<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464280#M58588</link>
    <description>&lt;P&gt;Yes - you are exactly right.&amp;nbsp; You can also use the SMH GUI to generate a CSR, grab the file from that same directory and sign it with your CA and then replace the file cert.pem with your new cert (use the same name).&amp;nbsp; Its a&amp;nbsp;lot of work to provide custom certs for 100's of servers so I can see why nobody would want to do it and you are probably better off you doing the simpler method they provide (deleting the existing files and restarting the service).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nelson&lt;/P&gt;</description>
    <pubDate>Fri, 02 May 2014 15:57:21 GMT</pubDate>
    <dc:creator>NJK-Work</dc:creator>
    <dc:date>2014-05-02T15:57:21Z</dc:date>
    <item>
      <title>Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration</title>
      <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464214#M58587</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to managing a Windows Server&amp;nbsp;environment which&amp;nbsp;is&amp;nbsp;a mix of Windows Server 2003/2008 &amp;nbsp;(32/64 bit) versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, several hundred servers had been detected with the Heartbleed bug on port 2381 which I beleive is related to SMH. The SMH version&amp;nbsp;was 7.2.2 which HP recommeds to upgrade to 7.2.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of the priority, I quickly upgraded these to 7.2.3&amp;nbsp;by installing the suggested .exe on HP site :&lt;/P&gt;
&lt;P&gt;&lt;A href="http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay?javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%253Demr_na-c04251388-1%257CdocLocale%253D%257CcalledBy%253D&amp;amp;javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;ac.admitted=1399017795638.876444892.199480143" target="_blank"&gt;http://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay?javax.portlet.begCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.endCacheTok=com.vignette.cachetoken&amp;amp;javax.portlet.prp_ba847bafb2a2d782fcbb0710b053ce01=wsrp-navigationalState%3DdocId%253Demr_na-c04251388-1%257CdocLocale%253D%257CcalledBy%253D&amp;amp;javax.portlet.tpst=ba847bafb2a2d782fcbb0710b053ce01&amp;amp;ac.admitted=1399017795638.876444892.199480143&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above fixed the vulnerability and produced clean scans.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I now wish to regenerate the certificates and am completely lost on how I should do that. As per the doc above,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"If it is suspected that a datacenter has been compromised by this security vulnerability, delete the SMH certificate or back it up by moving it to a private folder. The SMH certificate is located on each node of the datacenter, with the filenames cert.pem and file.pem, in folder C:\hp\sslshare. A new certificate will be created when the SMH service starts (at the end of the upgrade or new installation)."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the above mean that if&amp;nbsp;simply delete cert.pem and file.pem and restart the SMH service, the certificates will be re-genreated and&amp;nbsp;the issue is solved?&lt;/P&gt;
&lt;P&gt;Or When it says &amp;nbsp;"(at the end of the upgrade or new installation)", does it mean that I have to reinstall 7.2.3?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(FYI, PKI is *not* being used in our environment.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2014 08:07:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464214#M58587</guid>
      <dc:creator>aruntechie123</dc:creator>
      <dc:date>2014-05-12T08:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration</title>
      <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464280#M58588</link>
      <description>&lt;P&gt;Yes - you are exactly right.&amp;nbsp; You can also use the SMH GUI to generate a CSR, grab the file from that same directory and sign it with your CA and then replace the file cert.pem with your new cert (use the same name).&amp;nbsp; Its a&amp;nbsp;lot of work to provide custom certs for 100's of servers so I can see why nobody would want to do it and you are probably better off you doing the simpler method they provide (deleting the existing files and restarting the service).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nelson&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2014 15:57:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464280#M58588</guid>
      <dc:creator>NJK-Work</dc:creator>
      <dc:date>2014-05-02T15:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration</title>
      <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464286#M58589</link>
      <description>&lt;P&gt;Sorry, I just re-read you your post.&amp;nbsp; Here is what I would do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Install latest SMH.&amp;nbsp; Do not install 7.3.2 on Windows 2003.&amp;nbsp; This breaks&amp;nbsp;SMH as Windows 2003 does not support the the versionof PHP included in the SMH 7.3 familiy.&amp;nbsp; Use 7.2.3 for Windows 2003 and 7.3.2 for Windows 2008 and up.&amp;nbsp; This fixes the Heartbleed bug in HP SMH software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Install latest VCAgent if you are using it.&amp;nbsp; You can use 7.3.2 version of the VCA for both Windows 2003 and 2008 and up servers.&amp;nbsp; This fixes the Heartbleed bug in the HP VCA software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are worried your existing certificates have been comprimised, delete the certs as you outlined in your post and restart the SHM agent service to have them regenerated.&amp;nbsp; As you mentioned you are not using PKI you can ignore my earlier post regarding creating CSRs...and that is a lot of work anyways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;NK&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2014 16:05:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6464286#M58589</guid>
      <dc:creator>NJK-Work</dc:creator>
      <dc:date>2014-05-02T16:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration</title>
      <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6471616#M58618</link>
      <description>&lt;P&gt;Hello Nelson,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your advice.&lt;/P&gt;&lt;P&gt;I followed the steps you mentioned and received about 80% successful fixes (upgrades).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, on about 20% of the servers, the scan script still reports "probably vulnerable" for heartbleed&lt;/P&gt;&lt;P&gt;(a) c:\hp\hpsmh\bin\smhlogreader --version displays 7.2.3.1&lt;BR /&gt;(b) c:\hp\hpsmh\bin\ssleay32.dll and libeay32.dll show Product version as "1.0.1c"&lt;BR /&gt;(c) c:\smh_installer.log&amp;nbsp; seems to indicate a successful upgrade. PFA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I have not updated the VCAgent for any as yet)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Sun, 11 May 2014 22:30:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6471616#M58618</guid>
      <dc:creator>aruntechie123</dc:creator>
      <dc:date>2014-05-11T22:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie : HP Systems Mangement Homepage SSL Heartbleed bug; Cert regeneration</title>
      <link>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6475114#M58622</link>
      <description>Just FYI, once rebooted, it was fine.</description>
      <pubDate>Wed, 14 May 2014 14:59:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/newbie-hp-systems-mangement-homepage-ssl-heartbleed-bug-cert/m-p/6475114#M58622</guid>
      <dc:creator>aruntechie123</dc:creator>
      <dc:date>2014-05-14T14:59:54Z</dc:date>
    </item>
  </channel>
</rss>

