OpenSSL 0.9.8k - 0.9.8l

2010-04-16 Thread Tim Gustafson
Hi,

I run a few web servers with need to be PCI compliant.  Apparently there's a 
problem with OpenSSL 0.9.8k that requires us to upgrade to 0.9.8l for us to 
maintain our compliance level.

I've csup'd to RELENG_8_0 and did a build/install cycle and OpenSSL is still at 
0.9.8k.  Using RELENG_8 isn't really an option for me because the last I 
upgraded to that level, ipfw was broken and I'm not sure that the problem with 
ipfw has been fixed (Luigi tells me that it has, but I haven't had time to test 
it yet).

Is there any movement to patch RELENG_8_0 with OpenSSL 0.9.8l?  Or will I be 
stuck with 0.9.8k until I move to RELENG_8?

Tim Gustafson
Baskin School of Engineering
UC Santa Cruz
t...@soe.ucsc.edu
831-459-5354

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to freebsd-questions-unsubscr...@freebsd.org


Re: OpenSSL 0.9.8k - 0.9.8l

2010-04-16 Thread Ivan Voras

Tim Gustafson wrote:

Hi,

I run a few web servers with need to be PCI compliant.  Apparently there's a 
problem with OpenSSL 0.9.8k that requires us to upgrade to 0.9.8l for us to 
maintain our compliance level.

I've csup'd to RELENG_8_0 and did a build/install cycle and OpenSSL is still at 
0.9.8k.  Using RELENG_8 isn't really an option for me because the last I 
upgraded to that level, ipfw was broken and I'm not sure that the problem with 
ipfw has been fixed (Luigi tells me that it has, but I haven't had time to test 
it yet).

Is there any movement to patch RELENG_8_0 with OpenSSL 0.9.8l?  Or will I be 
stuck with 0.9.8k until I move to RELENG_8?


Try asking on the freebsd-security@ list.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to freebsd-questions-unsubscr...@freebsd.org