Upgrading OpenSSL in NetBackup
Hello,
I'm having a security issue with NetBackup. Basically I need to upgrade the installed version of OpenSSL that came with NetBackup. If the OpenSSL is not effected by the current and past vulnerabilities then I need to see document from Symantec.
Theses are the files I need to upgrade
/usr/openv/pdde/pdopensource/bin/.bin/openssl
/usr/openv/pdde/pdopensource/bin/openssl
OpenSSL 0.9.8y
This is the version I need to be up to date.
- OpenSSL 0.9.8za
- OpenSSL 1.0.0m
- OpenSSL 1.0.1h
I have had this issue before. Below is a link to by earlier post asking this question.
http://www.symantec.com/connect/forums/openssl-use-netbackup-7102
I have had this same issue with Java before. This the Symantec fix http://www.symantec.com/business/support/index?page=content&id=TECH148257
This fix is to use the OpenSSL that the OS is using.
Is there a way to do this for SSL?
I have opened a ticket with support and they don't know anything. They are not able to help me.
Can someone help me secure my sever.
Hi,
Your previous post is 2 years old. In the last few month there was the Heartbleed vulnerabiity. Since then Symantec have release 7.6.0.2 to address it.
http://www.symantec.com/docs/TECH216555
https://www-secure.symantec.com/connect/forums/netbackup-7602-netbackup-76-maintenance-release-2-now-available
Upgrade your systems.