Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default upgrade openssl

    Hello,
    I have an interesting question,

    PCI Compliance scans require openssl to be at 0.9.8c or higher.
    and ssh need to be at 5.1

    the issue we are running into is that the system only shows 0.9.8b and ssh at 4.9


    we have been informed by the data center that manually updating openssl will break c-panel.

    we have see this on 2 servers at this new datacenter. where after updating openssl and ssh that we are unable to generate CSR's

    What is the proper way to update to be PCI Compliant without breaking c-panel?

  2. #2
    Member
    Join Date
    May 2007
    Posts
    78

    Default

    we have been informed by the data center that manually updating openssl will break c-panel.
    I've been told by mine that if problems occur an OS reinstall would pretty much be mandatory!

    I haven't been brave enough to try it yet. Wonder why it is so hard to upgrade?

  3. #3
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I have discovered that using the newest redhat kernel will pass even though the banner says 0.9.8b

  4. #4
    Member
    Join Date
    May 2007
    Posts
    78

    Default

    Does that actually upgrade the security patches, too?

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,931

    Default

    What is the proper way to update to be PCI Compliant without breaking c-panel?
    you ask them to make an exception as a good scanning company will that some Linux distros are back-port fixed to the latest version
    Lowest Host/Empire Technology LLC
    Affordable hosting solutions http://empire-hosting.net
    List Your hosting site FREE in http://hostgeneration.com

  6. #6
    Member
    Join Date
    Jul 2004
    Posts
    41

    Default Can it be done?

    Has anyone yet found a way to upgrade OpenSSL that won't fry the server? We need to get ours into compliance as well.
    All cPanel Support has to say is:

    OpenSSL maintenance is a systems task that lays beyond the scope of our support
    Any ideas out there?

    Thanks,
    Patrick

  7. #7
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Nope
    and its funny, its not cpanels problem but its the cpanel version of this software that is causing the issues,

    I mean when you are told outright that updating things manually will cause issues there is a problem........

    the issue that we had with upgrading openssl was we could no longer creats CSRs


    however if you are keeping your kernel and your cpanel uptodate then you will be fine....and it should pas PCI Compliance

  8. #8
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by merlinpa1969 View Post
    Nope
    and its funny, its not cpanels problem but its the cpanel version of this software that is causing the issues,
    We don't provide OpenSSL.

    OpenSSL is provided by the Operating System Vendor (e.g. RedHat, CentOS, etc). We only use what they provide.

    As mentioned above, you need to contact your PCI Compliance Auditor and provide information that you are using OpenSSL packages provided by your Operating System vendor, who backports patches (if your OS vendor does do so. RedHat does).

  9. #9
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Thats fine however you still have not explained WHY manually upgrading openssl and openssh cause issues with creating a csr...

    Why is it recommended NOT to upgrade the software if your using cpanel

  10. #10
    Member SB-Nick's Avatar
    Join Date
    Aug 2008
    Posts
    110

    Default

    We have been upgrading OpenSSL for PCI compliance on some cPanel boxes without any problem.
    Did you try to upgrade it? If so, what error are you getting?
    :: Server Buddies ::

    Server Management & Monitoring

    .Dedicated Server Solutions At Affordable Rates.

  11. #11
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Yes we did upgrade it,
    redhat5

    causes issues

    you are not able to create CSR's it goes through the motion but dosnt create it

  12. #12
    Member SB-Nick's Avatar
    Join Date
    Aug 2008
    Posts
    110

    Default

    Hello,

    Did you double check you are using the updated openssl binaries?
    :: Server Buddies ::

    Server Management & Monitoring

    .Dedicated Server Solutions At Affordable Rates.

Similar Threads & Tags
Similar threads

  1. OpenSSL Upgrade
    By atillayasar in forum Security
    Replies: 4
    Last Post: 02-18-2011, 01:38 PM
  2. Upgrade OpenSSL
    By mickalo in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-05-2009, 06:15 PM
  3. how do I upgrade OpenSSL
    By SubZero in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-25-2006, 08:31 AM
  4. How do I upgrade OpenSSL 0.9.7h 0.9.7a ?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 12-29-2005, 05:31 AM
  5. Upgrade OpenSSL/0.9.7a to 0.9.8
    By wills in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-06-2005, 01:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube