<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: hpsmh heartbleed in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6460722#M58571</link>
    <description>&lt;P&gt;You need something like this below. All will then work for 2003 servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2008 servers work ok with 7.3.2.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLS&lt;BR /&gt;set repos=\\server\mydomain.com\d$\Win2003_SHMfix&lt;BR /&gt;&lt;BR /&gt;Echo Replacing php5apache2.so and php5ts.dll&lt;BR /&gt;Echo From: %repos%\%PROCESSOR_ARCHITECTURE%&lt;BR /&gt;Echo To : %systemDrive%\hp\hpsmh\modules&lt;BR /&gt;Echo For %PROCESSOR_ARCHITECTURE% type OS&lt;BR /&gt;&lt;BR /&gt;net stop "HP System Management Homepage" /Y&lt;BR /&gt;timeout 5 /nobreak &amp;gt;nul&lt;BR /&gt;&lt;BR /&gt;copy %repos%\%PROCESSOR_ARCHITECTURE% %systemDrive%\hp\hpsmh\modules /Y&lt;BR /&gt;&lt;BR /&gt;set repos=&lt;BR /&gt;net Start "HP System Management Homepage" /Y&lt;BR /&gt;echo Finsihed&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2014 14:07:32 GMT</pubDate>
    <dc:creator>Steve Weeks_1</dc:creator>
    <dc:date>2014-04-29T14:07:32Z</dc:date>
    <item>
      <title>hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6446064#M58518</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We discovered that hpsmh (version 7.2.2-8) is vurnerable for the OpenSSL Heartbleed problem on tcp port 2381, when will HP fix this issue? Is it possible to manual patch the embedded openssl?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alwin.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This trhead has been moevd&amp;nbsp;from ProLiant Servers (ML,DL,SL) to ITRC HP Systems Insight Manager Forum. - Hp forum moderator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 03:32:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6446064#M58518</guid>
      <dc:creator>Alwin Warringa</dc:creator>
      <dc:date>2014-04-14T03:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6446894#M58519</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this would interest me too!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read in the Revision history of SMH for Windows, that the last update to openSSL was with HP SMH version 7.3.0.9 in which OpenSSL got updated to version 1.0.1e.&lt;/P&gt;&lt;P&gt;According to the OpenSSL Security Advisory (&lt;A target="_blank" href="https://www.openssl.org/news/secadv_20140407.txt)"&gt;https://www.openssl.org/news/secadv_20140407.txt)&lt;/A&gt; the "heartbleed" is fixed in version 1.0.1g.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HP can you please provide us information about a release of a fixed HP SMH?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 05:49:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6446894#M58519</guid>
      <dc:creator>SwisspostIT</dc:creator>
      <dc:date>2014-04-14T05:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6447042#M58521</link>
      <description>&lt;P&gt;They released a security bulletin now which is available here:&amp;nbsp;&lt;SPAN&gt;&lt;A target="_blank" href="http://alerts.hp.com/r?2.1.3KT.2ZR.11MyKG.KUeOn0..N.ewLY.8RKW.bW89MQ%5f%5fDCTOFQR0"&gt;&lt;SPAN&gt;http://alerts.hp.com/r?2.1.3KT.2ZR.11MyKG.KUeOn0..N.ewLY.8RKW.bW89MQ%5f%5fDCTOFQR0&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(No information yet about a release of a fixed version)&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 09:20:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6447042#M58521</guid>
      <dc:creator>SwisspostIT</dc:creator>
      <dc:date>2014-04-14T09:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6448718#M58530</link>
      <description>&lt;P&gt;I was able to patch the service with a non-vulnerable openssl obtained from Red Hat rpms:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;openssl-1.0.1e-16.el6_5.7.x86_64.rpm&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;openssl-devel-1.0.1e-16.el6_5.7.x86_64.rpm&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is necessary to extract the binary, libraries and creating the necessary symlinks:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/hp/hpsmh # ll bin/openssl&lt;/P&gt;&lt;P&gt;-rwxr-xr-x 1 czkccz adminux 521472 Apr 15 10:00 &lt;STRONG&gt;bin/openssl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/hp/hpsmh # ll lib/libssl.so*&lt;/P&gt;&lt;P&gt;lrwxrwxrwx 1 root&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 Apr 15 10:06 lib/libssl.so -&amp;gt; libssl.so.1.0.1e&lt;/P&gt;&lt;P&gt;lrwxrwxrwx 1 root&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 Apr 15 10:06 lib/libssl.so.1.0.0 -&amp;gt; libssl.so.1.0.1e&lt;/P&gt;&lt;P&gt;-rwxr-xr-x 1 czkccz adminux 441112 Apr 15 10:01 &lt;STRONG&gt;lib/libssl.so.1.0.1e&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/hp/hpsmh # ll lib/libcrypto.so*&lt;/P&gt;&lt;P&gt;lrwxrwxrwx 1 root&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19 Apr 15 10:09 lib/libcrypto.so -&amp;gt; libcrypto.so.1.0.1e&lt;/P&gt;&lt;P&gt;lrwxrwxrwx 1 root&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19 Apr 15 10:09 lib/libcrypto.so.1.0.0 -&amp;gt; libcrypto.so.1.0.1e&lt;/P&gt;&lt;P&gt;-rwxr-xr-x 1 czkccz adminux 1950976 Apr 15 10:08 &lt;STRONG&gt;lib/libcrypto.so.1.0.1e&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;lrwxrwxrwx 1 root&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19 Apr 15 10:10 &lt;STRONG&gt;lib/libcrypto.so.10&lt;/STRONG&gt; -&amp;gt; libcrypto.so.1.0.1e&lt;/P&gt;&lt;P&gt;/opt/hp/hpsmh #&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the script (&lt;A target="_blank" href="https://github.com/noxxi/p5-scripts/blob/master/check-ssl-heartbleed.pl"&gt;https://github.com/noxxi/p5-scripts/blob/master/check-ssl-heartbleed.pl&lt;/A&gt;) to check and indicated that it is no longer vulnerable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# /etc/init.d/hpsmhd start&lt;/P&gt;&lt;P&gt;Starting hpsmhd ..&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; done&lt;/P&gt;&lt;P&gt;# ./ssl-hearbleed-check.pl -s 127.0.0.1:2381&lt;/P&gt;&lt;P&gt;...ssl received type=22 ver=0x301 ht=0x2 size=77&lt;/P&gt;&lt;P&gt;...ssl received type=22 ver=0x301 ht=0xb size=968&lt;/P&gt;&lt;P&gt;...ssl received type=22 ver=0x301 ht=0xe size=0&lt;/P&gt;&lt;P&gt;...send heartbeat#1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no reply - probably not vulnerable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it will be useful, while a new hpsmh version is released.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sergio&amp;nbsp;Ramirez&lt;/P&gt;&lt;P&gt;GNU/Linux Team&lt;/P&gt;&lt;P&gt;HP Enterprise Services México&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 16:10:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6448718#M58530</guid>
      <dc:creator>beermaster</dc:creator>
      <dc:date>2014-04-15T16:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6449242#M58532</link>
      <description>&lt;P&gt;Do we have any procedure for windows systems?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 05:26:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6449242#M58532</guid>
      <dc:creator>AUS-1032</dc:creator>
      <dc:date>2014-04-16T05:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6450300#M58537</link>
      <description>&lt;P&gt;Windows&lt;BR /&gt;&amp;nbsp;64&lt;BR /&gt;&amp;nbsp; 7.3.2.1 = cp023240 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/sc-windows/p221526337/v96952/cp023240.exe" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/sc-windows/p221526337/v96952/cp023240.exe&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; 7.2.3.1 = cp023243 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/sc-windows/p221526337/v96957/cp023243.exe" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/sc-windows/p221526337/v96957/cp023243.exe&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;32&lt;BR /&gt;&amp;nbsp; 7.3.2.1 = cp023239 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/sc-windows/p11160892/v96949/cp023239.exe" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/sc-windows/p11160892/v96949/cp023239.exe&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; 7.2.3.1 = cp023242 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/sc-windows/p11160892/v96955/cp023242.exe" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/sc-windows/p11160892/v96955/cp023242.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Linux&lt;BR /&gt;&amp;nbsp;64&lt;BR /&gt;&amp;nbsp; 7.3.2.1 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/pubsw-linux/p1507410135/v96951/hpsmh-7.3.2-1.x86_64.rpm" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/pubsw-linux/p1507410135/v96951/hpsmh-7.3.2-1.x86_64.rpm&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;32&lt;BR /&gt;&amp;nbsp; 7.3.2.1 = &lt;A href="http://ftp.hp.com/pub/softlib2/software1/pubsw-linux/p1980463820/v96948/hpsmh-7.3.2-1.i386.rpm" target="_blank"&gt;http://ftp.hp.com/pub/softlib2/software1/pubsw-linux/p1980463820/v96948/hpsmh-7.3.2-1.i386.rpm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 01:10:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6450300#M58537</guid>
      <dc:creator>Casper42</dc:creator>
      <dc:date>2014-04-17T01:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6451448#M58540</link>
      <description>&lt;P&gt;Hello people,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've updated the SMH for a Windows 2008 R2 server to the new version 7.3.2.1.&lt;/P&gt;&lt;P&gt;Now i get a timeout on the System Management homepage. I used the VCA 7.2.0.0 and this version becomes unresponsive with the new SMH. I had to update to the latest VCA. That version has the bug that you can't update the Diskfirmware. HP advised me to uninstall the VCA since HPSUm is the new way to update instead of VCA. So HP is leaving VCA. So i've just posteded this message to let you all know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew Haak&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2014 12:33:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6451448#M58540</guid>
      <dc:creator>Andrew_Haak</dc:creator>
      <dc:date>2014-04-18T12:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6454834#M58546</link>
      <description>&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your information!&lt;/P&gt;&lt;P&gt;Are you aware of any other bugs from the newest VCA except the harddisk firmware issue?&lt;/P&gt;&lt;P&gt;We'd like to have it installed anyway on the systems, so you have a overview of installed firmware/driver/software on one page... (unless we'll have rolled out HPSUM on every system)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Ville&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 07:52:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6454834#M58546</guid>
      <dc:creator>SwisspostIT</dc:creator>
      <dc:date>2014-04-23T07:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455418#M58553</link>
      <description>&lt;P&gt;Please be aware that the 32 bit Windows 7.3.2.1 version of the patch breaks the HP smh, the service starts but is not listening on 2381&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;smhstart_err.log show it cannot load the&amp;nbsp;php5apache2.so module&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 15:54:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455418#M58553</guid>
      <dc:creator>mikj</dc:creator>
      <dc:date>2014-04-23T15:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455718#M58554</link>
      <description>&lt;P&gt;mikj , I think I installed this on a 32bit windows 7.3.2.1 version and now when I try to open up&amp;nbsp; &lt;A href="https://localhost:2381/" target="_blank"&gt;https://localhost:2381&lt;/A&gt;&amp;nbsp;&amp;nbsp; i get a page can not be displayed ...&amp;nbsp; are you having same issue as me ?&lt;/P&gt;&lt;P&gt;I installed this on my windows 2003 standard version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 19:25:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455718#M58554</guid>
      <dc:creator>sungminjin</dc:creator>
      <dc:date>2014-04-23T19:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455816#M58555</link>
      <description>&lt;P&gt;Yes, the new(er) versions seems to break SMH and will not load.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I stayed on 7.2.2.9 for that reason alone.&lt;/P&gt;&lt;P&gt;Except for 2008 R2, if I install it on 2003 x32 or x64, the SMH page no longer loads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rather frustrating.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 21:22:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6455816#M58555</guid>
      <dc:creator>Sean Murray_1</dc:creator>
      <dc:date>2014-04-23T21:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6456358#M58561</link>
      <description>&lt;P&gt;Hello: To All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HP is committed to delivering secure systems that effectively manage our invaluable customer and employee data. Therefore we kindly request you to reach out to our&amp;nbsp;Software Security Response Team (SSRT).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly find the given below "Report a potential security vulnerability to HP"&amp;nbsp;&lt;SPAN style="line-height: 1.2;"&gt;link, If any claims you people have been impacted and/or have details where you can share with HP&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.2;"&gt;&amp;nbsp;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://h41268.www4.hp.com/live/index.aspx?qid=11503" target="_blank"&gt;https://h41268.www4.hp.com/live/index.aspx?qid=11503&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 10:40:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6456358#M58561</guid>
      <dc:creator>RASHMI</dc:creator>
      <dc:date>2014-04-24T10:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6457016#M58565</link>
      <description>&lt;P&gt;Rashmi, we know what the vulnerability is... and so does HP. We just want a fix that works on our 32 bit (x86) operating systems!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 18:00:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6457016#M58565</guid>
      <dc:creator>David Orwig</dc:creator>
      <dc:date>2014-04-24T18:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6457816#M58568</link>
      <description>&lt;P&gt;I am in the same boat - Windows 2003 servers that cannot run the latest SMH.&amp;nbsp; I am wondering if there is an older version of SMH that is free of the Heartbleed bug and also works with Windows 2003?&amp;nbsp; In other words, how long has Heartbleed been a problem?&amp;nbsp; Has it just shown up in the last few versions, and earlier version are OK?&amp;nbsp; If so, what is the last version of SMH that had a version of OpenSSL free from Heartbleed problems?&amp;nbsp; That is the version I would need to install since the lastest version - which fixes Heartbleed - is not supported on Windows 2003.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;NK&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:35:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6457816#M58568</guid>
      <dc:creator>NJK-Work</dc:creator>
      <dc:date>2014-04-25T14:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6460722#M58571</link>
      <description>&lt;P&gt;You need something like this below. All will then work for 2003 servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2008 servers work ok with 7.3.2.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLS&lt;BR /&gt;set repos=\\server\mydomain.com\d$\Win2003_SHMfix&lt;BR /&gt;&lt;BR /&gt;Echo Replacing php5apache2.so and php5ts.dll&lt;BR /&gt;Echo From: %repos%\%PROCESSOR_ARCHITECTURE%&lt;BR /&gt;Echo To : %systemDrive%\hp\hpsmh\modules&lt;BR /&gt;Echo For %PROCESSOR_ARCHITECTURE% type OS&lt;BR /&gt;&lt;BR /&gt;net stop "HP System Management Homepage" /Y&lt;BR /&gt;timeout 5 /nobreak &amp;gt;nul&lt;BR /&gt;&lt;BR /&gt;copy %repos%\%PROCESSOR_ARCHITECTURE% %systemDrive%\hp\hpsmh\modules /Y&lt;BR /&gt;&lt;BR /&gt;set repos=&lt;BR /&gt;net Start "HP System Management Homepage" /Y&lt;BR /&gt;echo Finsihed&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 14:07:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6460722#M58571</guid>
      <dc:creator>Steve Weeks_1</dc:creator>
      <dc:date>2014-04-29T14:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461018#M58572</link>
      <description>Yes please lets see a fix. I created an account just to leave this comment, thats how much i'd love a fix =) It's disconcerting that HP mentions that this is addressed and fixed already for x86 and x64 when the proof is in the pudding regarding the drop of PHP5 code suppport.&lt;BR /&gt;&lt;BR /&gt;Rashmi, can you put HP SSRT in contact with this thread and notice the 2300+ unique views on it?</description>
      <pubDate>Tue, 29 Apr 2014 17:23:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461018#M58572</guid>
      <dc:creator>The_Stig</dc:creator>
      <dc:date>2014-04-29T17:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461892#M58573</link>
      <description>&lt;P&gt;Two new versions of SMH are available, which provides fix for this vulnerability:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SMH 7.3.2&lt;/P&gt;&lt;P&gt;SMH 7.2.3&lt;/P&gt;&lt;P&gt;&lt;IMG title="Upgrade_path.jpg" src="https://community.hpe.com/t5/image/serverpage/image-id/42354iE7EC4DA455A25B99/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Upgrade_path.jpg" align="center" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 10:22:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461892#M58573</guid>
      <dc:creator>pkrai</dc:creator>
      <dc:date>2014-04-30T10:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461922#M58574</link>
      <description>&lt;P&gt;Please find enclosed some more information around the same topic...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 11:23:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6461922#M58574</guid>
      <dc:creator>pkrai</dc:creator>
      <dc:date>2014-04-30T11:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6462362#M58576</link>
