Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
openssl upgrade question
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
d-bugger
n00b
n00b


Joined: 21 Oct 2002
Posts: 6
Location: Belgium

PostPosted: Thu Feb 20, 2003 9:37 pm    Post subject: openssl upgrade question Reply with quote

I have a question on upgrading openssl:
Should I remerge all ebuilds who depend on it?

I'm a bit refering to the GLSA for openssl anounced today ...

Maybe this depends on what bugs were fixed?
Back to top
View user's profile Send private message
cram
Guru
Guru


Joined: 17 Nov 2002
Posts: 312
Location: Saskatoon, Canada

PostPosted: Thu Feb 20, 2003 10:22 pm    Post subject: Reply with quote

Quote:
Should I remerge all ebuilds who depend on it?

No, shouldn't be necessary.
_________________
aaarggghhhh.
Good point Chewie.
Back to top
View user's profile Send private message
Zu`
l33t
l33t


Joined: 26 May 2002
Posts: 716
Location: BE

PostPosted: Fri Feb 21, 2003 2:47 am    Post subject: Reply with quote

I've been wondering about this aswell, many times.

Can someone confirm it's really not needed ?

I think, if you want to be 100% sure, you could rebuild these packages:

Code:

emerge -pev world | grep +ssl


Although that's not 100% to be trusted actually, there might be more packages that use ssl but don't have a USE flag for it (in other words, they need it, as a hard dependency).
_________________
No growth without resistance.
No action without reaction.
No desire without restraint.
Back to top
View user's profile Send private message
psp
Tux's lil' helper
Tux's lil' helper


Joined: 06 Aug 2002
Posts: 120
Location: Cape Town, South Africa

PostPosted: Fri Feb 21, 2003 1:41 pm    Post subject: Reply with quote

This shouldn't be a problem _UNLESS_ the binaries statically compile ssl into themselves...
Back to top
View user's profile Send private message
taveren
Tux's lil' helper
Tux's lil' helper


Joined: 24 Jul 2002
Posts: 145
Location: London, Ontario

PostPosted: Fri Feb 21, 2003 2:14 pm    Post subject: Reply with quote

I just upgraded to 0.9.7a, it contains a very large warning that you must re-emerge everything that compiles against it. Now, this is most likely because I came up from 0.9.6h, but I can confirm that wget (which is compiled against 0.9.6h), doesn't work.

If you upgrade, only go up to 0.9.6i if your running something lower than that.
Back to top
View user's profile Send private message
taveren
Tux's lil' helper
Tux's lil' helper


Joined: 24 Jul 2002
Posts: 145
Location: London, Ontario

PostPosted: Fri Feb 21, 2003 2:39 pm    Post subject: Reply with quote

I can also confirm that downgrading back to the previously installed version (in my case, 0.9.6h) will make everything work again, assuming you still have the tar file sitting in /usr/portage/distfiles. If you don't, or try to install a different version, wget will fail, since it was compiled against a different version of OpenSSL.

I downgraded backed to 0.9.6h, and then back up to 0.9.6i and everything still works without re-emergeing anything else. Hope this helps someone.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum