#1 (permalink)  
Old 06-17-2005, 10:09 AM
Registered User
 
Join Date: Jun 2005
Posts: 1
ndial is on a distinguished road
OpenSSL banner / PCI compliance

For my company's latest compliance audit, we had a vulnerability test run against our server. The test reports that we're running Openssl 0.9.7a and that there is a "High" security risk related to that.

From speaking to other cPanel users and reading the forums, I've learned that cPanel builds a "patched version" and that even though the hbanner says 0.9.7a, it's really got the fix for that vulnerability.

So ...
1) how can I know that for sure, besides taking peoples' word for it, and

2) Where is some documentation to back it up, suitable for presenting in an audit report?

3) if it happens to really be running an older, unpatched version of openSSL, is there ay way in cPanel to fix it?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-17-2005, 11:04 AM
Registered User
 
Join Date: Jun 2003
Posts: 280
richy is on a distinguished road
No, it's not cPanel, it's RedHat that "back ports" security patches.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-17-2005, 11:30 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Indeed. You will find the relevant information over on redhat.com, though their site is a nightmare to navigate.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:23 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc