<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><br><div><div>On 9 Apr 2014, at 21:34, Aaron Scruggs <<a href="mailto:ascruggs@academicworks.com">ascruggs@academicworks.com</a>> wrote:</div><div><br></div><blockquote type="cite"><div dir="ltr"><div>Do I need to recompile shibd against a new version of openssl or is simply upgrading openssl on the server good enough?</div></div></blockquote><div><br></div><div>Unfortunately, the answer to that will depend on how you put your existing deployment together. For the systems we support directly it's normal for the OpenSSL dependency to be dynamically linked, which means that most people don't need to recompile. However, it sounds like you've compiled Shibboleth yourself and in cases like that it's going to depend on how you did that, and perhaps why (by which I mean: which OS are you on which required you to compile it yourself, which web server are you using, did you build that yourself as well, and so on).</div><div><br></div><blockquote type="cite"><div dir="ltr"><div>Do I need to rekey any certs? Some that come to mind are my Signature cert and my CredentialResolver key & cert.</div></div></blockquote><div><br></div><div>There's a possibility that any or all of those, as well as the browser-facing TLS certificate, are compromised. Without more details, I think we'd have to recommend that you play safe and rekey everything. Don't forget to revoke any CA-issued certificates, too. Many browsers actually do check that stuff these days, despite the FUD one sometimes hears, and it's therefore worth the extra minor effort involved even if it isn't guaranteed to benefit every user.</div></div><div>
<span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div><span class="Apple-tab-span" style="white-space: pre; "><br class="Apple-interchange-newline">        </span>-- Ian<br></div><div><span class="Apple-style-span" style="font-size: medium; "><br></span></div></span></span><br class="Apple-interchange-newline">
</div>
<br></body></html>