From predisclosure-applications-bounces@lists.xenproject.org Tue Feb 02 05:09:15 2021
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Tue, 02 Feb 2021 05:09:15 +0000
Received: from list by lists.xenproject.org with outflank-mailman.80229.146920 (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l6nwA-0004Me-Cj; Tue, 02 Feb 2021 05:09:14 +0000
X-Outflank-Mailman: Message body and most headers restored to incoming version
Received: by outflank-mailman (output) from mailman id 80229.146920; Tue, 02 Feb 2021 05:09:14 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l6nwA-0004MZ-9l; Tue, 02 Feb 2021 05:09:14 +0000
Received: by outflank-mailman (input) for mailman id 80229;
 Mon, 01 Feb 2021 23:58:02 +0000
Received: from us1-rack-iad1.inumbo.com ([172.99.69.81])
 by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from
 <SRS0=f8Oz=HD=freebsd.org=philip@srs-us1.protection.inumbo.net>)
 id 1l6j4z-0003SG-Vd
 for predisclosure-applications@lists.xenproject.org;
 Mon, 01 Feb 2021 23:58:02 +0000
Received: from mx2.freebsd.org (unknown [2610:1c1:1:606c::19:2])
 by us1-rack-iad1.inumbo.com (Halon) with ESMTPS
 id 273b29eb-d490-452a-ad5c-7e41d743844a;
 Mon, 01 Feb 2021 23:58:00 +0000 (UTC)
Received: from mx1.freebsd.org (mx1.freebsd.org [96.47.72.80])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits)
 client-signature RSA-PSS (4096 bits))
 (Client CN "mx1.freebsd.org", Issuer "R3" (verified OK))
 by mx2.freebsd.org (Postfix) with ESMTPS id 4148F9F8B6
 for <predisclosure-applications@lists.xenproject.org>;
 Mon,  1 Feb 2021 23:57:59 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from smtp.freebsd.org (smtp.freebsd.org
 [IPv6:2610:1c1:1:606c::24b:4])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
 client-signature RSA-PSS (4096 bits) client-digest SHA256)
 (Client CN "smtp.freebsd.org", Issuer "R3" (verified OK))
 by mx1.freebsd.org (Postfix) with ESMTPS id 4DV4dM13Bfz3QcL;
 Mon,  1 Feb 2021 23:57:59 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from weatherwax.trouble.is (weatherwax.trouble.is
 [IPv6:2a00:1098:82:3a::1])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client CN "weatherwax.trouble.is", Issuer "R3" (verified OK))
 (Authenticated sender: philip/mail)
 by smtp.freebsd.org (Postfix) with ESMTPSA id 000302353A;
 Mon,  1 Feb 2021 23:57:58 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from rincewind.trouble.is (rincewind.trouble.is [95.216.22.234])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
 client-signature RSA-PSS (4096 bits) client-digest SHA256)
 (Client CN "rincewind.trouble.is", Issuer "R3" (verified OK))
 by weatherwax.trouble.is (Postfix) with ESMTPS id 4DV4dL0jDbz24DN;
 Mon,  1 Feb 2021 23:57:58 +0000 (UTC)
Received: by rincewind.trouble.is (Postfix, authenticated sender philip)
 id 4DV4dJ3RvVz6Kg9; Mon,  1 Feb 2021 23:57:56 +0000 (UTC)
X-BeenThere: predisclosure-applications@lists.xenproject.org
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Precedence: list
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>
X-Inumbo-ID: 273b29eb-d490-452a-ad5c-7e41d743844a
From: "Philip Paeps" <philip@freebsd.org>
To: predisclosure-applications@lists.xenproject.org
Cc: "FreeBSD Security Team" <secteam@freebsd.org>
Subject: FreeBSD would like to join the Xen pre-disclosure list
Date: Tue, 02 Feb 2021 07:57:51 +0800
X-Clacks-Overhead: GNU Terry Pratchett
X-Mailer: MailMate (1.14r5757)
Message-ID: <D33E4B0B-CCE3-48A7-9272-A0B6A340B0DA@freebsd.org>
MIME-Version: 1.0
Content-Type: multipart/signed;
 boundary="=_MailMate_63B6A887-CA1D-42BE-B1BC-81D840596864_=";
 micalg=pgp-sha512; protocol="application/pgp-signature"

This is an OpenPGP/MIME signed message (RFC 3156 and 4880).

--=_MailMate_63B6A887-CA1D-42BE-B1BC-81D840596864_=
Content-Type: text/plain; markup=markdown
Content-Transfer-Encoding: quoted-printable

Hello!

I write on behalf of security-officer@freebsd.org.

The FreeBSD Project has supported Xen for many years.  We are aware of at=
 least one large deployment.

Information about the current state of Xen on FreeBSD is in the FreeBSD H=
andbook: https://docs.freebsd.org/en/books/handbook/virtualization/#virtu=
alization-host-xen, and on the FreeBSD wiki: https://wiki.freebsd.org/Xen=
=2E  We also have a freebsd-xen mailing list https://lists.freebsd.org/ma=
ilman/listinfo/freebsd-xen.

