Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Jun 2004
    Posts
    58

    Default PCI Compliancy - openssl & openssh

    I am trying to get past the PCI Compliancy checks that Controlscan does and two issues are flagged, openssl and openssh. Both are flagged as being version levels to old and insecure openssl 0.9.7a should be 0.9.7l, and openssh 3.9 should be 4.7.
    What I'd like to know is are the current version of openssl and openssh with Centos 4.6 already patched but nobody has changed the release number, and where can I find information on this to back my case to stating such.

    If they are not patched and I need to install a more current version of openssl and openssh, how and can I do this with my current cpanel and apach 2.2 ?

  2. #2
    cPanelBilly
    Guest

    Default

    These are automatically updated by your system (unless you turned that off in the update settings). Since you are using CentOS which is a derivative of RHEL and RH uses back patches rather than releasing the new binaries most likely you are already patched.

  3. #3
    Member
    Join Date
    Jun 2004
    Posts
    58

    Default

    Is there a way I can tell this, and use that info to answer the audit?

  4. #4
    Member
    Join Date
    Jan 2005
    Posts
    13

    Default

    This might be a little late, but here is the command in case anyone needs it.

    rpm -q --changelog openssl
    This will show what was applied to the openssl package. Just show proof that the patch was applied and they should OK the update.

    Ryan

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by rgyure View Post
    This might be a little late, but here is the command in case anyone needs it.



    This will show what was applied to the openssl package. Just show proof that the patch was applied and they should OK the update.

    Ryan
    Thanks! Handy command.

  6. #6
    Member
    Join Date
    Jan 2003
    Posts
    61

    Default how do you update openssl?

    Quote Originally Posted by cPanelBilly View Post
    These are automatically updated by your system (unless you turned that off in the update settings). Since you are using CentOS which is a derivative of RHEL and RH uses back patches rather than releasing the new binaries most likely you are already patched.

    For the same reasons, PCI Compliance, I would need to have OpenSSL to a more recent version. It's still not clear to me how I can do that.

    Specifically which part of the system is responsible for keeping openssh current and is this something that I can do or do we just have to wait till it's done? I ask this because I upgraded just about everything I could find to upgrade (at the push of a button ) and when I look at openssh.org it talks about compiling and that's where I have to stop and ask for help.

    Should I ask my colo to upgrade my os?


    Thank you,

    Tina


    Apache/2.2.8 (Unix) mod_ssl/2.2.8 OpenSSL/0.9.7a
    WHM 11.20.0 cPanel 11.22.3-C23899
    CENTOS Enterprise 4.5 i686 on xen - WHM X v3.1.0

  7. #7
    Registered User
    Join Date
    Jan 2006
    Posts
    1

    Default

    Here is a page with instructions on updating both openSSL and openSSH. Although it is from 2005, I simply changed the version numbers to the most current and I was able to update both on my server.

    I've tested the eCommerce sites on the server and everything appears to be working correctly.

    As with all things, use at your own risk.

    Here is the url: http://www.eth0.us/sshd

    -Skittles

  8. #8
    Member
    Join Date
    Jan 2004
    Posts
    252

    Default

    Depending on your scan vendor. You can explain to them that you are using backported patches, and provide them proof (which you can as long as your os is updated). They will commonly shake off the Alert.

    At any rate, you can compile openssh/openssl from scratch and avoid the whole issue all together.
    Rack911.com - Competent Server Administration
    Server Security - Administration - Managed Servers - Optimization - High Traffic Clusters

Similar Threads & Tags
Similar threads

  1. PCI scan openssl upgrade
    By Rooney in forum Security
    Replies: 7
    Last Post: 12-02-2011, 03:52 PM
  2. cPanel and PCI Compliancy
    By dmcrae in forum Security
    Replies: 4
    Last Post: 10-22-2009, 04:12 PM
  3. cPanel and PCI Compliancy
    By dmcrae in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-21-2009, 03:19 PM
  4. OpenSSL banner / PCI compliance
    By ndial in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-17-2005, 11:30 AM
  5. Vulnerabilities in OpenSSH and OpenSSL!
    By tsook in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-03-2003, 02:42 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube