Forum Discussion
Today's OpenSSL vulnerabilities - what are best channels for updates?
OpenSSL have given heads-up on release of high severity issue between 11am and 3pm today.
Have F5 been given advanced notice on these issues? e.g. Do they expect to issue a fix immediately the issues are made public?
What are the best channels for getting any information updates from F5 on this issue?
I'm already on the security announce email list, and following on twitter.
Appreciate F5 are in a tricky position because they can't simply roll vendor OpenSSL packages to clients, and in many cases there is more engineering to do to even establish when it is a problem.
On the other-hand we are all be getting quite good at this urgent patching malarky :(
1 Reply
- amolari
Cirrostratus
Devcentral is the faster channel so far (past experience showed). Then, F5 publishes a SOL (sec advisory). Many times, a workaround is proposed (configuration of SSL profiles usually).
F5 might change the way one can update its product in the future: allowing some base (OS) components to be individually updated, without the need of a SW hotfix.
Updating OpenSSL might have some bad side-effects: I have seen that CRL imports (performed by OpenSSL on the BIGIP) is more resources intensive with the newer OpenSSL versions (such as in v11.6) than in previous ones.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com