We're trying to achieve PCI DSS accreditation, and we're currently failing on our OpenSSL version - 0.9.7a. Apparently, we need at least 0.9.7b (wouldn't you know it!).
I've read through every thread on this forum about updating OpenSSL, and there doesn't appear to be a consistent method. We're using CentOS, by the way.
I've also read horror stories about people getting locked out of the server because SSH doesn't work anymore.
Bottom line - it's a server with over 100 clients on it, how can we update OpenSSL without compromising our clients?
And what absolutely *has* to be updated after OpenSSL?
Many, many thanks to anyone who can help with this. We're running Apache, PHP, all the usual apps.
I've read through every thread on this forum about updating OpenSSL, and there doesn't appear to be a consistent method. We're using CentOS, by the way.
I've also read horror stories about people getting locked out of the server because SSH doesn't work anymore.
Bottom line - it's a server with over 100 clients on it, how can we update OpenSSL without compromising our clients?
And what absolutely *has* to be updated after OpenSSL?
Many, many thanks to anyone who can help with this. We're running Apache, PHP, all the usual apps.