Security update for stunnel

Announcement ID: SUSE-OU-2016:1867-1
Rating: low
References:
Affected Products:
  • Security Module for SUSE Linux Enterprise 11 11-SP3
  • SLES for SAP Applications 11-SP4
  • SUSE Linux Enterprise Server 11 SP4

An update that has two fixes can now be installed.

Description:

This update provides a stunnel-openssl1 package which is built against openssl1 to provide TLS 1.2 support. (FATE#320187 bsc#961377 FATE#319972 bsc#987861)

The stunnel-openssl1 package can be installed additionally to the stunnel package.

The upate-alternatives method can be used to select either the openssl0 or openssl1 build, default is the openssl1 build.

To show what is selected: update-alternatives --display stunnel

To switch switch use:

    update-alternatives --set stunnel /usr/sbin/stunnel.openssl0

    update-alternatives --set stunnel /usr/sbin/stunnel.openssl1

or to change back to automatic handling use:

    update-alternatives --auto stunnel

Also the ECDHE default elliptic curve was changed to the prime256v1 curve.

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Security Module for SUSE Linux Enterprise 11 11-SP3
    zypper in -t patch secsp3-stunnel-openssl1-12663=1
  • SUSE Linux Enterprise Server 11 SP4
    zypper in -t patch slessp4-stunnel-openssl1-12663=1
  • SLES for SAP Applications 11-SP4
    zypper in -t patch slessp4-stunnel-openssl1-12663=1

Package List:

  • Security Module for SUSE Linux Enterprise 11 11-SP3 (s390x x86_64 i586 ppc64 ia64)
    • stunnel-openssl1-4.54-0.11.1
  • SUSE Linux Enterprise Server 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • stunnel-4.54-0.11.1
  • SLES for SAP Applications 11-SP4 (ppc64 x86_64)
    • stunnel-4.54-0.11.1

References: