LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 11-20-2013, 05:40 AM   #1
andypooz
LQ Newbie
 
Registered: Nov 2013
Posts: 2

Rep: Reputation: Disabled
Open SSH backported version out of date for PCI


I have a shop that requires PCI compliance and we're currently being flagged as having an outdated patch for openSSH. It is a self-managed VPN and I'm stuck between securitymetrics telling me the backported version is outdated and my host telling me that if it was, it would update automatically.

I have openssh-server-5.3p1-81.el6_3.x86_64 and securitymetrics want to see openssh-server-5.3p1-84.1.el6.x86_64. Notices on redhat seem to confirm that the version I have is out of date ( https://rhn.redhat.com/errata/RHBA-2012-1443.html ) but it has not been updated automatically.

I am not a server guy, and the idea of compiling my own ssh version scares the hell out of me (and I wouldn't know where to start). If this backporting thing is supposed to be automated, I shouldn't have to should I?

Could someone please explain why this hasn't happened? Is there some way I can force this update? When I try to update through yum I get a dependency issue which stops the update (ie. the current version is blocking the older version). I am trying to do this through SSH, so uninstalling the current version isn't an option even if I had the nerve.

My host has very quickly distanced themselves from me since I showed them things weren't up-to-date and are saying no one else is reporting this issue. How can this be? Surely there are lots of users needing pci compliance.

Anyway, if any of you have hunches or things to try, I'd really appreciate it.

Regards
Andy
 
Old 11-20-2013, 06:44 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,474

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Hi Andy,

Contact RedHat support and ask their advice, what version of RedHat are you using?

Quote:
Originally Posted by andypooz View Post
Surely there are lots of users needing pci compliance.
I'm surprised that your PCI Auditor is happy for you to be using a "third party" VPS to hold cardholder data. How do they propose doing the datacenter level vulnerability scan on the physical hardware?
 
Old 11-20-2013, 06:46 AM   #3
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,474

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Oh, and good luck with PCI certification, took us about 18 months to complete it end-to-end.
 
Old 11-20-2013, 06:58 AM   #4
andypooz
LQ Newbie
 
Registered: Nov 2013
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thanks

We don't store creditcard numbers, but they are entered on the site and transmitted to the payment provider via ssl. This PCI compliance seems to be a full time job in itself- ridiculous! Thanks for the advice
 
Old 11-20-2013, 07:07 AM   #5
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,474

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Quote:
Originally Posted by andypooz View Post
We don't store creditcard numbers, but they are entered on the site and transmitted to the payment provider via ssl.
Check to see if the site can be modified so that the entry of cardholder data is done on a secure "shopping cart" of your payment provider rather than on "your" site. That way you're sending a shopping cart / transaction ID backwards and forwards rather than CHD.

Quote:
Originally Posted by andypooz View Post
This PCI compliance seems to be a full time job in itself- ridiculous!
It pretty much is depending on what level of PCI you seek. There is a "self-certified" level that many people consider enough, and there's the full on certification that could take you months to achieve.

Quote:
Originally Posted by andypooz View Post
Thanks for the advice
You're welcome.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: CyanogenMod 7.2 gets backported Android 4.0 features LXer Syndicated Linux News 0 06-21-2012 06:30 PM
Open SSH windows version Red Squirrel Linux - Software 5 06-01-2009 04:02 PM
What would we do if Kmuto backported Cds did not exist? Luckily he's still there frenchn00b Debian 0 11-07-2008 11:34 AM
Passwordless SSH with SSH commercial server and open ssh cereal83 Linux - General 7 04-18-2006 12:34 PM
which version of debian is stable but up to date? r3dhatter Debian 3 03-15-2004 07:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 04:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration