<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenSSL  0.9.8p to 0.9.8r or 1.0.0e in Security</title>
    <link>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86404#M2864</link>
    <description>&lt;P&gt;(A) Splunk's OpenSSL is bundled into Splunk as a private copy.  Splunk does not care what your "system" OpenSSL is.&lt;/P&gt;

&lt;P&gt;(B) Splunk maintains OpenSSL (and several other bundled components) as part of their overall release process.  You should not expect to upgrade "just" Splunk's OpenSSL w/o upgrading Splunk itself.  More info is available on &lt;A href="http://splunk-base.splunk.com/answers/6653/how-do-splunk-releases-integrate-security-patches-for-dependent-libraries"&gt;http://splunk-base.splunk.com/answers/6653/how-do-splunk-releases-integrate-security-patches-for-dependent-libraries&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Oct 2011 20:37:47 GMT</pubDate>
    <dc:creator>dwaddle</dc:creator>
    <dc:date>2011-10-04T20:37:47Z</dc:date>
    <item>
      <title>OpenSSL  0.9.8p to 0.9.8r or 1.0.0e</title>
      <link>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86401#M2861</link>
      <description>&lt;P&gt;Current project I am working on require that OpenSSL be upgraded to at least 0.9.8r (with experimental "ECCdraft" ciphersuites disabled) or 1.0.0e. Specifically, OpenSSL 0.9.8p is cited as vulnerable.&lt;BR /&gt;
Could you tell me if OpenSSL used by Splunk can be upgraded to 0.9.8r? Or can it be configured to simply use the existing installation of OpenSSL on the server so that we don’t always have to upgrade two copies on each server.&lt;/P&gt;

&lt;P&gt;The version we are using is 4.2.1.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2011 19:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86401#M2861</guid>
      <dc:creator>fi5033</dc:creator>
      <dc:date>2011-10-04T19:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL  0.9.8p to 0.9.8r or 1.0.0e</title>
      <link>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86402#M2862</link>
      <description>&lt;P&gt;If you review the open source license definitions that are distributed with splunk you should be able to ascertain the version of openssl you are running. I am using Splunk 4.1.8 and the license documents were located here: /opt/splunk/share/splunk/3rdparty. According to Copyright-for-openssl-0.9.8n.txt I should expect openssl 0.9.8n to be in my copy of Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2011 20:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86402#M2862</guid>
      <dc:creator>jasonnadeau</dc:creator>
      <dc:date>2011-10-04T20:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL  0.9.8p to 0.9.8r or 1.0.0e</title>
      <link>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86403#M2863</link>
      <description>&lt;P&gt;The version of openssl came with 4.2.1 is 0.9.8p. &lt;/P&gt;

&lt;P&gt;bash-3.00$ ls Copyright-for-open*&lt;BR /&gt;
Copyright-for-openssl-0.9.8p.txt&lt;/P&gt;

&lt;P&gt;Still seeking to upgrade 0.9.8p to 0.9.8r and not sure if this is even doable?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2011 20:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86403#M2863</guid>
      <dc:creator>fi5033</dc:creator>
      <dc:date>2011-10-04T20:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL  0.9.8p to 0.9.8r or 1.0.0e</title>
      <link>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86404#M2864</link>
      <description>&lt;P&gt;(A) Splunk's OpenSSL is bundled into Splunk as a private copy.  Splunk does not care what your "system" OpenSSL is.&lt;/P&gt;

&lt;P&gt;(B) Splunk maintains OpenSSL (and several other bundled components) as part of their overall release process.  You should not expect to upgrade "just" Splunk's OpenSSL w/o upgrading Splunk itself.  More info is available on &lt;A href="http://splunk-base.splunk.com/answers/6653/how-do-splunk-releases-integrate-security-patches-for-dependent-libraries"&gt;http://splunk-base.splunk.com/answers/6653/how-do-splunk-releases-integrate-security-patches-for-dependent-libraries&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2011 20:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OpenSSL-0-9-8p-to-0-9-8r-or-1-0-0e/m-p/86404#M2864</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-10-04T20:37:47Z</dc:date>
    </item>
  </channel>
</rss>