Our Xen implementation lives here: https://cgit.freebsd.org/src/tree/sys/=
xen.

Information about the FreeBSD security-officer team lives here: https://w=
ww.freebsd.org/security/.

We would like to be subscribed (as security-officer@freebsd.org) to the X=
en pre-disclosure list please.  The requirements on the Xen security poli=
cy page https://xenproject.org/developers/security-policy/ match our way =
of working, specifically with respect to the handling of embargoed issues=
=2E

Many thanks for your consideration.

Philip

-- =

Philip Paeps
Senior Reality Engineer
Alternative Enterprises

--=_MailMate_63B6A887-CA1D-42BE-B1BC-81D840596864_=
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename=signature.asc
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE9Xl/y/HxTiwoqUh7fGK8R3bJ8p4FAmAYlX8ACgkQfGK8R3bJ
8p7zCQf+PoI2Uub+mHA0WRenNF4RhzMnrHzAr2xoLkc4I+ue9qlQgksbuqZeFlrF
7v8G7XJFqH3oIrhy2VLgzn+KLrjnACkIFVIeHDXuAyCqTnvicg90S21p4iGnona/
A/jCPEKp68S1vYC3IKitufm3QV+m/UzwDCYk2DGfKPUU/ujiXvOgBlSZ7Mi0/cB2
myeeKW91RE9eeWJMd3/XGCbMFJXGKybAmBtMlT+E0n1LXQBomJvtFs82JNp7G2KQ
kuIv/4ZdYqgnv7JuckSRhDoW+Pvz8tKUaAl0D5oki6cZ/jaIcxIJAifIbLoWbSqu
vrTMHqtut0y6PnNFq+DBhlj/gZMifg==
=z5ru
-----END PGP SIGNATURE-----

