Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 22 Apr 2010 22:59:15 -0400
From:      "Philip M. Gollucci" <pgollucci@p6m7g8.com>
To:        =?UTF-8?B?RWlyaWsgw5h2ZXJieQ==?= <ltning@anduin.net>
Cc:        Tim Gustafson <tjg@soe.ucsc.edu>, =?UTF-8?B?dg==?= <des@des.no>, =?UTF-8?B?RGFnLUVybGluZyBTbcO4cmdyYQ==?=, freebsd-security@freebsd.org
Subject:   Re: OpenSSL 0.9.8k -> 0.9.8l
Message-ID:  <4BD10D03.7010201@p6m7g8.com>
In-Reply-To: <D86F370E-98A5-41B1-97D5-F2CD98CE1716@anduin.net>
References:  <258059512.789871271827382221.JavaMail.root@mail-01.cse.ucsc.edu> <D86F370E-98A5-41B1-97D5-F2CD98CE1716@anduin.net>

next in thread | previous in thread | raw e-mail | index | archive | help
--------------000806040504050001000200
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit

On 4/21/2010 1:55 AM, Eirik Øverby wrote:
> It is a misconseption to think that one _has to_ run the latest version (as suggested by dumb network scans) in order to remain compliant (PCI DSS or otherwise). What is needed is that the issues found are either patched or documented to be not applicable.
I completely agree; however, having just achieved PCI certification for
$work in *this* month -- 2 different (unamed pci auditing firms) refused
to accept openssl had been patched without version number changes.

Kind of odd considering they said my httpd 2.2.14 was vunlerable to the
windows mod_issapi cve on fbsd but accepted on face value that we can't
possibly be since its not windows and not loaded.  Yet the version #
didn't change here.

Additionally odd, they did accept that 2.2.14 disabled ssl functionality
to prevent the issue though not fix it.  Yet again the version # didn't
change.

Interestingly we have some other equipment that requires the client
renegotiation but b/c we are leasing it rather then own it, its out of
scope.

IMHO, its simply easier to always mod the version string in some way
rather then trying to argue with them.



-- 
------------------------------------------------------------------------
1024D/DB9B8C1C B90B FBC3 A3A1 C71A 8E70  3F8C 75B8 8FFB DB9B 8C1C
Philip M. Gollucci (pgollucci@p6m7g8.com) c: 703.336.9354
VP Apache Infrastructure; Member, Apache Software Foundation
Committer,                        FreeBSD Foundation
Consultant,                       P6M7G8 Inc.
Sr. System Admin,                 Ridecharge Inc.

Work like you don't need the money,
love like you'll never get hurt,
and dance like nobody's watching.

--------------000806040504050001000200--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4BD10D03.7010201>