<div dir="ltr"><div>As a service provider who was using a version of openssl that had the heartbleed bug, what actions should I take to ensure that my shibd daemon is not vulnerable? <br></div><div><br></div><div>Any general advice is greatly appreciated. Additionally, I have a few specific questions:</div>
<div><br></div><div>Do I need to recompile shibd against a new version of openssl or is simply upgrading openssl on the server good enough?</div><div><br></div><div>Do I need to rekey any certs? Some that come to mind are my Signature cert and my CredentialResolver key & cert.</div>
<div><br></div><div>Thanks!</div><div>Aaron Scruggs</div>
</div>