Solved

OPENSSL UPGRADE

Posted on 2009-07-01
3
510 Views
Last Modified: 2013-11-08
Hi Support,

I am using openssl 0.9.8b. Now I want to upgrde the same as it is having vurnablities.
I have configured mod_ssl & Apache which is live.

How I can upgrade openssl version without affecting my application
My Centos version is 5.2
0
Comment
Question by:laxmileela
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 7

Expert Comment

by:unSpawn
ID: 24760918
>How I can upgrade openssl version without affecting my application
Strictly speaking that does not compute: if the library version in use is vulnerable then you would *want* an upgrade to affect your application, right?

If you mean that you do not want to suffer application downtime, and the service does not support reloading libraries on say kill -HUP, then generally speaking you could duplicate whatever the service consists of so you can run a second instance, upgrade the library, redirect traffic and start the second instance, restart the original instance and remove the traffic redirect, then kill the second instance.

The way you run your second instance depends on your resources. If you managed to configure and run loadbalancing/failover then you would already know what to do. If you run all services on one machine you could run the second instance on a different port and redirect traffic using iptables rules.
* With respect to application downtime: session replication is not taken into account here: please consult your product documents.
0
 

Author Comment

by:laxmileela
ID: 24763100
Ok then tell me
How I can upgrade my openssl. Is there anything to change in my application side.

Please give me the full detail & steps
0
 
LVL 7

Accepted Solution

by:
unSpawn earned 500 total points
ID: 24765062
If this concerns a production machine you should assess if you need to run the install on a staging machine or testbed before proceeding. You should assess if you need to make backups before proceeding. You should preferably access updates through Yum. If Yum doesn't provide any OpenSSL updates later than openssl-0.9.8b, download the RPM or try 'rpm --test -i ftp://ftp.sunet.se/pub/os/Linux/distributions/centos/5.3/os/i386/CentOS/openssl-0.9.8e-7.el5.i686.rpm'. The "--test" switch will let you go through the motions so you can assess if it will or will not install. Then a restart of the webserver (make certain all threads get killed off) should show if it recognizes the new libraries.

There's other ways like rebuilding the .src.rpm or lesser preferred ways like building from tarball but let's see you give feedback on RPM test install.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Creating a Samba server for a small office. Ubuntu Linux and Samba can breathe new life into a retired PC and save an office money on new hardware/software. Our example server will have two hard disks, one exclusively for storing shared data. …
This document is written for Red Hat Enterprise Linux AS release 4 and ORACLE 10g.  Earlier releases can be installed using this document as well however there are some additional steps for packages to be installed see Metalink. Disclaimer: I hav…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question