[COLUG] Companies that support a custom distribution

R P Herrold herrold at owlriver.com
Fri Apr 4 10:28:41 EST 2008


On Thu, 3 Apr 2008, Jeff Frontz wrote:

> Has anyone heard of any company that can, given a list of 
> packages/RPMs/whatever, create a distribution and provide 
> some amount of support for it (perhaps along the lines of 
> monitoring CERT, etc., looking for the intersection of any 
> critical bug reports with said list of packages, applying 
> fixes/updates, and performing a modicum of testing on the 
> result)?

Well, of course, this is what I do through Owl River Company, 
all day every day, with CentOS, as one of its founders, as its 
security point of contact, and with my work for many years as 
the editor of the RPM web presence.

As to spinning and maintaining a custom distribution, I have 
done these for many years for customers:
    http://www.owlriver.com/support/wings/

and also to support non-mainstream processor arches.  Reduced 
package count line, and custom LTSP distributions for customer 
needs, and then 'spike' packagings of 'hard to solve' package 
groups -- bioinformatics, complex perl applications, are well 
reflected at:
    http://www.owlriver.com/projects/ORC/

which is where we place the open license packagings sources 
masters done for clients [to meet and satisfy GPL 
obligations].

CERT is less relevant than CVE fixes [CERT lags and is VERY 
scanty in what it covers]; I also serve on the non-public 
'vendor-sec' Linux distribution group, which is really where 
the pre-release security remediation is done and coordinated 
in Linux space.

-- Russ herrold
 	614 488 6954


More information about the colug432 mailing list