--=_MailMate_63B6A887-CA1D-42BE-B1BC-81D840596864_=--


From predisclosure-applications-bounces@lists.xenproject.org Tue Feb 02 15:56:57 2021
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Tue, 02 Feb 2021 15:56:57 +0000
Received: from list by lists.xenproject.org with outflank-mailman.80609.147519 (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l6y2x-0004s7-He; Tue, 02 Feb 2021 15:56:55 +0000
X-Outflank-Mailman: Message body and most headers restored to incoming version
Received: by outflank-mailman (output) from mailman id 80609.147519; Tue, 02 Feb 2021 15:56:55 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l6y2x-0004s3-Ed; Tue, 02 Feb 2021 15:56:55 +0000
Received: by outflank-mailman (input) for mailman id 80609;
 Tue, 02 Feb 2021 15:38:51 +0000
Received: from all-amaz-eas1.inumbo.com ([34.197.232.57]
 helo=us1-amaz-eas2.inumbo.com)
 by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from
 <SRS0=XIJv=HE=citrix.com=george.dunlap@srs-us1.protection.inumbo.net>)
 id 1l6xlS-0002zZ-SK
 for predisclosure-applications@lists.xenproject.org;
 Tue, 02 Feb 2021 15:38:50 +0000
Received: from esa1.hc3370-68.iphmx.com (unknown [216.71.145.142])
 by us1-amaz-eas2.inumbo.com (Halon) with ESMTPS
 id 09073243-85c7-490a-9292-4b66b3f68c00;
 Tue, 02 Feb 2021 15:38:49 +0000 (UTC)
X-BeenThere: predisclosure-applications@lists.xenproject.org
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Precedence: list
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>
X-Inumbo-ID: 09073243-85c7-490a-9292-4b66b3f68c00
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
  d=citrix.com; s=securemail; t=1612280329;
  h=from:to:cc:subject:date:message-id:references:
   in-reply-to:content-id:content-transfer-encoding:
   mime-version;
  bh=xm0b8KOi/yx03ZxCiLuqRwMVI6O2w+/+QZyBOTkmsD8=;
  b=Bgeh0nqH5zOAPSOztyMasIevlfw9tnKXOdmtrx+TP5g62kylIqSOnI1V
   k4SKdZzWHupbdDYTU8r/Xo+2U308tTHvEzAIiiK9wvPmdXEfbefiKGnNe
   0s8kqGY0EpMKbPAwTzAgt6+3jsUAc2hUwWZ+PQFozqczHUkhUm5l8qbBN
   Y=;
Authentication-Results: esa1.hc3370-68.iphmx.com; dkim=pass (signature verified) header.i=@citrix.onmicrosoft.com
IronPort-SDR: 1BVJfU49F6AFiK0cU1BZb8HHam4RH1ksTge+3qXA4/9oAr6FPSNcEfddHVg2PYpYu7xdd0hXEn
 ShTAaLbVJNzerBxVwGjky6cE7ZFVCSnlfBpr/3nI/yThsGIGmdTTcEiX/5/eoKPe11AgEBMKlb
 7ALHhRg4Ls6ddysFIuOC/DA99/REwq3NL7puAjIqMeqxA2iU7rJPeqNbe103xXDrASjVW6L/w6
 xk/k8F5bUKiiLvrgNpmjUKipn7sm6Iui8Ih5CCzTdVGyn/Lz0nI3hH9RNV8sHInANRP6962KLA
 Ahk=
X-SBRS: 5.2
X-MesageID: 36759485
X-Ironport-Server: esa1.hc3370-68.iphmx.com
X-Remote-IP: 162.221.156.83
X-Policy: $RELAYED
X-IronPort-AV: E=Sophos;i="5.79,395,1602561600"; 
   d="scan'208";a="36759485"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
 b=kV6MB1R1aWT5cvK7QRNvUSmG1oQLGo2DWN6zT2bE4vh/yrYPGBax54XiHKsNEdO3O3iC/XZVqcVTu5SPmxxVPOZnLwBd1R5aTyfabgeyFb+ivuuh9LLHaX0x4w5Uk3eW+g5iOj8xRF47o+Eqp6A1fYVGNd110B17JN9LLPMqLSawHMKUkj9L8g8aCKtOQ+AQXfdACZXQs/WororfLGOS1XZaFg+gIulj3kZQFIFXLczhl5yt9VCUnugBhnQ/7EEMVAZmSZf91eagP/czZHQcTlMUViTd2hqRlekcgzjscAmGhhdANOIbD0UaO7dilPSxSmMzqmuYlZKlncFTGFtkaQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
 s=arcselector9901;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=xm0b8KOi/yx03ZxCiLuqRwMVI6O2w+/+QZyBOTkmsD8=;
 b=UtU2uN6/RWKvPw/5H8R9UL9KNXMz30bSl7YHDJyXmLX956M2XGXs24qcKL7Wpz84P8ygIlibgyLklK1QSk9QeqsK8Ia87CZTq7NizY4ULFrsD/w0wr6PUiIZjU+Nj/nmCrNX1QaqqdQfPs5SJZhUldvdhsuuLtzREtKIr4iLC32V5qvFt+2IT9DONzWxdM0T8p3jxdj4rHZY+zMkI3maIZFSpwwhoRqjaZbyF8U5ckgXzhCdSSV9bE4uS1QSCYurLDLO6zXuPqT1me+xakkz/ubwvJ17f7YPGdZYDH6Iyw0q0cLyMXBdaKuX2vM5Od3UFcpeBkapWXldW0pPpODrYQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
 smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com;
 dkim=pass header.d=citrix.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=citrix.onmicrosoft.com; s=selector2-citrix-onmicrosoft-com;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=xm0b8KOi/yx03ZxCiLuqRwMVI6O2w+/+QZyBOTkmsD8=;
 b=I+x+0ux48QeXdAvUHi2rn0+UekQkuq3kzK77UDf24Zs+1UcjgEU09VzRvM3ZId8TJgZEVwQUC9FdfsI+bh0tXz5iiGtTc91MPUwTLEJC2S2CizApELP5Z9Un9mjzn75ppO1PeRmvlkVUfheNP0P1L8lUmEE+1nIQ/60C/LJ7uOM=
From: George Dunlap <George.Dunlap@citrix.com>
To: Philip Paeps <philip@freebsd.org>
CC: "predisclosure-applications@lists.xenproject.org"
	<predisclosure-applications@lists.xenproject.org>, FreeBSD Security Team
	<secteam@freebsd.org>
Subject: Re: FreeBSD would like to join the Xen pre-disclosure list
