The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

'openssl', version '1.0.1e', is out of date, and possibly a security risk.

Discussion in 'General Discussion' started by postcd, Nov 19, 2015.

  1. postcd

    postcd Well-Known Member

    Joined:
    Oct 22, 2010
    Messages:
    621
    Likes Received:
    6
    Trophy Points:
    18
    Hello,

    i have CentOS 6.7 and cpanel on it.

    from rkhunter i got this warning:

    Warning: Application 'openssl', version '1.0.1e', is out of date, and possibly a security risk.

    # openssl version
    OpenSSL 1.0.1e-fips 11 Feb 2013

    WHM 11.52.0 (build 22)

    How should i safely fix it while not reducing functionality & security of the SSL on the server?
     
  2. cotswoldphoto

    cotswoldphoto Active Member

    Joined:
    Feb 20, 2015
    Messages:
    25
    Likes Received:
    3
    Trophy Points:
    3
    cPanel Access Level:
    Root Administrator
    I would read this:

    Rkhunter reports openssl warning

    I tend to test my site using the SSL Server Test (Powered by Qualys SSL Labs) test suite, although I DO add my own custom Pre Main Include to alter the cipher suites, like this:

    Home » Service Configuration » Apache Configuration » Include Editor » Pre Main Include » All versions

    In the Global Box delete what is there and paste this:

    Code:
    SSLProtocol -All +TLSv1 +TLSv1.1 +TLSv1.2
    SSLHonorCipherOrder On
    SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS
    It is possible that this needs updating for newer standards (please advise me if it does), but it works for me.
     
Loading...

Share This Page