Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  Openssl

    Posted Mon January 31, 2022 11:52 AM
    Hello

    Can someone help me on this topic?
    Regarding openssl veriosn I have OpenSSL 1.0.2u which the latest available.
    and this is the filest infor for openssl base in server
    lslpp -l | grep -i openssl.base
    openssl.base 1.0.2.2102 COMMITTED Open Secure Socket Layer

    But the vulnerability scan always reporting latest version need to apply
    OpenSSL 1.0.2x,y,z and no package exist

    Is it need to upgrade openssl here or as fileset info 1.0.2u is ok?

    ------------------------------
    Alwin Alex
    ------------------------------

    #AIXOpenSource


  • 2.  RE: Openssl

    Posted Wed February 02, 2022 02:05 AM
    Hello

    OpenSSL fileset VRMF 1.0.2.2102 is the current latest VRMF and it has been patched with all recent vulnerabilities that were fixed through openssl community 1.0.2x,y,z etc.

    So, at this moment since you're fileset level is latest, you are ok. Please do check AIX web download pack for any latest releases of openssl fileset, in which any new vulnerabilities will get fixed.

    Thanks

    ------------------------------
    Sandeep Umesh
    ------------------------------