Thread-Topic: FreeBSD would like to join the Xen pre-disclosure list
Thread-Index: AQHW+SGiPXlXHkqGNEi6F7yUYu46JqpFAKgA
Date: Tue, 2 Feb 2021 15:38:32 +0000
Message-ID: <C0553DCE-15EA-470E-879A-85641FDF5E67@citrix.com>
References: <D33E4B0B-CCE3-48A7-9272-A0B6A340B0DA@freebsd.org>
In-Reply-To: <D33E4B0B-CCE3-48A7-9272-A0B6A340B0DA@freebsd.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3654.20.0.2.21)
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9ae7a6cd-9048-4161-afa2-08d8c7909920
x-ms-traffictypediagnostic: PH0PR03MB5685:
x-microsoft-antispam-prvs: <PH0PR03MB5685502331D0E3B0AE45700F99B59@PH0PR03MB5685.namprd03.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: kgOjM1/Ur4gOQCEjZhREs0LWyAKbVowUYvZiiF4vdVQPDX955bwjyXKiLE7pJgDdxPWpogEwCeNPm3NuPSiSHDJRu7/DzgGGGcSyosO4uaZyFK+sYNTHHOu7sWRCDEAjyqEhRIuLgHgH/CkI4oUNw1ZGBb4+8CWpbbOCpm+AZI0eKkd+LioCJ19S5BCMdtItBfN98UvKQC8xvBbZ0Z0vw4tw8w+MYaRzlSoK5hG46O9vIe3YHZ2uy2Kf/9Bq/O/G8Xykg7hFE62twnSWL7OEQB1w06bPg6POOgCRoNyegjufgwmlUD/INL9JH0acgxz0mOIY/3sKnJKxLOpqK7KfDmrJwLTKc28POsJYAfB8pEqoLuu+XEWUHuuuEn6qNSCvEIJ3vL6lmKSawRy+u38JMNyIstOjXs+kbBT342p/TKjOir505i8nqMronfBMEjaUlyixcYw9FXNo9IY9/zgeiul3TE/Acp2wkgjD5O4jUTo6UePt3aWAakdVXF5SxYJ60LeaI+Cjv+b3I2UCXepgy2M86tB/OUfxl1ZGqftV2w3MaHOfwwAc/HJ8b72aGn6w7jpN7S1ohpq3K2KMHvObrq7R/HetOyUWT4y6OB9/wo3lOm8Yh2NueZgr7lDvsELJLA2g0R2JPp2ZGWTsKnMhumaD6v10QWYHEOEdpIwB6j4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PH0PR03MB5669.namprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(4636009)(39860400002)(376002)(346002)(136003)(366004)(396003)(36756003)(64756008)(2616005)(316002)(66946007)(6506007)(66556008)(66446008)(66476007)(186003)(54906003)(91956017)(76116006)(5660300002)(26005)(71200400001)(8676002)(478600001)(8936002)(33656002)(6486002)(86362001)(6512007)(966005)(2906002)(4326008)(53546011)(83380400001)(6916009)(45980500001);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata: =?utf-8?B?SXZYR2NOVGQvWnRGZVR4UjlhRnQxUDUvcFBWU2hONk1xSFhqKzdENW9rNUl2?=
 =?utf-8?B?MW9sa0NIREZqTXZkMDZCa2xZU1I3OTE1eEx0SGJ3MnIwUFNvdkdsTzljZ0FQ?=
 =?utf-8?B?NUVOSGVBZnNyczlEUmNtQXpNVmM4THc4MkVUQ0h4M2ltWmhXVDVkRzNSc0xq?=
 =?utf-8?B?TXpmNFJjbmNReldhU2VpanM3b0FxWjRHd2xUUXBUdUJQSlc3elp1TTZMUFhy?=
 =?utf-8?B?OFc0TFNpWENtRmVyckpCM2FkaWdQVEVYSFRRdlVYcDZpMkNZTzBQbFR2WEph?=
 =?utf-8?B?YjBZNlNCOXQ5TTR6T2hxclRLYmlYM01xakVSeGI3S253empnKy9nT2RFTWZk?=
 =?utf-8?B?NGRad1VNTWxKYWJaV0hacDlVUVFSV0RHOERJN2Y1dmU3UU56ZzNSR1Y2Yk5h?=
 =?utf-8?B?SjFXWTUyZGZQQmc4NWVkdUtpbEsrblRVNkJoY082bVFsOUMzTVUrb2Nmamla?=
 =?utf-8?B?QS9sRERmVE9UWEcva3dnZFJNTkNyWE1sUGNUMnpuM2J3NnNzS0VPalBQLzhn?=
 =?utf-8?B?TUNSQU4yQ1FTbzR0NEJIZnNhVTdGR1psZTR5dU0vdnV4ODdPaUJYZGYyTlpi?=
 =?utf-8?B?WTU4c3dveVRidENNdDJBSkc2S2NtSitwYU95SnhMR3dwRXZTVm5najlSZzEx?=
 =?utf-8?B?MTMyTHRqL1pSWXNFUDRPSWk1ZVYwSGVDMUZzYXZuMEhNWHYwT3J4WEZEbWd4?=
 =?utf-8?B?ZDRqR2pHdUZ6WStzdDNITHVKTTMvbmNhakxtVU5LMlhQS1RwMGszNFpGYXVO?=
 =?utf-8?B?aHdwQ21SdTg3KzRxYnRsdnVQVDF6d1FJeGZXU1NDNkRhSVZBK0ovVmJITnV4?=
 =?utf-8?B?WWlDdkk4WUdxTFR2Nkx2VjEvMjdGLzVYMXRocWcvLzNaTFNiS1NlV0V6YTBl?=
 =?utf-8?B?SjFBSEpYWEUvdHZ2WGdnUEhUWnhFNEc0UFczcGZackNZNjYwbnpINXZ1TU9y?=
 =?utf-8?B?WHJ1dGZQYnlibVc0SmxYb1VLVmYrL2NpZVA0RVgwb2p0MG9qMXc2a0lkQnJU?=
 =?utf-8?B?anFaOWc0aDlXVHlaSGpnOXcvM015T1lBNFhNbTFNb3BhVzhrejZabDRtMnRj?=
 =?utf-8?B?VUw2ZVhaWWZFL3lDVllpdkZnNzh6WCtJaFUxcllTVlV2dDhxZlpYdUJKZ1Qx?=
 =?utf-8?B?Mk5VSW1uUzQySlJ0WlNjTlJjTVhFZUcwQ2wreXVxRHptUnVQdlhZVUJ4RWlr?=
 =?utf-8?B?MXVxckhuZnhmVFBIRENhZ2RNS0NBcGQyUkwvbmFCNEZ6ZmpDdzFBSStHNU5t?=
 =?utf-8?B?YnEzckxEaUcrS1JVSnAzY2s1eVRvZ200bWJYSEplb2M2TkRWb1dhTVRhcFpF?=
 =?utf-8?B?YUlQdmRtbFIrdU1xTlBSNzQ5c2tXQlo2c2VrUkNLN0FKNkZCNTRPdHkzN0lv?=
 =?utf-8?B?cm9LOXNoZmY1ZjBNemI4cERKenJ1UmdJanVyVmRlRlNPajdGVlJ1MzRtLzcr?=
 =?utf-8?B?cC9OVkFxek1YaW16QWt0bEl3R3dvUUpWcUExVEt3PT0=?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <F4FB750A5344D94998D1AB47605E909B@namprd03.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR03MB5669.namprd03.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9ae7a6cd-9048-4161-afa2-08d8c7909920
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Feb 2021 15:38:33.0064
 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 335836de-42ef-43a2-b145-348c2ee9ca5b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: VX0JnQ9/Dld9ciwSmjpqwVSE1Te26Dxs2HHYl5Nc5g1wyjYv0wITmjsNt0oBs4AEZ1d13Y5GgaNWAVIosSloo5YSicr72420NDJXG34En1Q=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR03MB5685
X-OriginatorOrg: citrix.com

