openSSL 3.0.7 - any timelines yet?

Started by chemlud, November 01, 2022, 11:15:58 AM

Previous topic - Next topic
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

It's my understanding that OPNSense uses OPENSSL 1.1.1 so it's not affected.

November 01, 2022, 01:08:15 PM #2 Last Edit: November 01, 2022, 01:28:44 PM by seed
root@OPNsense:~ # openssl version
OpenSSL 1.1.1o-freebsd  3 May 2022


Edit:

Versions       OPNsense 22.7.6-amd64
                   FreeBSD 13.1-RELEASE-p2
                   OpenSSL 1.1.1q 5 Jul 2022
i want all services to run with wirespeed and therefore run this dedicated hardware configuration:

AMD Ryzen 7 9700x
ASUS Pro B650M-CT-CSM
64GB DDR5 ECC (2x KSM56E46BD8KM-32HA)
Intel XL710-BM1
Intel i350-T4
2x SSD with ZFS mirror
PiKVM for remote maintenance

private user, no business use

root@OPNsense:~ # /usr/local/bin/openssl version
OpenSSL 1.1.1q  5 Jul 2022
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

So it's consensus that only 3.x is vulnerable? Any source for that conclusion yet?
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

Erm...yes....the very hyperlink you posted above?

@chemlud - the article you linked in your initial post?
QuoteWhat is known is that the incoming vulnerability only affects 3.0.x versions of OpenSSL

What's all the fuss about? OPNsense does not use this particular product, why should Deciso or the OPNsense team publish anything at all?
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

I asked two questions, I don't see any "fuss". Nice to know that sense is not affected...
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

jup indeed.
The only strange thing I found was that opnsense gui states:
OPNsense 22.7.6-amd64
FreeBSD 13.1-RELEASE-p2
OpenSSL 1.1.1q 5 Jul 2022

and the terminal window:
openssl version
OpenSSL 1.1.1o-freebsd

so why is the gui claiming version 1q and terminal gives back 1o?
Deciso DEC850v2

What about LibreSSL?  My OpnSense is currently on LibreSSL 3.3.6.  I see version 3.6.1 was just released but not sure if this vuln applies.

@RamSense
Quoteso why is the gui claiming version 1q and terminal gives back 1o?
widget shows ports version (/usr/local/bin/openssl version)
shell shows base (OS) version (/usr/bin/openssl version)

@Deku
no
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
openssl only.
3.0 branch only

@Fright, ah, thanks for explaining!
Deciso DEC850v2

openssl 1.1.1s has been published.
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

Quote from: Deku on November 01, 2022, 06:48:16 PM
What about LibreSSL?  My OpnSense is currently on LibreSSL 3.3.6.  I see version 3.6.1 was just released but not sure if this vuln applies.
https://marc.info/?t=166716388700001&r=1&w=2

Is LibreSSL still functional with 22.7.x? It was my understanding that support of LibreSSL would be deleted with 22.7 (but for the last months I didn't have the ttime to follow up) so I switched to openSSL before updating to 22.7...

kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....