Open SSL and Heartbleed

Homepage Clovertech Forums Read Only Archives Cloverleaf Cloverleaf Open SSL and Heartbleed

  • Creator
    Topic
  • #54218
    Paul Marriott
    Participant

    Does anyone know if the recent http://heartbleed.com/ Heartbleed Bug is an issue on any of the Cloverleaf installations on ALL modules.

    We are running RHEL Linux so assume the standard patch from Red Hat will work without adversely impacting our HTTPS, IB and FTPS (S)FTP intrefaces.

Viewing 0 reply threads
  • Author
    Replies
    • #80622
      Elisha Gould
      Participant

      It’s dependant on your openssl version. Versions 1.0.1 through 1.0.1f are affected.

      To check execute the following.

      Code:

      openssl version

      This issue mainly affects external (internet) facing servers that do not have ip range restrictions for clients. It does not affect client connections to other servers (although those servers may have been compromised. It is up to those vendors to check).

      If you have an external facing server and the openssl version is or has been one of the affected versions, then it may be safer to re-issue the certificates and change the passwords for the users that use the interface.

Viewing 0 reply threads
  • The forum ‘Cloverleaf’ is closed to new topics and replies.

Forum Statistics

Registered Users
5,117
Forums
28
Topics
9,292
Replies
34,435
Topic Tags
286
Empty Topic Tags
10