Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

OpenSSL updates

Discussion in 'Security' started by Hedloff, Aug 1, 2017.

Tags:
  1. Hedloff

    Hedloff Well-Known Member

    Joined:
    Jun 7, 2004
    Messages:
    135
    Likes Received:
    4
    Trophy Points:
    168
    Location:
    Up north!
    cPanel Access Level:
    DataCenter Provider
    Hello,

    Why hasn't OpenSSL version been updated for years?
    On EA3 server:
    root@server [~]# openssl version
    OpenSSL 1.0.1e-fips 11 Feb 2013

    root@server [~]# rpm -qa | grep openssl
    alt-openssl-libs-1.0.2k-2.el6.cloudlinux.10.x86_64
    openssl-1.0.1e-57.el6.x86_64
    openssl-devel-1.0.1e-57.el6.x86_64

    On EA4 server:

    root@server2:/# openssl version
    OpenSSL 1.0.1e-fips 11 Feb 2013

    root@server2:/# rpm -qa | grep openssl
    ea-openssl-1.0.2k-5.el7.cloudlinux.1.x86_64
    openssl-devel-1.0.1e-60.el7_3.1.x86_64
    alt-openssl-libs-1.0.2k-2.el7.cloudlinux.10.x86_64
    openssl-1.0.1e-60.el7_3.1.x86_64
    openssl-libs-1.0.1e-60.el7_3.1.x86_64

    How can customers use version 1.0.2k?

    Changelog:
    /news/changelog.html
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,260
    Likes Received:
    390
    Trophy Points:
    583
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Hedloff

    Hedloff Well-Known Member

    Joined:
    Jun 7, 2004
    Messages:
    135
    Likes Received:
    4
    Trophy Points:
    168
    Location:
    Up north!
    cPanel Access Level:
    DataCenter Provider
    That thread did not solve anything.
    1.0.1 is not supported anymore so I'm wondering why it is still used on all our cPanel servers?
    OpenSSL - Wikipedia
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    43,961
    Likes Received:
    1,821
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    OpenSSL is provided by the operating system (e.g. CentOS, Red Hat) and is not a package that's developed or published by cPanel. You may find the following command helpful to see which patches have been backported to the version of openssl installed on your system:

    Code:
    rpm -q --changelog openssl | grep CVE
    It lists the patches included with the RPM, as the version number will not always change after an update. Also, since you are using CloudLinux, they provide updates to the OpenSSL package. Here's their latest blog post regarding openssl:

    OpenSSL updated for CloudLinux 6 and CloudLinux 7

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice