[KLUG Members] SSL patch

Bruce Smith members@kalamazoolinux.org
17 Sep 2002 11:51:49 -0400


It _appears_ to me that Redhat has already fixed this by patching an
older version of OpenSSL.

http://rhn.redhat.com/errata/RHSA-2002-160.html

Can anyone verify if that fixes the worm?

> I need to patch a couple of OpenSSL installs.  I ssh'ed to the boxes and
> downloaded Openssl-0.9.6g.tar.gz and untarred it ( I don't have the make
> programs on those boxen, so I will have to put that in too).
> 
> My question is what is the best method for the Upgrade path, as opposed
> to installing everything like it was fresh?  What will this do to my
> keys?  Do I need to recreate the keys too?


--------------------------------------------
Bruce Smith                bruce@armintl.com
System Administrator / Network Administrator
Armstrong International, Inc.
Three Rivers, Michigan  49093  USA
http://www.armstrong-intl.com/
--------------------------------------------