Re: [lfs-support] OpenSSL Heartbleed-bug

2014-04-15 Thread Aleksandar Kuktin
CORRECTION!! >On Tue, 15 Apr 2014 20:06:03 +0200 >Aleksandar Kuktin wrote: > > >On Tue, 15 Apr 2014 19:06:14 +0200 > >loki wrote: > > 3.) Do I have to recreate the keys used for the users of OpenVPN? > > (After I update OpenSSL) > > If they were not loaded into the servers address space (and t

Re: [lfs-support] OpenSSL Heartbleed-bug

2014-04-15 Thread Aleksandar Kuktin
>On Tue, 15 Apr 2014 19:06:14 +0200 >loki wrote: > 1.) Is it enough for me to recompile only OpenSSL or do I have to > recompile OpenSSH, apache, OpenVPN? I have not yet looked at the patch that fixes CVE-2014-0160, but I imagine that you do not need to recompile anything that dynamically linkes

Re: [lfs-support] OpenSSL Heartbleed-bug

2014-04-15 Thread Fernando de Oliveira
Em 15-04-2014 14:06, loki escreveu: > Hey all, > > unfortunatly you can't find much heartbleed bug info on the net for > administrators. So I will try my luck here. > > I have some https websites and a openvpn server. My questions are: > > 1.) Is it enough for me to recompile only OpenSSL or do

[lfs-support] OpenSSL Heartbleed-bug

2014-04-15 Thread loki
Hey all, unfortunatly you can't find much heartbleed bug info on the net for administrators. So I will try my luck here. I have some https websites and a openvpn server. My questions are: 1.) Is it enough for me to recompile only OpenSSL or do I have to recompile OpenSSH, apache, OpenVPN? 2.) Do