Thursday, May 1, 2014

Admins: why not review config standards as you fix Heartbleed?

[f-secure.com] As you have to update your SSL anyway, why not make sure your configuration is up to modern standards? There has been plenty of noise about Heartbleed , so if you're an admin, you already know what to do. 1. Find everything you have using vulnerable versions of OpenSSL 2. Update to the latest OpenSSL version 3. Create new private keys and SSL certificates as the old ones may have leaked 4. Revoke old certificates But since you have to touch your server configuration and cre…