Security update for stunnel
Announcement ID: | SUSE-OU-2016:1867-1 |
---|---|
Rating: | low |
References: | |
Affected Products: |
|
An update that has two fixes can now be installed.
Description:
This update provides a stunnel-openssl1 package which is built against openssl1 to provide TLS 1.2 support. (FATE#320187 bsc#961377 FATE#319972 bsc#987861)
The stunnel-openssl1 package can be installed additionally to the stunnel package.
The upate-alternatives method can be used to select either the openssl0 or openssl1 build, default is the openssl1 build.
To show what is selected: update-alternatives --display stunnel
To switch switch use:
update-alternatives --set stunnel /usr/sbin/stunnel.openssl0
update-alternatives --set stunnel /usr/sbin/stunnel.openssl1
or to change back to automatic handling use:
update-alternatives --auto stunnel
Also the ECDHE default elliptic curve was changed to the prime256v1 curve.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Security Module for SUSE Linux Enterprise 11 11-SP3
zypper in -t patch secsp3-stunnel-openssl1-12663=1
-
SUSE Linux Enterprise Server 11 SP4
zypper in -t patch slessp4-stunnel-openssl1-12663=1
-
SLES for SAP Applications 11-SP4
zypper in -t patch slessp4-stunnel-openssl1-12663=1
Package List:
-
Security Module for SUSE Linux Enterprise 11 11-SP3 (s390x x86_64 i586 ppc64 ia64)
- stunnel-openssl1-4.54-0.11.1
-
SUSE Linux Enterprise Server 11 SP4 (s390x x86_64 i586 ppc64 ia64)
- stunnel-4.54-0.11.1
-
SLES for SAP Applications 11-SP4 (ppc64 x86_64)
- stunnel-4.54-0.11.1