LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-05-2015, 11:14 AM   #1
trackstar2000
Member
 
Registered: Apr 2013
Posts: 82

Rep: Reputation: Disabled
OpenSSL


Hello,

I installed OpenSSL in which it corrected a few errors when testing the software. A quick background on the application. OpenSSL is an optional install. At the command line the application has the ability to open a browser up to allow user to use the browser instead of command line. The application can serve user logins.

Sage:
http://www.sagemath.org/doc/installa...er-environment
./sage -i openssl

./sage -f python

make ssl

Anyways, my question is with OpenSSL installed even without the intention to use it, is the machine vulnerable to any future issues or do I have to actually configure and enable it?


[root@math1 sage-6.4.1]# openssl version -a
OpenSSL 1.0.1e-fips 11 Feb 2013
built on: Tue Jan 20 17:30:05 UTC 2015
platform: linux-x86_64

Centos 6.4

Thanks, TT
 
Old 02-05-2015, 10:15 PM   #2
veerain
Senior Member
 
Registered: Mar 2005
Location: Earth bound to Helios
Distribution: Custom
Posts: 2,524

Rep: Reputation: 319Reputation: 319Reputation: 319Reputation: 319
Openssl is a crypto library. It is used in many security apllications.

It is usually used by applications which provide secure communication like internet, web, email.

It is used by web browsers, email, git, subversion, video chat clients, webservers, email servers and many.
 
Old 02-06-2015, 07:46 AM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
As with all crypto resources, you do need to take the time to learn about OpenSSL and how to properly configure and use it. It's present on nearly all machines. No, its presence does not per se represent a vulnerability.

Contrast this, for example, with the SSH daemon, sshd, which might be running on a machine that you never actually intend to secure-login to from the outside. If you never intend to do that, that daemon should never be running, and if it is running, it must be properly configured and secured. SSL is a library, not a daemon.

Last edited by sundialsvcs; 02-06-2015 at 07:48 AM.
 
Old 02-06-2015, 11:19 AM   #4
trackstar2000
Member
 
Registered: Apr 2013
Posts: 82

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by sundialsvcs View Post
As with all crypto resources, you do need to take the time to learn about OpenSSL and how to properly configure and use it. It's present on nearly all machines. No, its presence does not per se represent a vulnerability.

Contrast this, for example, with the SSH daemon, sshd, which might be running on a machine that you never actually intend to secure-login to from the outside. If you never intend to do that, that daemon should never be running, and if it is running, it must be properly configured and secured. SSL is a library, not a daemon.
Got it. Thanks for the clarification. I installed it cause the dam test runs kept on failing. Users who are accessing the Linux machine are going through VNC over SSH. The browser option provides GUI interface (can be opened http or https) but the web service itself is not accessible from any other machine
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
openssl: any simple examples no how to use openssl to do some decryption? eantoranz Programming 7 07-26-2012 07:57 PM
install of openssl-0.9.8b-8.3.el5 conflicts with file from package openssl-0.9.8b-8.3 jsaravana87 Linux - Server 1 09-26-2011 01:02 PM
oops openssl-0.9.8e over openssl-0.9.8d bad install now 2 copies? rcorkum Slackware 4 06-29-2007 01:58 AM
OpenSSL paul_mat Linux - Software 1 03-21-2006 06:21 PM
Openssl velan Programming 1 05-16-2005 12:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration