<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SHA1 encryption under OpenSSL in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911698#M104018</link>
    <description>&lt;P&gt;FYI: Technically SHA1 and SHA2 are a hash or digest, not the cipher itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay but just wondering how we can establish, in advance, whether we will be impacted by loss of SHA1 encryption under OpenSSL . i &amp;nbsp;understand that HP Openview operations agent for OpenVMS (OVA) and HP System management (SMH) - (both of which we use) , are reliant on SSL but not sure how to ascertain whether the loss of SHA1 encryption under OpenSSl will have any impact on this s/ware and/or any certificates currently installed ? &amp;nbsp;We currently have the following versions of SSL installed on our live Alpha/Integrity Servers running OpenVMS, and so wondering whether any potential issues would be addressed by upgrading to (latest ?) &amp;nbsp;version&amp;nbsp;&lt;SPAN&gt; HP SSL1 V 1.0 (mentioned in the following article.) &amp;nbsp;although note that HP SSL1 V1.0 is only compatible with OpenVMS 8.4.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://h41379.www4.hpe.com/openvms/products/ssl/ssl.html" target="_blank"&gt;http://h41379.www4.hpe.com/openvms/products/ssl/ssl.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;p.s We curently have the following versions of SSL / VMS installed&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OpenVMS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SSL&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;AXPVMS OPENVMS V8.3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.3-281&lt;/P&gt;&lt;P&gt;I64VMS &amp;nbsp;8.3-1H1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.3-284&lt;/P&gt;&lt;P&gt;I64VMS OPENVMS V8.4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.4-334&lt;/P&gt;&lt;P&gt;I64VMS OPENVMS V8.4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V1.4-334&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 08:55:09 GMT</pubDate>
    <dc:creator>Paolo_c</dc:creator>
    <dc:date>2016-10-25T08:55:09Z</dc:date>
    <item>
      <title>SHA1 encryption under OpenSSL</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6909869#M104016</link>
      <description>&lt;P&gt;Hi , &amp;nbsp;I understand that SHA1 encryption used with OpenSSL . is due to expire shortly, and wondering if this will impact upon any of the applications running on our OpenVMS system. Although I can see some OpenSSL executables on our system below, it doesnt look as if the product is fully installed ,(inc any openssl startup files or any applications accessing these files ), so assuming its safe to assume that we're not using OpenSSL for encryption and that we wont have to consider migrating to SHA2. encryption ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[SYS0.SYSCOMMON.SSL]&lt;/P&gt;&lt;P&gt;OPENSSL-VMS.CNF;1&lt;BR /&gt;17 18-MAR-2010 21:49:58.35 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL-VMS.CNF_TEMPLATE;1&lt;BR /&gt;17 18-MAR-2010 21:49:58.35 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL.CNF;1 20 18-MAR-2010 21:49:58.37 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL.CNF_TEMPLATE;1&lt;BR /&gt;20 18-MAR-2010 21:49:58.37 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 4 files, 74 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[SYS0.SYSCOMMON.SSL.DOC]&lt;/P&gt;&lt;P&gt;OPENSSL.TXT;1 92 8-MAR-2007 09:26:14.24 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 1 file, 92 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[SYS0.SYSCOMMON.SSL.IA64_EXE]&lt;/P&gt;&lt;P&gt;OPENSSL.EXE;1 9340 18-MAR-2010 20:22:44.34 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 1 file, 9340 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[SYS0.SYSCOMMON.SSL.INCLUDE]&lt;/P&gt;&lt;P&gt;OPENSSLCONF.H;1 15 18-MAR-2010 18:28:12.53 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSLV.H;1 8 18-MAR-2010 17:04:29.51 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 2 files, 23 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[VMS$COMMON.SSL]&lt;/P&gt;&lt;P&gt;OPENSSL-VMS.CNF;1&lt;BR /&gt;17 18-MAR-2010 21:49:58.35 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL-VMS.CNF_TEMPLATE;1&lt;BR /&gt;17 18-MAR-2010 21:49:58.35 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL.CNF;1 20 18-MAR-2010 21:49:58.37 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSL.CNF_TEMPLATE;1&lt;BR /&gt;20 18-MAR-2010 21:49:58.37 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 4 files, 74 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[VMS$COMMON.SSL.DOC]&lt;/P&gt;&lt;P&gt;OPENSSL.TXT;1 92 8-MAR-2007 09:26:14.24 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 1 file, 92 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[VMS$COMMON.SSL.IA64_EXE]&lt;/P&gt;&lt;P&gt;OPENSSL.EXE;1 9340 18-MAR-2010 20:22:44.34 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 1 file, 9340 blocks.&lt;/P&gt;&lt;P&gt;Directory SYS$SYSDEVICE:[VMS$COMMON.SSL.INCLUDE]&lt;/P&gt;&lt;P&gt;OPENSSLCONF.H;1 15 18-MAR-2010 18:28:12.53 [SYSTEM (RWED,RWED,RE,RE)&lt;BR /&gt;OPENSSLV.H;1 8 18-MAR-2010 17:04:29.51 [SYSTEM (RWED,RWED,RE,RE)&lt;/P&gt;&lt;P&gt;Total of 2 files, 23 blocks.&lt;/P&gt;&lt;P&gt;Grand total of 8 directories, 16 files, 19058 blocks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 14:25:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6909869#M104016</guid>
      <dc:creator>Paolo_c</dc:creator>
      <dc:date>2016-10-21T14:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: SHA1 encryption under OpenSSL</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911057#M104017</link>