UGhpbGlwLA0KDQpFdmVyeXRoaW5nIGxvb2tzIHRvIGJlIGluIG9yZGVyLCBleGNlcHQgZm9yIG9u
ZSB0aGluZy4uLg0KDQo+IE9uIEZlYiAxLCAyMDIxLCBhdCAxMTo1NyBQTSwgUGhpbGlwIFBhZXBz
IDxwaGlsaXBAZnJlZWJzZC5vcmc+IHdyb3RlOg0KPiANCj4gSGVsbG8hDQo+IA0KPiBJIHdyaXRl
IG9uIGJlaGFsZiBvZiBzZWN1cml0eS1vZmZpY2VyQGZyZWVic2Qub3JnLg0KPiANCj4gVGhlIEZy
ZWVCU0QgUHJvamVjdCBoYXMgc3VwcG9ydGVkIFhlbiBmb3IgbWFueSB5ZWFycy4gIFdlIGFyZSBh
d2FyZSBvZiBhdCBsZWFzdCBvbmUgbGFyZ2UgZGVwbG95bWVudC4NCj4gDQo+IEluZm9ybWF0aW9u
IGFib3V0IHRoZSBjdXJyZW50IHN0YXRlIG9mIFhlbiBvbiBGcmVlQlNEIGlzIGluIHRoZSBGcmVl
QlNEIEhhbmRib29rOiBodHRwczovL2RvY3MuZnJlZWJzZC5vcmcvZW4vYm9va3MvaGFuZGJvb2sv
dmlydHVhbGl6YXRpb24vI3ZpcnR1YWxpemF0aW9uLWhvc3QteGVuLCBhbmQgb24gdGhlIEZyZWVC
U0Qgd2lraTogaHR0cHM6Ly93aWtpLmZyZWVic2Qub3JnL1hlbi4gIFdlIGFsc28gaGF2ZSBhIGZy
ZWVic2QteGVuIG1haWxpbmcgbGlzdCBodHRwczovL2xpc3RzLmZyZWVic2Qub3JnL21haWxtYW4v
bGlzdGluZm8vZnJlZWJzZC14ZW4uDQo+IA0KPiBPdXIgWGVuIGltcGxlbWVudGF0aW9uIGxpdmVz
IGhlcmU6IGh0dHBzOi8vY2dpdC5mcmVlYnNkLm9yZy9zcmMvdHJlZS9zeXMveGVuLg0KPiANCj4g
SW5mb3JtYXRpb24gYWJvdXQgdGhlIEZyZWVCU0Qgc2VjdXJpdHktb2ZmaWNlciB0ZWFtIGxpdmVz
IGhlcmU6IGh0dHBzOi8vd3d3LmZyZWVic2Qub3JnL3NlY3VyaXR5Ly4NCj4gDQo+IFdlIHdvdWxk
IGxpa2UgdG8gYmUgc3Vic2NyaWJlZCAoYXMgc2VjdXJpdHktb2ZmaWNlckBmcmVlYnNkLm9yZykg
dG8gdGhlIFhlbiBwcmUtZGlzY2xvc3VyZSBsaXN0IHBsZWFzZS4gIFRoZSByZXF1aXJlbWVudHMg
b24gdGhlIFhlbiBzZWN1cml0eSBwb2xpY3kgcGFnZSBodHRwczovL3hlbnByb2plY3Qub3JnL2Rl
dmVsb3BlcnMvc2VjdXJpdHktcG9saWN5LyBtYXRjaCBvdXIgd2F5IG9mIHdvcmtpbmcsIHNwZWNp
ZmljYWxseSB3aXRoIHJlc3BlY3QgdG8gdGhlIGhhbmRsaW5nIG9mIGVtYmFyZ29lZCBpc3N1ZXMu
DQoNClNvcnJ5IHRvIGJlIHBlZGFudGljIGhlcmUsIGJ1dCB5b3UgZG9u4oCZdCBhY3R1YWxseSBz
dGF0ZSB0aGF0IHlvdSBhZ3JlZSB0byBhYmlkZSBieSBvdXIgcG9saWN5LiA6LSkgIElmIHlvdSBj
YW4ganVzdCByZXNwb25kIHRvIHRoaXMgZW1haWwgY29uZmlybWluZyB0aGF0IHlvdSBpbnRlbmQg
dG8gYWJpZGUgYnkgdGhlIHBvbGljeSwgd2XigJlsbCBhZGQgeW91IHRvIHRoZSBsaXN0Lg0KDQpQ
ZWFjZSwNCiAtR2VvcmdlIER1bmxhcA==


