<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL 1.4 breaks running environments in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648244#M18390</link>
    <description>For OpenSSL, if you cannot link PHP again,there is no alternative than the options you describe (changing logicals around).&lt;BR /&gt;&lt;BR /&gt;Installing the older version will probably not work, I'm not sure what will happen: either it will not install, or it will remove the newer version. OpenSSL is not upward compatible between any version that has different numbers ( 9.6.7 != 9.6.8). &lt;BR /&gt;&lt;BR /&gt;It's a pain.</description>
    <pubDate>Tue, 22 Jun 2010 14:21:07 GMT</pubDate>
    <dc:creator>SDIH1</dc:creator>
    <dc:date>2010-06-22T14:21:07Z</dc:date>
    <item>
      <title>SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648239#M18385</link>
      <description>I'm using 8.4FT and ran into a problem with PHP: Ident mismatch with SSL$LIBCRYPTO_SHR32, in both PHPSHR and PHP. This seems to be an issue with SSL 1.4; others have downloaded the SSL kit from ITRC, and found remarks in the release notes that it would be incompatible with a lot of (HP-supplied!) products:&lt;BR /&gt;&lt;BR /&gt; LDAP&lt;BR /&gt; ENCRYPT (and therefore BACKUP/ENCRYPT)&lt;BR /&gt; Stunnel&lt;BR /&gt; HP System Management Homepage (HP SMH) for OpenVMS&lt;BR /&gt; HP WBEM Services for OpenVMS Integrity servers&lt;BR /&gt; HP OpenView Operations Agent for OpenVMS&lt;BR /&gt; OpenView Performance Agent (OVPA) for OpenVMS&lt;BR /&gt; Secure Web Server&lt;BR /&gt; ABS&lt;BR /&gt; HP Enterprise Directory&lt;BR /&gt; iCAp/nPar (dependent on HP WBEM Services)&lt;BR /&gt;&lt;BR /&gt;For the webserver that I use (WASD), there is no issue since it is supplied as object files and linked locally on installtion. But since the files in MOD_PHP are not supplied that way, they won't work.&lt;BR /&gt;&lt;BR /&gt;Of course, I could install the previous version of SSL on the system and refer to that version for PHP and PHPSHR only, but I learned from an earlier version of PHP that when a shared image was referred to by a logical, this is ignored by PHP: the file MUST reside on SYS$LIBRARY.&lt;BR /&gt;I could add a separate directory for SSL 1.3 and add the location to the searchlist of SYS$LIBARY just for PHP, but I consider this a bad idea....&lt;BR /&gt;&lt;BR /&gt;Could be assured, PLEASE, that when a VMS system is upgraded to 8.4, that ALL exsiting applications would still work - without the requirement to relink the applications - since that may not always be possible!</description>
      <pubDate>Wed, 16 Jun 2010 07:06:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648239#M18385</guid>
      <dc:creator>Willem Grooters</dc:creator>
      <dc:date>2010-06-16T07:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648240#M18386</link>
      <description>More details available over at &lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/openvms/products/ssl/ssl.html" target="_blank"&gt;http://h71000.www7.hp.com/openvms/products/ssl/ssl.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;and updated versions of various components are appearing in patches. &lt;BR /&gt;&lt;BR /&gt;If you want to use SSL V1.4 then plan it's deployment carefully.&lt;BR /&gt;&lt;BR /&gt;As it appears that OpenVMS V8.4 includes SSL 1.4 then careful planning about upgrading will be needed.&lt;BR /&gt;&lt;BR /&gt;HP SSL is based on OpenSSL.org and the API is not stable at least to version 1.0.0</description>
      <pubDate>Wed, 16 Jun 2010 11:19:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648240#M18386</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2010-06-16T11:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648241#M18387</link>
      <description>Willem,&lt;BR /&gt;&lt;BR /&gt;just after releasing HP SSL V1.4, there now also appeared a security advice against HP SSL V1.3 - what a coincidence ;-(&lt;BR /&gt;&lt;BR /&gt;HPSBOV02540 SSRT090249 rev.1 - HP SSL for OpenVMS, Remote Unauthorized Data Injection, Denial of Service(Dos)&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Thu, 17 Jun 2010 08:35:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648241#M18387</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2010-06-17T08:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648242#M18388</link>
      <description>here is a pointer to that bulletin&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02227287" target="_blank"&gt;http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02227287&lt;/A&gt;</description>