      <description>&lt;P&gt;Let's say, for the sake of argument, that you absolutely cannot update to the latest version of SMH, VCA or VCRM. &amp;nbsp;All 3 of those have recently been updated to include OpenSSL 1.0.1g, but let's pretend you can't update for whatever reason (compatibility concerns, effort involved, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could, if you want, simply download OpenSSL 1.0.1g for your OS and update the files yourself. &amp;nbsp;I don't have any physical boxes running Linux so I won't pretend to know about that, but someone already mentioned how a few posts up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Windows, you download a compiled version and you should have a couple of DLL's to focus on:&lt;/P&gt;&lt;P&gt;ssleay32.dll&lt;/P&gt;&lt;P&gt;libeay32.dll&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're having trouble finding compiled versions of those DLL's, well hey, just extract the contents of the latest VCA, VCRM or SMH and they're inside there, both 32 and 64 bit versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your Windows machine, under C:\HP you'll find multiple locations where those files exist, depending on what all you have installed. &amp;nbsp;On my machine which has SMH, VCA *and* VCRM installed, there are 4 spots where both files live:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\hp\hpsmh\bin\libeay32.dll&lt;BR /&gt;C:\hp\hpsmh\bin\ssleay32.dll&lt;BR /&gt;C:\hp\hpsmh\data\cgi-bin\vcagent\libeay32.dll&lt;BR /&gt;C:\hp\hpsmh\data\cgi-bin\vcagent\ssleay32.dll&lt;BR /&gt;C:\hp\hpsmh\data\cgi-bin\vcrepository\libeay32.dll&lt;BR /&gt;C:\hp\hpsmh\data\cgi-bin\vcrepository\ssleay32.dll&lt;BR /&gt;C:\hp\hpsmh\modules\libeay32.dll&lt;BR /&gt;C:\hp\hpsmh\modules\ssleay32.dll&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't quite figure out why, but the DLLs located in hpsmh\bin and hpsmh\modules are slightly different filesizes than the ones in vcagent and vcrepository... they're all 1.0.1g though, and the 64-bit version on my 64-bit Windows, but it's odd. &amp;nbsp;It's like HP compiled them differently. &amp;nbsp;I think it'd be safe to use the same one for all the spots though, but if you really want to be sure, extract the specific files from the specific HP software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, copy over either the 32 or 64 bit version depending on what you're running. &amp;nbsp; You'll need to stop the services first of course. &amp;nbsp;If you use the files from inside the HP software, the 64-bit versions have "x64" in the filename, so just copy them over to the regular filename.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If none of this is making any sense, then you probably shouldn't be attempting something like this... just saying...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh, and if you're running HP SIM, there's no new version out yet, but it's running an older version of OpenSSL that isn't vulnerable. &amp;nbsp;I just checked, and my HP SIM 7.3 with the latest hotfixes only has version 0.9.8d. &amp;nbsp;Seems like HP SIM is safe only by it's extreme negligence in keeping it's SSL libraries up to date in the first place. &amp;nbsp;Could be worse I guess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course your best bet is to install the latest HP software anyway because there's more fixes besides just OpenSSL, but if none of them apply to you and you're happy with the version you're on, this could be an easier way to go to secure things. &amp;nbsp;Just script something to stop those services remotely, copy the new files out where they belong, and restart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disclaimer: I have NOT tried this out myself, but when Heartbleed was first announced, I looked into doing this as a plan B in case HP dragged it's feet getting it patched properly. &amp;nbsp;If it doesn't work, keep those old DLL's handy and roll back if needed.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 15:50:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6462362#M58576</guid>
      <dc:creator>waaronb</dc:creator>
      <dc:date>2014-04-30T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: hpsmh heartbleed</title>
      <link>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6462552#M58581</link>
      <description>&lt;P&gt;Thanks for the version list - that was vey helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that mean if I have a server running a much version of the SMH, that I dont have to update it (to patch for Heartbleed)?&amp;nbsp; For example, if I have a server running this version:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HP System Management Homepage v3.0.1.73&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and since this version is not on your list, it is not affected by Heartbleed (I am assuming it is using an older version OpenSSL that was not affected by Heartbleed)?&amp;nbsp; Or are pretty much ALL versions of SHM affected by Heartbleed except the two new versions you listed.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;NK&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 17:49:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/hpsmh-heartbleed/m-p/6462552#M58581</guid>
      <dc:creator>NJK-Work</dc:creator>
      <dc:date>2014-04-30T17:49:21Z</dc:date>
    </item>
  </channel>
</rss>

