Planned Outage - Nov 1

M
Matt_K
Posts: 4809
Joined: Mar 21, 2018

by Matt_K »

I will have an outage sometime on November 1st to potentially address the recently discovered [url=https://www.darkreading.com/vulnerabilities-threats/prepare-critical-flaw-openssl-security-experts-warn]Critical Vulnerability in OpenSSL. I'm unsure of time, OpenSSL has not indicated when they will drop the patch on Nov 1 yet.

I need to do an OS upgrade, so this is an opportune time to do that as well. It's likely the site actually isn't vulnerable, which is why I stick to an LTS distro that just backports security patches for quite some time :good:
B
bymiller
Posts: 6
Joined: Sep 11, 2022

by bymiller »

Very prudent - definitely also a fan of using LTS on production sites for just this kind of fun. Thank you for all of the work you do to keep this excellent site running! :D
C
craign
Posts: 47
Joined: Aug 31, 2022

by craign »

Yeah, my understanding is it only impacts quite new versions of OpenSSL (approx. last year), so if running LTS I doubt you are impacted.
M
Matt_K
Posts: 4809
Joined: Mar 21, 2018

by Matt_K »

Indeed, looks like we have no vulnerability based on the version we're running, so I'm going to cancel the planned outage. If you are managing systems that have OpenSSL >1... good luck today. :shock: