Openssl vulnerability installation upgrade to process
OpenSSL's protocol has just exposed a "devastating" security vulnerability, or the encryption keys (cryptographic keys) and private communications (private communications) of some heavyweight services. If your server is using OpenSSL 1.0.1f, be sure to upgrade to OpenSSL 1.0.1g immediately. In addition, versions prior to 1.0.1 are not affected by this, but 1.0.2-beta still needs to be fixed.
You can detect the existence of this vulnerability on your website at the following address, as follows:
Http://possible.lv/tools/hb/
First, check the version of openssl on the service:
Openssl version-a
1. Download the latest OpenSSL https://www.openssl.org/source/ from the following pages
Https://www.openssl.org/source/openssl-1.0.1g.tar.gz
2. Openssl-1.0.1g.tar.gz decompression command:
Tar-zxvf openssl-1.0.1g.tar.gz
3. The default installation directory is / usr/local/ssl
You can use-- prefix=/*** to change the installation directory during configuration
. / configmake & & make install
Finally, you can see the installed files in / usr/local/ssl.
If OpenSSL is already installed on your computer, you need to upgrade it.
The upgrade process is:
1. Follow the installation procedure to make install
2. Execute the following command:
Mv / usr/bin/openssl / usr/bin/openssl.OFFmv / usr/include/openssl / usr/include/openssl.OFFln-s / usr/local/ssl/bin/openssl / usr/bin/opensslln-s / usr/local/ssl/include/openssl / usr/include/openssl
3 configure library file search path
Echo "/ usr/local/ssl/lib" > > / etc/ld.so.confldconfig-v
4 check the openssl version number to verify the correctness of the installation
Openssl version-a