Unsolved
This post is more than 5 years old
2 Intern
•
214 Posts
0
3109
April 8th, 2014 15:00
OpenSSL Heart bleed
Hi there,
Does the OpenSSL vulnerability 'heart bleed' affect the Clariion range in anyway?
Thanks,
Ed
No Events found!
Unsolved
This post is more than 5 years old
2 Intern
•
214 Posts
0
3109
April 8th, 2014 15:00
Hi there,
Does the OpenSSL vulnerability 'heart bleed' affect the Clariion range in anyway?
Thanks,
Ed
Top
peglarr
99 Posts
0
April 8th, 2014 17:00
Ed - cannot speak for Clariion, but we have confirmed that Isilon nodes are not, repeat not affected. I hope someone else can confirm for Clariion/VNX.
edhoward
2 Intern
•
214 Posts
0
April 8th, 2014 22:00
Thanks for the reply, I take it that this only really affects possible access to the management interface?
Also how so you know that Isilon isn't affected?
peglarr
99 Posts
0
April 9th, 2014 06:00
Hi Ed,
We know because the version of OpenSSL in OneFS is not one of the versions with the bug. BTW this does not only affect the management interface but many of the protocol stacks, since we support Kerberos authentication over several protocols and OpenSSL may call routines in the Kerberos library. The TLS routines in OpenSSL are the key to this issue, pun intended
mjzraz
1 Rookie
•
93 Posts
0
April 9th, 2014 13:00
is there a way to know if openssl is used or check the version on the VNX systems?
M_Salem
213 Posts
0
April 10th, 2014 01:00
We have now a knowledgebase article addressed for VNX systems KB185969. It is not yet a customer viewable. It is still limited to EMC Employees and partners.
The resolution up to this point is:
We ave 2 tickets opened with Engineering for further investigation of the issue. We are doing the same for all other EMC products.
Hope it helps
Mohammed Salem @yankoora