Re: SSL Vulnerability

"Peter Janett" <[email protected]> Tue, 11 Mar 2003 12:24:48 -0700
Newsgroups gmane.linux.redhat.stronghold
Organization New Media One Web Services, LLC
Message-ID <004101c2e803$e2498490$55285742@peterlaptop>
I purchased a license for Stronghold 3, and understand that since Red Hat
has purchased Stronghold, Stronghold 4 will be Open Source.

I have spent a good deal of time trying to download Stronghold 4, but it
seems impossible to find a link to download it on the Stronghold web site.

Please let me know how I can download Stronghold 4, since support for
version 3 will be dropped in June.

Thanks,

Peter Janett

New Media One Web Services
http://www.newmediaone.net
webmaster "at" newmediaone.net
(303)828-9882


----- Original Message -----
From: "Min Min Tsan" <[email protected]>
To: <[email protected]>; "Jeromey Hannel"
<[email protected]>
Sent: Tuesday, March 11, 2003 9:02 AM
Subject: Re: SSL Vulnerability


> On Mon, Mar 10, 2003 at 10:24:28AM -0600, Jeromey Hannel wrote:
> > Redhat just released an updated OpenSSL packages fix timing attack
> > (Security Advisory - RHSA-2003:062-11).  After looking into this, I
> > noticed that openssl.org had also released a patch resolving this
> > issue.
> >
> > I currently run Stronghold 3.0 Build 3020.  Will there be an upgrade
> > or a patch to resolve this issue.
>
> New packages for Stronghold 4 for other platforms have been recently
> released on 28 February 2003 to fix this issue. Please refer to the
> errata at:
>
> http://rhn.redhat.com/errata/RHSA-2003-082.html
>
> However, our engineers are currently still working on new packages for
> Stronghold 3.0 to fix the above issue and we'll be releasing a security
> advisory about this earliest by end of this week. Please note that Red
> Hat will continue to provide technical support and any critical security
> software updates for Stronghold 3 until June 30, 2003 only.
>
> Kind regards,
> Min Min
> --
> Red Hat Stronghold Support
> http://stronghold.redhat.com/
> http://www.redhat.com/software/apache/stronghold/
>
>
>
> _______________________________________________
> Stronghold-users mailing list
> [email protected]
> https://listman.redhat.com/mailman/listinfo/stronghold-users
>
>