OpenSSL heartbleed vulnerability with Nagios XI
Posted: Wed Apr 16, 2014 10:37 am
Hello Members,
We have created 5 VM's with CentOS release 6.4 (Final) for Nagios XI with the same image.
We have used only one server for our POC which is currently having OpenSSL 1.0.1e-fips 11 Feb 2013 which has the heartbleed vulnerability.
Rest of the VM's are having OpenSSL 1.0.0-fips 29 Mar 2010 as we have not installed anything on it.
Our Unix Admins have raised a concern that Nagios Full-install script is upgrading the OpenSSL version from OpenSSL 1.0.0-fips 29 Mar 2010 to OpenSSL 1.0.1e-fips 11 Feb 2013.
We are using Nagios XI version Nagios XI 2012R2.8c.
Please confirm of the script is doing the same and if yes how to solve the issue.
Please also suggest if the script is upgrading OpenSSL,do we have another version which will not do the same.
We have created 5 VM's with CentOS release 6.4 (Final) for Nagios XI with the same image.
We have used only one server for our POC which is currently having OpenSSL 1.0.1e-fips 11 Feb 2013 which has the heartbleed vulnerability.
Rest of the VM's are having OpenSSL 1.0.0-fips 29 Mar 2010 as we have not installed anything on it.
Our Unix Admins have raised a concern that Nagios Full-install script is upgrading the OpenSSL version from OpenSSL 1.0.0-fips 29 Mar 2010 to OpenSSL 1.0.1e-fips 11 Feb 2013.
We are using Nagios XI version Nagios XI 2012R2.8c.
Please confirm of the script is doing the same and if yes how to solve the issue.
Please also suggest if the script is upgrading OpenSSL,do we have another version which will not do the same.