      <description>&lt;P&gt;FYI: Technically SHA1 and SHA2 are a hash or digest, not the cipher itself.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 21:13:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911057#M104017</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2016-10-22T21:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: SHA1 encryption under OpenSSL</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911698#M104018</link>
      <description>&lt;P&gt;FYI: Technically SHA1 and SHA2 are a hash or digest, not the cipher itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay but just wondering how we can establish, in advance, whether we will be impacted by loss of SHA1 encryption under OpenSSL . i &amp;nbsp;understand that HP Openview operations agent for OpenVMS (OVA) and HP System management (SMH) - (both of which we use) , are reliant on SSL but not sure how to ascertain whether the loss of SHA1 encryption under OpenSSl will have any impact on this s/ware and/or any certificates currently installed ? &amp;nbsp;We currently have the following versions of SSL installed on our live Alpha/Integrity Servers running OpenVMS, and so wondering whether any potential issues would be addressed by upgrading to (latest ?) &amp;nbsp;version&amp;nbsp;&lt;SPAN&gt; HP SSL1 V 1.0 (mentioned in the following article.) &amp;nbsp;although note that HP SSL1 V1.0 is only compatible with OpenVMS 8.4.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://h41379.www4.hpe.com/openvms/products/ssl/ssl.html" target="_blank"&gt;http://h41379.www4.hpe.com/openvms/products/ssl/ssl.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;p.s We curently have the following versions of SSL / VMS installed&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OpenVMS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SSL&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;AXPVMS OPENVMS V8.3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.3-281&lt;/P&gt;&lt;P&gt;I64VMS &amp;nbsp;8.3-1H1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.3-284&lt;/P&gt;&lt;P&gt;I64VMS OPENVMS V8.4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V 1.4-334&lt;/P&gt;&lt;P&gt;I64VMS OPENVMS V8.4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V1.4-334&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 08:55:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911698#M104018</guid>
      <dc:creator>Paolo_c</dc:creator>
      <dc:date>2016-10-25T08:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: SHA1 encryption under OpenSSL</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911852#M104019</link>
      <description>&lt;P&gt;&amp;gt; [...] it doesnt look as if the product is fully installed ,(inc any&lt;BR /&gt;&amp;gt; openssl startup files or any applications accessing these files ), [...]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Where did you look?&amp;nbsp; To see what's installed:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; product show product *ssl*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Around here, I see start-up files: SYS$STARTUP:*ssl*.com&lt;/P&gt;&lt;P&gt;&amp;gt; [...] wondering if this will impact upon any of the applications&lt;BR /&gt;&amp;gt; running on our OpenVMS system. [...]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Some of us have little idea which applications are running on your&lt;BR /&gt;OpenVMS system.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 13:57:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6911852#M104019</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2016-10-25T13:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: SHA1 encryption under OpenSSL</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6912225#M104020</link>
      <description>&lt;P&gt;Thanks for the feedback,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OpenVMS SSL&lt;BR /&gt;------------------------------------------------------------------------&lt;BR /&gt;AXPVMS OPENVMS V8.3 V 1.3-281&lt;BR /&gt;I64VMS 8.3-1H1 V 1.3-284&lt;BR /&gt;I64VMS OPENVMS V8.4 V 1.4-334&lt;BR /&gt;I64VMS OPENVMS V8.4 V1.4-334&lt;/P&gt;&lt;P&gt;Where did you look? To see what's installed:&lt;BR /&gt;product show product *ssl*&lt;/P&gt;&lt;P&gt;Around here, I see start-up files: SYS$STARTUP:*ssl*.com&lt;/P&gt;&lt;P&gt;&amp;gt; If you look at the previous update I posted to this call, you'll see that we do have SSL installed on all of our Integrity/Alpha VMS boxes. below.. My original comments referred to OpenSSL not SSL (as I making the incorrect assumption that OpenSSL and SSL aren't interlinked).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;HP I64VMS SSL V1.4-334&lt;/P&gt;&lt;P&gt;HP AXPVMS SSL V1.3-281&lt;/P&gt;&lt;P&gt;HP I64VMS SSL V1.3-284&lt;/P&gt;&lt;P&gt;&amp;gt; [...] wondering if this will impact upon any of the applications&lt;/P&gt;&lt;P&gt;&amp;gt; running on our OpenVMS system. [...]&lt;/P&gt;&lt;P&gt;Some of us have little idea which applications are running on your&lt;BR /&gt;OpenVMS system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; The only "application" I can see on our systems which appears to reference SSL is HP OpenView Operations Agent for OpenVMS (OVA) and so wondering whether this is likely to be affected by the potential issue surrouding SHA1 encryption expiring ? I note that HPE SSL1 1.02h is the latest product available for systems running OpenVMS 8.4 so wondering whether this would address any potential issues and/or whether we need to consider migrating to SSH2 encryption ? We also have some Alpha Systems running OpenVMS 8.3 (which also run OpenView Operations Agent for OpenVMS - OVA), so given that we cant upgrade to HP SS1 (without upgrading to OpenVMS 8.4) , wondering if we're likely to suffer any associated issues when SSH1 encryption expires ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 08:08:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sha1-encryption-under-openssl/m-p/6912225#M104020</guid>
      <dc:creator>Paolo_c</dc:creator>
      <dc:date>2016-10-26T08:08:35Z</dc:date>
    </item>
  </channel>
</rss>