From predisclosure-applications-bounces@lists.xenproject.org Wed Feb 03 05:34:19 2021
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Wed, 03 Feb 2021 05:34:19 +0000
Received: from list by lists.xenproject.org with outflank-mailman.80737.148007 (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l7Anx-0007GX-48; Wed, 03 Feb 2021 05:34:17 +0000
X-Outflank-Mailman: Message body and most headers restored to incoming version
Received: by outflank-mailman (output) from mailman id 80737.148007; Wed, 03 Feb 2021 05:34:17 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l7Anx-0007GS-0H; Wed, 03 Feb 2021 05:34:17 +0000
Received: by outflank-mailman (input) for mailman id 80737;
 Tue, 02 Feb 2021 22:08:01 +0000
Received: from us1-rack-iad1.inumbo.com ([172.99.69.81])
 by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from
 <SRS0=TO56=HE=freebsd.org=philip@srs-us1.protection.inumbo.net>)
 id 1l73q5-0001kk-9g
 for predisclosure-applications@lists.xenproject.org;
 Tue, 02 Feb 2021 22:08:01 +0000
Received: from mx2.freebsd.org (unknown [2610:1c1:1:606c::19:2])
 by us1-rack-iad1.inumbo.com (Halon) with ESMTPS
 id 580df474-404f-4100-98c8-cf75a119064e;
 Tue, 02 Feb 2021 22:08:00 +0000 (UTC)
Received: from mx1.freebsd.org (mx1.freebsd.org [96.47.72.80])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits)
 client-signature RSA-PSS (4096 bits))
 (Client CN "mx1.freebsd.org", Issuer "R3" (verified OK))
 by mx2.freebsd.org (Postfix) with ESMTPS id E66EF7318D;
 Tue,  2 Feb 2021 22:07:58 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from smtp.freebsd.org (smtp.freebsd.org
 [IPv6:2610:1c1:1:606c::24b:4])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
 client-signature RSA-PSS (4096 bits) client-digest SHA256)
 (Client CN "smtp.freebsd.org", Issuer "R3" (verified OK))
 by mx1.freebsd.org (Postfix) with ESMTPS id 4DVf7y5qDzz4drm;
 Tue,  2 Feb 2021 22:07:58 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from weatherwax.trouble.is (weatherwax.trouble.is
 [IPv6:2a00:1098:82:3a::1])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client CN "weatherwax.trouble.is", Issuer "R3" (verified OK))
 (Authenticated sender: philip/mail)
 by smtp.freebsd.org (Postfix) with ESMTPSA id A3FC92D985;
 Tue,  2 Feb 2021 22:07:58 +0000 (UTC)
 (envelope-from philip@freebsd.org)
Received: from rincewind.trouble.is (rincewind.trouble.is [95.216.22.234])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
 client-signature RSA-PSS (4096 bits) client-digest SHA256)
 (Client CN "rincewind.trouble.is", Issuer "R3" (verified OK))
 by weatherwax.trouble.is (Postfix) with ESMTPS id 4DVf7x5Lr0z24t5;
 Tue,  2 Feb 2021 22:07:57 +0000 (UTC)
Received: by rincewind.trouble.is (Postfix, authenticated sender philip)
 id 4DVf7v5DCtz6KqH; Tue,  2 Feb 2021 22:07:55 +0000 (UTC)
X-BeenThere: predisclosure-applications@lists.xenproject.org
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Precedence: list
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>
X-Inumbo-ID: 580df474-404f-4100-98c8-cf75a119064e
From: "Philip Paeps" <philip@freebsd.org>
To: "George Dunlap" <George.Dunlap@citrix.com>
Cc: predisclosure-applications@lists.xenproject.org,
 "FreeBSD Security Team" <secteam@freebsd.org>
Subject: Re: FreeBSD would like to join the Xen pre-disclosure list
Date: Wed, 03 Feb 2021 06:07:52 +0800
X-Clacks-Overhead: GNU Terry Pratchett
X-Mailer: MailMate (1.14r5757)
Message-ID: <B602758A-C202-4338-B4AB-C0A2F21B5BD7@freebsd.org>
In-Reply-To: <C0553DCE-15EA-470E-879A-85641FDF5E67@citrix.com>
References: <D33E4B0B-CCE3-48A7-9272-A0B6A340B0DA@freebsd.org>
 <C0553DCE-15EA-470E-879A-85641FDF5E67@citrix.com>
MIME-Version: 1.0
Content-Type: multipart/signed;
 boundary="=_MailMate_1892DF33-F128-49CF-A869-A8373FB1A54F_=";
 micalg=pgp-sha512; protocol="application/pgp-signature"

