升级openssl
依赖openssl的软件,如果是静态编译openssl,那么需要重新编译软件,如果是利用openssl的so动态库,那么只需要替换一下so文件并重启软件即可
openssh也依赖openssl
参考文章
http://www.111cn.net/sys/CentOS/61326.htm
http://bguncle.blog.51cto.com/3184079/1392870/
http://www.cnblogs.com/doomsword/p/3654131.html
http://baike.baidu.com/link?url=-JPAJup4lhmkzO__PjR9IeyHzJ46WjSHYQQSxaQYOxnjc2DVrkzJHRV5M56vhFgiif7Ir_-9spu2mgj8VtMXMq
今天用rkhunter检测了一下服务器,检测结果报:openssl版本太低
# grep -i OpenSSL /var/log/rkhunter.log
[13:43:50] Checking for string '/usr/include/openssl' [ Not found ]
[13:44:11] Checking version of OpenSSL [ Warning ]
[13:44:11] Warning: Application 'openssl', version '1.0.1e', isout of date, and possibly a security risk.
ln -s /usr/local/ssl/bin/openssl /usr/bin/openssl 静态编译用 静态库
ln -s /usr/local/ssl/lib/libssl.so /usr/local/lib64/libssl.so 动态编译用 动态库
strings /usr/lib64/libssl.so.10 |grep -i openssl
OpenSSLDie
OPENSSL_cleanse
OPENSSL_DIR_read
OPENSSL_DIR_end
OPENSSL_init_library
OPENSSL_1.0.1OPENSSL_1.0.1_EC
SSLv2 part of OpenSSL1.0.1e-fips 11 Feb 2013SSLv3 part of OpenSSL1.0.1e-fips 11 Feb 2013TLSv1 part of OpenSSL1.0.1e-fips 11 Feb 2013DTLSv1 part of OpenSSL1.0.1e-fips 11 Feb 2013OpenSSL1.0.1e-fips 11 Feb 2013
rpm -ql openssl/usr/bin/openssl/usr/lib64/libcrypto.so.1.0.1e/usr/lib64/libcrypto.so.10
/usr/lib64/libssl.so.1.0.1e/usr/lib64/libssl.so.10
/usr/lib64/openssl
http://baike.baidu.com/