Go Back  HTML Forums - Free Webmaster Forums and Help Forums > TOOLS OF THE TRADE > Security Alert
User Name:
Password:
 

Reply
Thread Tools   Display Modes
  View First Unread
 
Old 12-08-2007, 06:26 PM
  #1
scoutt
Mister Admin to you
 
scoutt's Avatar
 
Join Date: Jul 2001
Posts: 30,868
iTrader: (0)
scoutt is a jewel in the roughscoutt is a jewel in the roughscoutt is a jewel in the roughscoutt is a jewel in the rough
OpenSSL Patch Presents Dilemma for Federal Users

(November 29, 2007)
A flaw in the pseudo random number generator (PRNG) OpenSSL
cryptographic module means that "generated random data is far more
predictable than it should be." The Open Source Software Institute has
released both a patch and a workaround for the flaw. Federal users are
faced with a dilemma regarding the fix. Federal agencies are required
to use FIPS-certified cryptographic products. The patch has not been
certified, so the agencies must choose between running unpatched
versions of the software or applying the patch and falling out of
compliance. A new version of OpenSSL that does not have the flaw is
currently undergoing FIPS testing.
http://www.gcn.com/online/vol1_no1/4...ty&CMP=OTC-RSS
[Editor's Note (Schultz): This kind of dilemma occurs too often in the
compliance arena. Compliance is by its very nature a more slow and
gradual process. Urgency and patching, on the other hand, go
hand-in-hand.
(Northcutt): I will not even ask how a non-random version passed the
Government's crypto testing in the first place. This does need to be
fixed. Please keep in mind that you may be running OpenSSL and not know
it. If I remember right there was a nasty bug a while back and a LOT of
commercial products were found to be using OpenSSL. I wrote a paper a
while back on TLS and getting FIPS approval. As this story unfolds, I
will update it. The paper is located and under that is the OpenSSL
advisory:
http://www.sans.edu/resources/securitylab/296.php
http://openssl.org/news/secadv_20071129.txt ]
__________________
Have a Script or Snippet you want to share?

WWW Standards: HTML 4.01, CSS2.1, CSS3, XHTML 1.0
PHP Standards: PHP Standards
scoutt is offline   Add to del.icio.us Add to del.icio.us    Can you digg it?Can you digg it? Reply With Quote

Reply
KEEP TABS
SPONSORS
 
Boxedart



 
 


 
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
  
 
 
 



 
  POSTING RULES
 
 
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Thread Tools
Display Modes

Forum Jump

 

All times are GMT -5. The time now is 05:11 AM.

   

Mascot team created by Drawshop.com

Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.

Server Monitoring by ENIACmonitor 0.01
HTMLforums.com © Big Resources, Inc. Web Design by BoxedArt.com
vRewrite 1.5 beta SEOed URLs completed by Tech Help Forum and Chalo Na.