This is an OpenPGP/MIME signed message (RFC 3156 and 4880).

--=_MailMate_1892DF33-F128-49CF-A869-A8373FB1A54F_=
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On 2021-02-02 23:38:32 (+0800), George Dunlap wrote:
> Everything looks to be in order, except for one thing...
>
>> On Feb 1, 2021, at 11:57 PM, Philip Paeps <philip@freebsd.org> wrote:
>>
>> Hello!
>>
>> I write on behalf of security-officer@freebsd.org.
>>
>> The FreeBSD Project has supported Xen for many years.  We are aware of=
 at least one large deployment.
>>
>> Information about the current state of Xen on FreeBSD is in the FreeBS=
D Handbook: https://docs.freebsd.org/en/books/handbook/virtualization/#vi=
rtualization-host-xen, and on the FreeBSD wiki: https://wiki.freebsd.org/=
Xen.  We also have a freebsd-xen mailing list https://lists.freebsd.org/m=
ailman/listinfo/freebsd-xen.
>>
>> Our Xen implementation lives here: https://cgit.freebsd.org/src/tree/s=
ys/xen.
>>
>> Information about the FreeBSD security-officer team lives here: https:=
//www.freebsd.org/security/.
>>
>> We would like to be subscribed (as security-officer@freebsd.org) to th=
e Xen pre-disclosure list please.  The requirements on the Xen security p=
olicy page https://xenproject.org/developers/security-policy/ match our w=
ay of working, specifically with respect to the handling of embargoed iss=
ues.
>
> Sorry to be pedantic here, but you don=E2=80=99t actually state that yo=
u agree to abide by our policy. :-)  If you can just respond to this emai=
l confirming that you intend to abide by the policy, we=E2=80=99ll add yo=
u to the list.

I appreciate the pedantry. :-)

Yes: I confirm that the FreeBSD security-officer team intends to abide by=
 the Xen security pre-disclosure policy.

Best wishes.
Philip

-- =

Philip Paeps
Senior Reality Engineer
Alternative Enterprises

--=_MailMate_1892DF33-F128-49CF-A869-A8373FB1A54F_=
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename=signature.asc
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE9Xl/y/HxTiwoqUh7fGK8R3bJ8p4FAmAZzTgACgkQfGK8R3bJ
8p53Zgf/fwiLhJw8gcf2ajqUGJ2KGo5Sdd8trja0/uNIgUQxqtG+UYCEhRi89Hh0
84lBCZrSN/S6Ivy9Z0K9oOVyc54vIKvGMtkjCmKtmiiZKt6Bj7XIH6uNyRT+n/xs
7iQXDR+jHub9wPVTYfam86h0HS8IUS9gBmjA5aK4PPpsawJ9dUOGFGMunpDyGRYC
a1JtJYJv51fcPFYvQFKnJyN9jbsze+m2nrtKGoSDgfzSRgE25etmJyegzzOrXnDI
HECoUN8Mo+KVu4iJBRbp2K/ZUVmfcclDKA18zpPlVCbJzs1ka0UXdq6KrPBUCKFl
uIkSOjQJ592pQCF6ZZS9Pdmwihp0pg==
=pt9L
-----END PGP SIGNATURE-----

