Re: Openssl heartbleed

2014-04-09 Thread Ed Greshko
On 04/09/14 15:47, Chuck Forsberg WA7KGX wrote: > Has a name been chosen Fedora 21 yet? https://lists.fedoraproject.org/pipermail/advisory-board/2013-October/012209.html -- Getting tired of non-Fedora discussions and self-serving posts -- test mailing list test@lists.fedoraproject.org To unsu

Re: Openssl heartbleed

2014-04-09 Thread Chuck Forsberg WA7KGX
A new openssh showed up on yum update this evening, along with a new Heisenbug kernel and other stuff. My server now passes the heartbleed test. Has a name been chosen Fedora 21 yet? -- Chuck Forsberg WA7KGX c...@omen.com www.omen.com Developer of Industrial ZMODEM(Tm) for Embedded App

Re: Openssl heartbleed

2014-04-09 Thread Ed Greshko
On 04/09/14 14:55, Gregory Maxwell wrote: > On Tue, Apr 8, 2014 at 8:46 PM, Adam Williamson wrote: >> On Tue, 2014-04-08 at 18:47 -0700, Gregory Maxwell wrote: >>> On Tue, Apr 8, 2014 at 6:44 PM, Chuck Forsberg WA7KGX wrote: According to the announcement, that version is vulnerable. Of

Re: Openssl heartbleed

2014-04-08 Thread Gregory Maxwell
On Tue, Apr 8, 2014 at 8:46 PM, Adam Williamson wrote: > On Tue, 2014-04-08 at 18:47 -0700, Gregory Maxwell wrote: >> On Tue, Apr 8, 2014 at 6:44 PM, Chuck Forsberg WA7KGX wrote: >> > According to the announcement, that version is vulnerable. >> > Of the 1.01 versions, only 1.01g is saf(er). >> >

Re: Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Dennis Gilmore
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 08 Apr 2014 20:48:16 -0700 Adam Williamson wrote: > On Tue, 2014-04-08 at 21:39 -0500, Dennis Gilmore wrote: > > On Wed, 09 Apr 2014 12:00:54 +1000 > > Ankur Sinha wrote: > > > > > On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: >

Re: Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Dennis Gilmore
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 08 Apr 2014 20:48:16 -0700 Adam Williamson wrote: > On Tue, 2014-04-08 at 21:39 -0500, Dennis Gilmore wrote: > > On Wed, 09 Apr 2014 12:00:54 +1000 > > Ankur Sinha wrote: > > > > > On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: >

Re: Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Adam Williamson
On Tue, 2014-04-08 at 21:39 -0500, Dennis Gilmore wrote: > On Wed, 09 Apr 2014 12:00:54 +1000 > Ankur Sinha wrote: > > > On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: > > > > > > The update has been available since yesterday afternoon. You have to > > > restart your services after in

Re: Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Adam Williamson
On Wed, 2014-04-09 at 12:00 +1000, Ankur Sinha wrote: > On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: > > > > The update has been available since yesterday afternoon. You have to > > restart your services after installing it. > > So, I tried to update openssl as the announcement sugge

Re: Openssl heartbleed

2014-04-08 Thread Adam Williamson
On Tue, 2014-04-08 at 18:47 -0700, Gregory Maxwell wrote: > On Tue, Apr 8, 2014 at 6:44 PM, Chuck Forsberg WA7KGX wrote: > > According to the announcement, that version is vulnerable. > > Of the 1.01 versions, only 1.01g is saf(er). > > RedHat backported the fix as the openssl in fedroda/rhel is

Re: Openssl heartbleed

2014-04-08 Thread Adam Williamson
On Tue, 2014-04-08 at 18:44 -0700, Chuck Forsberg WA7KGX wrote: > On 04/08/2014 06:36 PM, Ankur Sinha wrote: > > yum -y install koji > > > koji download-build --arch=x86_64 openssl-1.0.1e-37.fc20.1 > > > yum localinstall openssl-1.0.1e-37.fc20.1.x86_64.rpm > According to the announcement, th

Re: Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Dennis Gilmore
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, 09 Apr 2014 12:00:54 +1000 Ankur Sinha wrote: > On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: > > > > The update has been available since yesterday afternoon. You have to > > restart your services after installing it. > > So, I

Re: Openssl heartbleed

2014-04-08 Thread Sérgio Basto
On Ter, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: > On Tue, 2014-04-08 at 17:55 -0700, Chuck Forsberg WA7KGX wrote: > > I checked my server with an internet heartbleed test and the > > result was positive. Heisenbug does not have the correct g version. > > http://fedoramagazine.org/statu

Unable to use dnf to update Openssl [Was: Re: Openssl heartbleed]

2014-04-08 Thread Ankur Sinha
On Tue, 2014-04-08 at 17:57 -0700, Adam Williamson wrote: > > The update has been available since yesterday afternoon. You have to > restart your services after installing it. So, I tried to update openssl as the announcement suggested. I couldn't do it via dnf: http://paste.fedoraproject.org/92

Re: Openssl heartbleed

2014-04-08 Thread Gregory Maxwell
On Tue, Apr 8, 2014 at 6:44 PM, Chuck Forsberg WA7KGX wrote: > According to the announcement, that version is vulnerable. > Of the 1.01 versions, only 1.01g is saf(er). RedHat backported the fix as the openssl in fedroda/rhel is carrying a ton of patches. I expect this is going to cause a lot of

Re: Openssl heartbleed

2014-04-08 Thread Chuck Forsberg WA7KGX
On 04/08/2014 06:36 PM, Ankur Sinha wrote: yum -y install koji > koji download-build --arch=x86_64 openssl-1.0.1e-37.fc20.1 > yum localinstall openssl-1.0.1e-37.fc20.1.x86_64.rpm According to the announcement, that version is vulnerable. Of the 1.01 versions, only 1.01g is saf(er). --

Re: Openssl heartbleed

2014-04-08 Thread Ankur Sinha
On Tue, 2014-04-08 at 18:20 -0700, Chuck Forsberg WA7KGX wrote: > No sign of an update in yum yet - just checked. Please grab the package directly from koji if it's urgent. It's mentioned in the announcement Robyn made: > For Fedora 19 x86_64: > yum -y install koji > koji download-build --arc

Re: Openssl heartbleed

2014-04-08 Thread Chuck Forsberg WA7KGX
On 04/08/2014 05:57 PM, Adam Williamson wrote: On Tue, 2014-04-08 at 17:55 -0700, Chuck Forsberg WA7KGX wrote: I checked my server with an internet heartbleed test and the result was positive. Heisenbug does not have the correct g version. http://fedoramagazine.org/status-on-cve-2014-0160-aka

Re: Openssl heartbleed

2014-04-08 Thread Adam Williamson
On Tue, 2014-04-08 at 17:55 -0700, Chuck Forsberg WA7KGX wrote: > I checked my server with an internet heartbleed test and the > result was positive. Heisenbug does not have the correct g version. http://fedoramagazine.org/status-on-cve-2014-0160-aka-heartbleed/ The update has been available sin