I was browsing and stumbled across this fix for the nrpe weak sss/ciphers issue.
https://github.com/NagiosEnterprises/nr ... e-2-16-RC2
Can anyone from Nagios verify this?
Thanks
Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
5 x Nagios 5.6.9 Enterprise Edition
RHEL 6 & 7
rrdcached & ramdisk optimisation
RHEL 6 & 7
rrdcached & ramdisk optimisation
Re: Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
Insofar as that is our official GitHub account, yes I can verify that we wrote that fix. However as it is still a release candidate and not an official release, we have not yet officially tested the code. I tend to believe it's been fixed as I trust John's work, but I can't set for sure at the moment. It will be tested eventually, but it will need to make it through the paces first.
Former Nagios employee
Re: Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
Hope Nagios can fast track the unit test and verify all the vulnerabilities(medium strength and weak ciphers support) has been addressed so that we can do regression testing.tmcdonald wrote:Insofar as that is our official GitHub account, yes I can verify that we wrote that fix. However as it is still a release candidate and not an official release, we have not yet officially tested the code. I tend to believe it's been fixed as I trust John's work, but I can't set for sure at the moment. It will be tested eventually, but it will need to make it through the paces first.
This is a major audit issue in enterprise environments.
Thanks
5 x Nagios 5.6.9 Enterprise Edition
RHEL 6 & 7
rrdcached & ramdisk optimisation
RHEL 6 & 7
rrdcached & ramdisk optimisation
Re: Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
Being that we're heading into the holiday season, our weeks are going to be somewhat short for a while so I can't guarantee it will be done before 2016. We're also working on getting some testing done on our commercial products as we prepare for new releases, so that is taking some time. It will be done, but I can't promise a fast-track.
Former Nagios employee
Re: Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
I understand, asap will be fine. This is one of the major points against nagios from your competitors.tmcdonald wrote:Being that we're heading into the holiday season, our weeks are going to be somewhat short for a while so I can't guarantee it will be done before 2016. We're also working on getting some testing done on our commercial products as we prepare for new releases, so that is taking some time. It will be done, but I can't promise a fast-track.
So it is in your best interest also.
Thanks
5 x Nagios 5.6.9 Enterprise Edition
RHEL 6 & 7
rrdcached & ramdisk optimisation
RHEL 6 & 7
rrdcached & ramdisk optimisation
Re: Nagios nrpe & check_nrpe fix available nrpe-2-16-RC2?
I'll leave this open for now. I know we have a lot of people waiting for the new NRPE release, and I'm glad it's being updated with some features that have been requested for awhile. Thanks for your feedback!
Former Nagios Employee.
me.
me.