      <pubDate>Thu, 17 Jun 2010 09:11:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648242#M18388</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2010-06-17T09:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648243#M18389</link>
      <description>Note that updates are appearing for the RTLs and Layered Products affected by this change.&lt;BR /&gt;&lt;BR /&gt;At the time of writing, new versions of ENCRYPT and ACMELDAP are available for download from ITRC.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Jeremy Begg</description>
      <pubDate>Fri, 18 Jun 2010 02:14:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648243#M18389</guid>
      <dc:creator>Jeremy Begg</dc:creator>
      <dc:date>2010-06-18T02:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648244#M18390</link>
      <description>For OpenSSL, if you cannot link PHP again,there is no alternative than the options you describe (changing logicals around).&lt;BR /&gt;&lt;BR /&gt;Installing the older version will probably not work, I'm not sure what will happen: either it will not install, or it will remove the newer version. OpenSSL is not upward compatible between any version that has different numbers ( 9.6.7 != 9.6.8). &lt;BR /&gt;&lt;BR /&gt;It's a pain.</description>
      <pubDate>Tue, 22 Jun 2010 14:21:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648244#M18390</guid>
      <dc:creator>SDIH1</dc:creator>
      <dc:date>2010-06-22T14:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648245#M18391</link>
      <description>I just realized last night that I'm stuck with this too.&lt;BR /&gt;&lt;BR /&gt;I use WBEM$SERVER (MGMT Agents 3.4) so that I can run the SNMP page without loading Apache (I have pretty strict audit requirements that say no web servers on database servers).&lt;BR /&gt;&lt;BR /&gt;I had been able to throw MGMT Agents 3.4 on Alphas and Itaniums with no issue but now it looks like I'm being forced towards SMH, which pushes me towards apache and I can't go there.&lt;BR /&gt;&lt;BR /&gt;Does anybody know if there's a way to run SMH without starting the Apache server?&lt;BR /&gt;&lt;BR /&gt;I know that there's something newer for Itaniums but I still have a lot of Alpha clients too.</description>
      <pubDate>Sat, 16 Oct 2010 15:06:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648245#M18391</guid>
      <dc:creator>Carl Bennett_1</dc:creator>
      <dc:date>2010-10-16T15:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648246#M18392</link>
      <description>Willem,&lt;BR /&gt;&lt;BR /&gt;You KNEW this beforehand! (Or at least SHOULD have known).&lt;BR /&gt;I was sitting in the chair next to you at the Dutch TUD when this was warned about in the "what is new in 8.4" session.&lt;BR /&gt;Neihther the audience nor Engineering was happy about it, but if you (have to) follow OpenSource, and OpenSource does not really care about upward compatibility, this is what you get.&lt;BR /&gt;&lt;BR /&gt;But still it is REALLY unsatisfying, of course :-(&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one in me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Sun, 17 Oct 2010 10:41:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648246#M18392</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2010-10-17T10:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648247#M18393</link>
      <description>It'd be interesting to learn more about the changes to the SSL interfaces involved here, as there do appear to be paths available for establishing the SSL version upgrades more incrementally; without the big-bang upgrade.&lt;BR /&gt;&lt;BR /&gt;If the changes here were strictly API-level changes and whether changed APIs, new APIs,  or removed APIs, then the implementation of the upgrade could have easily been handled (differently), and the results would have permitted an incremental SSL upgrade.  Which implies that there were more endemic changes involved here.  Which makes me curious around the changes.&lt;BR /&gt;&lt;BR /&gt;Lacking the details of the complexity of the API changes (and lacking equally key, though entirely API-tangental details, including available project scheduling and staffing), I'll leave it to VMS Engineering to have made the appropriate design and deployment calls here.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;&lt;BR /&gt;FWIW, the OpenSSL code-base hasn't hit their V1.0 release, so they've not locked down their programming interfaces.    Without (or even with!) that compatibility statement from the project team, interface changes are a normal part of software development operations with layered products, and have arisen even within VMS itself. &lt;BR /&gt;&lt;BR /&gt;Yes, API compatibility has occasionally gone sideways within VMS itself, such as what happened with the BACKUP API some years back.&lt;BR /&gt;&lt;BR /&gt;These sorts of incompatible changes to tools and APIs are somewhat more typical in a Unix environment, which can be (somewhat counterintuitively) a strength.  Maintaining compatibility is not without its costs.  (And of all the folks around, the folks in VMS engineering most definitely appreciate the costs of this compatibility.)</description>
