Operating System - OpenVMS
1752786 Members
5675 Online
108789 Solutions
New Discussion

Re: Field Test version of SSL T1.4 is now available in the web!

 

Field Test version of SSL T1.4 is now available in the web!

http://h71000.www7.hp.com/openvms/products/ssl/ssl.html

This new release is based on OpenSSL 0.9.8h and it includes all latest security updates from openssl.org.

Since SSL is not backward compatible, I request all SSL consumers to rebuild your application (to make use of this latest SSL version for VMS).

Please let us know if you find any problems/issues while building/testing your application.

In another one month we will be releasing the V version.


Regards
Srividhya
7 REPLIES 7
Jon Pinkley
Honored Contributor

Re: Field Test version of SSL T1.4 is now available in the web!

Srividhya,

Thanks for the pointer.

From the

HP SSL Version T1.4 for OpenVMS
Installation Guide and Release Notes

September 2009
-------------------------------------------------------------------


http://h71000.www7.hp.com/openvms/products/ssl/ssl_iguide.txt


Software Prerequisites

HP SSL for OpenVMS requires the following software.

- Operating System

HP OpenVMS Alpha Version 8.2-1 or higher, or
HP OpenVMS Integrity server Version 8.2-1 or higher

- TCP/IP Transport

HP TCP/IP Services for OpenVMS Version 5.6 or higher (for HP SSL on
OpenVMS Integrity server and OpenVMS Alpha Version 8.2 or higher), or

HP TCP/IP Services for OpenVMS Version 5.4 or higher (for HP SSL on
OpenVMS Alpha Version 7.3-2)

-------------------------------------------------------------------

If OpenVMS Alpha Version 8.2-1 or higher is required, why does this show up?

HP TCP/IP Services for OpenVMS Version 5.4 or higher (for HP SSL on
OpenVMS Alpha Version 7.3-2)

Is the T1.4 field test compatible with 7.3-2 / TCPIP 5.4 or not?

Jon
it depends
Volker Halle
Honored Contributor

Re: Field Test version of SSL T1.4 is now available in the web!

Jon,

these probably are cut & paste errors and indicate, that noone is really cross-checking those documents for correctness - EXCEPT the OpenVMS customers ;-)

As we all know, there is no version of OpenVMS Alpha V8.2-1 nor will there ever be one.

Volker.

Re: Field Test version of SSL T1.4 is now available in the web!

Jon,
->
Is the T1.4 field test compatible with 7.3-2 / TCPIP 5.4 or not?
->
No. We have not qualified with 7.3-2.
Hoff
Honored Contributor

Re: Field Test version of SSL T1.4 is now available in the web!

FWIW, here are the release announcements and the published CHANGES.TXT for OpenSSL directly from the OpenSSL folks:

http://www.openssl.org/news/announce.html
Steven Schweda
Honored Contributor

Re: Field Test version of SSL T1.4 is now available in the web!

> http://h71000.www7.hp.com/openvms/products/ssl/ssl.html

[...] based on OpenSSL 0.9.8h and
includes the following latest security
updates, known to date [...]

Known to _which_ date? The latest OpenSSL
kit (as of today) is version 0.9.8k, not
0.9.8h. How latest is your "latest"?

Unqualified, "latest" is seldom a useful
description.
Ian Miller.
Honored Contributor

Re: Field Test version of SSL T1.4 is now available in the web!

I note in http://h71000.www7.hp.com/openvms/products/ssl/ssl_iguide.txt

there are some updates backported from 0.9.9
____________________
Purely Personal Opinion

Re: Field Test version of SSL T1.4 is now available in the web!

After 0.9.8h release, OpenSSL has released till now the following two security advisories.


07-Jan-2009:
Security Advisory: incorrect checks for malformed signatures


25-Mar-2009:
Security Advisory: Three moderate severity security issues


We have ported these two advisories (thatâ s why we have put â it includes the following latest security updates, known to dateâ in the website)

Vulnerabilities CVE/CAN:

CVE-2008-5077
CVE-2009-0590
CVE-2009-0591
CVE-2009-0789