Solved

OPENSSL UPGRADE

Posted on 2009-07-01
3
511 Views
Last Modified: 2013-11-08
Hi Support,

I am using openssl 0.9.8b. Now I want to upgrde the same as it is having vurnablities.
I have configured mod_ssl & Apache which is live.

How I can upgrade openssl version without affecting my application
My Centos version is 5.2
0
Comment
Question by:laxmileela
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 7

Expert Comment

by:unSpawn
ID: 24760918
>How I can upgrade openssl version without affecting my application
Strictly speaking that does not compute: if the library version in use is vulnerable then you would *want* an upgrade to affect your application, right?

If you mean that you do not want to suffer application downtime, and the service does not support reloading libraries on say kill -HUP, then generally speaking you could duplicate whatever the service consists of so you can run a second instance, upgrade the library, redirect traffic and start the second instance, restart the original instance and remove the traffic redirect, then kill the second instance.

The way you run your second instance depends on your resources. If you managed to configure and run loadbalancing/failover then you would already know what to do. If you run all services on one machine you could run the second instance on a different port and redirect traffic using iptables rules.
* With respect to application downtime: session replication is not taken into account here: please consult your product documents.
0
 

Author Comment

by:laxmileela
ID: 24763100
Ok then tell me
How I can upgrade my openssl. Is there anything to change in my application side.

Please give me the full detail & steps
0
 
LVL 7

Accepted Solution

by:
unSpawn earned 500 total points
ID: 24765062
If this concerns a production machine you should assess if you need to run the install on a staging machine or testbed before proceeding. You should assess if you need to make backups before proceeding. You should preferably access updates through Yum. If Yum doesn't provide any OpenSSL updates later than openssl-0.9.8b, download the RPM or try 'rpm --test -i ftp://ftp.sunet.se/pub/os/Linux/distributions/centos/5.3/os/i386/CentOS/openssl-0.9.8e-7.el5.i686.rpm'. The "--test" switch will let you go through the motions so you can assess if it will or will not install. Then a restart of the webserver (make certain all threads get killed off) should show if it recognizes the new libraries.

There's other ways like rebuilding the .src.rpm or lesser preferred ways like building from tarball but let's see you give feedback on RPM test install.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you sitting there reading this and wondering how to get started with Linux? It almost seems like picking the right Linux distribution is about like picking the right college or buying a new car if you read some of the article out there. Relax… l…
You ever wonder how to backup Linux system files just like Windows System Restore?  Well you can use Timeshift in Linux to perform those similar action.  This tutorial will show you how to backup your system files and keep regular intervals. Note…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question