D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On 8 April 2014 11:01, Martijn Grooten <martijn@xxxxxxxxxxxxxxxxxx> wrote:
> On Tue, Apr 08, 2014 at 10:44:02AM +0100, Paul Sutton wrote:
>> So is this easy to fix then or is it more complex than just patching
>> the issue and releasing an updated version.
>
> Fixing is easy: just upgrade to OpenSSL 1.0.1g.
>
> The problem is that it might be that someone has used this against your
> server and thus obtained secret keys and other information that you
> don't want others to steal.
>
> This blog:
>   http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/
> advises to also regenerate your private key AND to replace SSL
> certificates. Which is a huge pain.


In case it's not obvious, that means taking the affected systems
offline and airgapped while you regenerate keys.

-- 
Phil Hudson                  http://hudson-it.no-ip.biz
@UWascalWabbit                 PGP/GnuPG ID: 0x887DCA63

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq