW5kIGhhdmluZyBqdXN0IHRoZSAub3JnIGVtYWlsIHRoZXJlLgo+ICAKPiBM
ZXQgbWUga25vdyBpZiB5b3UgbmVlZCBhbnl0aGluZyBlbHNlIGZvciBtZSB0byBiZSByZWdpc3Rl
cmVkIHRoZXJlLgo+IAo+IEJlc3QsCj4gCj4gT2xpdmllciBMYW1iZXJ0Cj4gX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KPiBQcmVkaXNjbG9zdXJlLWFwcGxp
Y2F0aW9ucyBtYWlsaW5nIGxpc3QKPiBQcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9uc0BsaXN0cy54
ZW5wcm9qZWN0Lm9yZwo+IGh0dHBzOi8vbGlzdHMueGVucHJvamVjdC5vcmcvbWFpbG1hbi9saXN0
aW5mby9wcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9ucwoKCl9fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fClByZWRpc2Nsb3N1cmUtYXBwbGljYXRpb25zIG1haWxp
bmcgbGlzdApQcmVkaXNjbG9zdXJlLWFwcGxpY2F0aW9uc0BsaXN0cy54ZW5wcm9qZWN0Lm9yZwpo
dHRwczovL2xpc3RzLnhlbnByb2plY3Qub3JnL21haWxtYW4vbGlzdGluZm8vcHJlZGlzY2xvc3Vy
ZS1hcHBsaWNhdGlvbnM=

