Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Registered User
    Join Date
    Jun 2005
    Posts
    1

    Default OpenSSL banner / PCI compliance

    For my company's latest compliance audit, we had a vulnerability test run against our server. The test reports that we're running Openssl 0.9.7a and that there is a "High" security risk related to that.

    From speaking to other cPanel users and reading the forums, I've learned that cPanel builds a "patched version" and that even though the hbanner says 0.9.7a, it's really got the fix for that vulnerability.

    So ...
    1) how can I know that for sure, besides taking peoples' word for it, and

    2) Where is some documentation to back it up, suitable for presenting in an audit report?

    3) if it happens to really be running an older, unpatched version of openSSL, is there ay way in cPanel to fix it?

  2. #2
    Member
    Join Date
    Jun 2003
    Posts
    280

    Default

    No, it's not cPanel, it's RedHat that "back ports" security patches.

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Indeed. You will find the relevant information over on redhat.com, though their site is a nightmare to navigate.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. PCI Compliance
    By richardsonchris in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-21-2011, 09:04 AM
  2. PCI Compliance
    By mickalo in forum E-mail Discussions
    Replies: 2
    Last Post: 08-20-2009, 01:34 PM
  3. OpenSSL, Exim Version problems for PCI-Compliance
    By jlhost in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-21-2008, 02:20 PM
  4. pci compliance help
    By EWD in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 05-30-2008, 12:34 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube