Solved

OPENSSL UPGRADE

Posted on 2009-07-01
3
508 Views
Last Modified: 2013-11-08
Hi Support,

I am using openssl 0.9.8b. Now I want to upgrde the same as it is having vurnablities.
I have configured mod_ssl & Apache which is live.

How I can upgrade openssl version without affecting my application
My Centos version is 5.2
0
Comment
Question by:laxmileela
  • 2
3 Comments
 
LVL 7

Expert Comment

by:unSpawn
ID: 24760918
>How I can upgrade openssl version without affecting my application
Strictly speaking that does not compute: if the library version in use is vulnerable then you would *want* an upgrade to affect your application, right?

If you mean that you do not want to suffer application downtime, and the service does not support reloading libraries on say kill -HUP, then generally speaking you could duplicate whatever the service consists of so you can run a second instance, upgrade the library, redirect traffic and start the second instance, restart the original instance and remove the traffic redirect, then kill the second instance.

The way you run your second instance depends on your resources. If you managed to configure and run loadbalancing/failover then you would already know what to do. If you run all services on one machine you could run the second instance on a different port and redirect traffic using iptables rules.
* With respect to application downtime: session replication is not taken into account here: please consult your product documents.
0
 

Author Comment

by:laxmileela
ID: 24763100
Ok then tell me
How I can upgrade my openssl. Is there anything to change in my application side.

Please give me the full detail & steps
0
 
LVL 7

Accepted Solution

by:
unSpawn earned 500 total points
ID: 24765062
If this concerns a production machine you should assess if you need to run the install on a staging machine or testbed before proceeding. You should assess if you need to make backups before proceeding. You should preferably access updates through Yum. If Yum doesn't provide any OpenSSL updates later than openssl-0.9.8b, download the RPM or try 'rpm --test -i ftp://ftp.sunet.se/pub/os/Linux/distributions/centos/5.3/os/i386/CentOS/openssl-0.9.8e-7.el5.i686.rpm'. The "--test" switch will let you go through the motions so you can assess if it will or will not install. Then a restart of the webserver (make certain all threads get killed off) should show if it recognizes the new libraries.

There's other ways like rebuilding the .src.rpm or lesser preferred ways like building from tarball but let's see you give feedback on RPM test install.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you sitting there reading this and wondering how to get started with Linux? It almost seems like picking the right Linux distribution is about like picking the right college or buying a new car if you read some of the article out there. Relax… l…
The purpose of this article is to demonstrate how we can upgrade Python from version 2.7.6 to Python 2.7.10 on the Linux Mint operating system. I am using an Oracle Virtual Box where I have installed Linux Mint operating system version 17.2. Once yo…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question