--=_MailMate_1892DF33-F128-49CF-A869-A8373FB1A54F_=--


From predisclosure-applications-bounces@lists.xenproject.org Wed Feb 03 11:32:20 2021
Return-path: <predisclosure-applications-bounces@lists.xenproject.org>
Envelope-to: archives@lists.xenproject.org
Delivery-date: Wed, 03 Feb 2021 11:32:20 +0000
Received: from list by lists.xenproject.org with outflank-mailman.80883.148289 (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l7GOQ-0002Dm-ND; Wed, 03 Feb 2021 11:32:18 +0000
X-Outflank-Mailman: Message body and most headers restored to incoming version
Received: by outflank-mailman (output) from mailman id 80883.148289; Wed, 03 Feb 2021 11:32:18 +0000
Received: from localhost ([127.0.0.1] helo=lists.xenproject.org)
	by lists.xenproject.org with esmtp (Exim 4.92)
	(envelope-from <predisclosure-applications-bounces@lists.xenproject.org>)
	id 1l7GOQ-0002Di-KK; Wed, 03 Feb 2021 11:32:18 +0000
Received: by outflank-mailman (input) for mailman id 80883;
 Wed, 03 Feb 2021 11:30:31 +0000
Received: from mail.xenproject.org ([104.130.215.37])
 by lists.xenproject.org with esmtp (Exim 4.92)
 (envelope-from <iwj@xenproject.org>) id 1l7GMh-0002BT-Sy
 for predisclosure-applications@lists.xenproject.org;
 Wed, 03 Feb 2021 11:30:31 +0000
Received: from xenbits.xenproject.org ([104.239.192.120])
 by mail.xenproject.org with esmtp (Exim 4.92)
 (envelope-from <iwj@xenproject.org>) id 1l7GMh-0006jN-Px
 for predisclosure-applications@lists.xenproject.org;
 Wed, 03 Feb 2021 11:30:31 +0000
Received: from iwj (helo=mariner.uk.xensource.com)
 by xenbits.xenproject.org with local-bsmtp (Exim 4.92)
 (envelope-from <iwj@xenproject.org>) id 1l7GMh-0006uK-PG
 for predisclosure-applications@lists.xenproject.org;
 Wed, 03 Feb 2021 11:30:31 +0000
Received: from iwj by mariner.uk.xensource.com with local (Exim 4.89)
 (envelope-from <iwj@xenproject.org>)
 id 1l7GMa-0004nJ-F2; Wed, 03 Feb 2021 11:30:24 +0000
X-BeenThere: predisclosure-applications@lists.xenproject.org
List-Id: Applications for membership of Xen Security Advisories Pre-disclosure
 List <predisclosure-applications.lists.xenproject.org>
List-Unsubscribe: <https://lists.xenproject.org/mailman/options/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=unsubscribe>
List-Post: <mailto:predisclosure-applications@lists.xenproject.org>
List-Help: <mailto:predisclosure-applications-request@lists.xenproject.org?subject=help>
List-Subscribe: <https://lists.xenproject.org/mailman/listinfo/predisclosure-applications>, 
 <mailto:predisclosure-applications-request@lists.xenproject.org?subject=subscribe>
Errors-To: predisclosure-applications-bounces@lists.xenproject.org
Precedence: list
Sender: "Predisclosure-applications"
 <predisclosure-applications-bounces@lists.xenproject.org>
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=xenproject.org; s=20200302mail; h=References:In-Reply-To:Subject:Cc:CC:To:
	Date:Message-ID:Content-Transfer-Encoding:Content-Type:MIME-Version:From;
	bh=SUBZmvucBfqBxdCA6Cw2cTb4jr7nkF0gpxrpa2CVeRw=; b=ZZN4uzPJmIAlhL9/xmKFvGs6nV
	AHGBwedo0JXNZDa6IAZvP9fJrvQZsD5rdHCA6buLTBVfJQhA1AaYhzUoizotBZFQVdvAW5tE5yxvO
	zHthiwSfDpCXCKuXQbzP6E5cIFbA6xyq1mZoYvxSVgoBaZaOIS7uwaMKJBHYV06sodc8=;
From: Ian Jackson <iwj@xenproject.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <24602.35152.180582.134245@mariner.uk.xensource.com>
Date: Wed, 3 Feb 2021 11:30:24 +0000
To: FreeBSD Security Team <secteam@freebsd.org>
CC: George Dunlap <George.Dunlap@citrix.com>
Cc: Philip Paeps <philip@freebsd.org>,
    "predisclosure-applications\@lists.xenproject.org" <predisclosure-applications@lists.xenproject.org>,
Subject: Re: FreeBSD would like to join the Xen pre-disclosure list
In-Reply-To: <B602758A-C202-4338-B4AB-C0A2F21B5BD7@freebsd.org>
References: <D33E4B0B-CCE3-48A7-9272-A0B6A340B0DA@freebsd.org>
	<C0553DCE-15EA-470E-879A-85641FDF5E67@citrix.com>
	<B602758A-C202-4338-B4AB-C0A2F21B5BD7@freebsd.org>
X-Mailer: VM 8.2.0b under 24.5.1 (i686-pc-linux-gnu)

Philip Paeps writes ("Re: FreeBSD would like to join the Xen pre-disclosure list"):
> Yes: I confirm that the FreeBSD security-officer team intends to abide by the Xen security pre-disclosure policy.

Great, thanks.  I've added you to the list and sent you copies of the
four currently-outstanding advisories.

George, the web page needs updating too.

Regards,
Ian.



