Recommended update for libopenssl
SUSE Recommended Update: Recommended update for libopenssl
This update brings various enhancements for OpenSSL:
*
IPv6 support was added to the openssl s_client and
s_server command line tool. (bnc#859228)
*
The openssl command line tool now checks certificates
by default against /etc/ssl/certs (this can be changed via
the -CApath option). (bnc#860332)
*
The Elliptic Curve Diffie-Hellman key exchange
selector was enabled and can be selected by kECDHE, kECDH,
ECDH tags in the SSL cipher string. (bnc#859924)
*
If an optional "openssl1" command line tool is
installed in parallel, c_rehash uses it to generate
certificate hashes in both OpenSSL 0 and OpenSSL 1 style.
This allows parallel usage of OpenSSL 0.9.8j and OpenSSL
1.x client libraries with a shared certificate store.
(bnc#862181)
Announcement ID: | SUSE-RU-2014:0330-1 |
Rating: | moderate |
References: | #859228 #859924 #860332 #862181 |
Affected Products: |
An update that has four recommended fixes can now be installed.
Description:
This update brings various enhancements for OpenSSL:
*
IPv6 support was added to the openssl s_client and
s_server command line tool. (bnc#859228)
*
The openssl command line tool now checks certificates
by default against /etc/ssl/certs (this can be changed via
the -CApath option). (bnc#860332)
*
The Elliptic Curve Diffie-Hellman key exchange
selector was enabled and can be selected by kECDHE, kECDH,
ECDH tags in the SSL cipher string. (bnc#859924)
*
If an optional "openssl1" command line tool is
installed in parallel, c_rehash uses it to generate
certificate hashes in both OpenSSL 0 and OpenSSL 1 style.
This allows parallel usage of OpenSSL 0.9.8j and OpenSSL
1.x client libraries with a shared certificate store.
(bnc#862181)
Patch Instructions:
To install this SUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Software Development Kit 11 SP3:
zypper in -t patch sdksp3-libopenssl-devel-8905
- SUSE Linux Enterprise Server 11 SP3 for VMware:
zypper in -t patch slessp3-libopenssl-devel-8905
- SUSE Linux Enterprise Server 11 SP3:
zypper in -t patch slessp3-libopenssl-devel-8905
- SUSE Linux Enterprise Desktop 11 SP3:
zypper in -t patch sledsp3-libopenssl-devel-8905
To bring your system up-to-date, use "zypper patch".
Package List:
- SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64):
- libopenssl-devel-0.9.8j-0.52.1
- SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64):
- libopenssl0_9_8-0.9.8j-0.52.1
- libopenssl0_9_8-hmac-0.9.8j-0.52.1
- openssl-0.9.8j-0.52.1
- openssl-doc-0.9.8j-0.52.1
- SUSE Linux Enterprise Server 11 SP3 for VMware (x86_64):
- libopenssl0_9_8-32bit-0.9.8j-0.52.1
- libopenssl0_9_8-hmac-32bit-0.9.8j-0.52.1
- SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64):
- libopenssl0_9_8-0.9.8j-0.52.1
- libopenssl0_9_8-hmac-0.9.8j-0.52.1
- openssl-0.9.8j-0.52.1
- openssl-doc-0.9.8j-0.52.1
- SUSE Linux Enterprise Server 11 SP3 (ppc64 s390x x86_64):
- libopenssl0_9_8-32bit-0.9.8j-0.52.1
- libopenssl0_9_8-hmac-32bit-0.9.8j-0.52.1
- SUSE Linux Enterprise Server 11 SP3 (ia64):
- libopenssl0_9_8-x86-0.9.8j-0.52.1
- SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64):
- libopenssl0_9_8-0.9.8j-0.52.1
- openssl-0.9.8j-0.52.1
- SUSE Linux Enterprise Desktop 11 SP3 (x86_64):
- libopenssl0_9_8-32bit-0.9.8j-0.52.1
References:
- https://bugzilla.novell.com/859228
- https://bugzilla.novell.com/859924
- https://bugzilla.novell.com/860332
- https://bugzilla.novell.com/862181
- http://download.novell.com/patch/finder/?keywords=c71a5e505ced419ba7f97300d7586066