Hi

i know that this is more or less off-topic but i doubt there
are better sources to ask then the httpd-developers

after update openssl and re-new all certificates one question
remains: in case of httpd-prefork would a attacker only have
been able to compromise the private key and data of his
worker-process or as well access the memory of other workers?

in that case also all passwords of any website should be
treated as compromised which is the big question now

the dovecot-developer says if dovecot is running in high-security
mode with single processes the setup has been safe except the
private key, but in case of dovceot there is also a chroot
involved for the login-workers

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to