      <pubDate>Sun, 17 Oct 2010 13:47:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648247#M18393</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2010-10-17T13:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648248#M18394</link>
      <description>On the OpenSSL website I found additional information. There have been complaints here as well. It seems the team works toward a 1.0 version and it is agreed that supervision has been lacking - causing this mess. That has to removed first. And even after 1.0 has been released, newer version will be incompatible - once again - with previous one. &lt;BR /&gt;&lt;BR /&gt;So be prepared for even more trouble.</description>
      <pubDate>Sun, 17 Oct 2010 16:34:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648248#M18394</guid>
      <dc:creator>Willem Grooters</dc:creator>
      <dc:date>2010-10-17T16:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648249#M18395</link>
      <description>SSL 1.4 also "broke"  ConnectDirect A.K.A NDM under V8.3A during ECO/upgrade activity.&lt;BR /&gt;NDM version V3.4-01 ECO-A071209 SP.</description>
      <pubDate>Wed, 27 Oct 2010 15:31:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648249#M18395</guid>
      <dc:creator>Zia_Ahmad</dc:creator>
      <dc:date>2010-10-27T15:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648250#M18396</link>
      <description>Anyone else run into this same issue with OVO v8 agent install on OpenVMS v8.4 integrity?&lt;BR /&gt;-------------------------------------------&lt;BR /&gt;HP I64VMS VMSSPI V8.0-1: HP OpenView Operations Operating System Smart Plug-In f&lt;BR /&gt;or OpenVMS&lt;BR /&gt;&lt;BR /&gt;    Read me file is available in sys$specific:[ovo]VMSSPI_README.TXT&lt;BR /&gt;Defining OVO$POSIX_ROOT to DSA7:[OVO$FOCDI1.OVO.],DSA7:[OVO$COMMON_IA64.OVO.]&lt;BR /&gt;          Starting opcactivate utility.&lt;BR /&gt;&lt;BR /&gt;NOTE:     opcactivate script will use the values:&lt;BR /&gt;          OVO Server hostname:          HPOM7001WIN&lt;BR /&gt;          Certificate Server hostname:  HPOM7001WIN&lt;BR /&gt;&lt;BR /&gt;%DCL-W-ACTIMAGE, error activating image SSL$LIBSSL_SHR32&lt;BR /&gt;-CLI-E-IMGNAME, image file DSA1:[SYS0.SYSCOMMON.][SYSLIB]SSL$LIBSSL_SHR32.EXE&lt;BR /&gt;-SYSTEM-F-SHRIDMISMAT, ident mismatch with shareable image&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Jan 2011 15:56:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648250#M18396</guid>
      <dc:creator>Joseph Bettro</dc:creator>
      <dc:date>2011-01-04T15:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648251#M18397</link>
      <description>Try redirecting the image activations to side copies of the old shareable images via logical name?  &lt;BR /&gt;&lt;BR /&gt;Place old copies elsewhere and aim some logical names at it.  (Given the file is installed, it'll have to be a trusted logical name in a trusted logical name table, unfortunately.)  Or if you're so inclined, you might try patching the OVO images to reference a different name for the file, and use that as a shim to insinuate the older images into the activation path.  (Given this is security code, that shim may or may not work.)&lt;BR /&gt;&lt;BR /&gt;Do call HP support, and let them know they apparently have another dependency issue with the SSL patch, if they haven't noticed this case already.&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Jan 2011 16:44:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648251#M18397</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2011-01-04T16:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL 1.4 breaks running environments</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648252#M18398</link>
      <description>This is brand new system build so unfortunately no prior version of SSl exists. I don't want to take the chance of installing a prior version and breaking some other products. I've got a case open with HP for the OVO install issue...&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Tue, 04 Jan 2011 17:54:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssl-1-4-breaks-running-environments/m-p/4648252#M18398</guid>
      <dc:creator>Joseph Bettro</dc:creator>
      <dc:date>2011-01-04T17:54:39Z</dc:date>
    </item>
  </channel>
</rss>

