implementing SNI




Hello out there,

Implementing the SNI extension, to permit encrypted virtual web domain service, seems to be spreading.

I hope I'm not too far OT in asking this list for advice on making this transition on FreeBSD.

The first server to be migrated is currently running:

7.1-RELEASE-p13 with the base openssl 0.9.8.e and apache 2.2.13

Several options seem to be available:

1) upgrade the openssl in the existing 7.1 release
2) migrate to gnuTLS in the existing 7.1 release
3) upgrade freebsd to 8.1 with openssl 0.9.8n

I'm pre-inclined towards upgrading the OS to 8.1. The primary concerns I've considered revolve around moving the installed ports through this upgrade with minimal downtime.

Could anyone please offer advice on the openssl upgrade issues involved in such a migration?

In addition to apache, this server is a pretty loaded toaster, also hosting DNS with bind9, virtual mail domains with postfix, courier-imap/authlib, and mysql, and shell accounts via openssh.

A simpler question that I've been unable to resolve: Does the openssl of 8.1-RELEASE enable the TLS extensions, including SNI, by default? If I have to rebuild from source to enable this feature anyway, it takes some of the incentive out of migrating the OS now.

Thanks for any insight or experience you're able to share!

johnea

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Getting rid of the Apache SLAPPER
    ... I couldn't get an RPM upgrade to ... I have a version of Apache 2.0 on ... > anyway and openssl version still tells me that the OpenSSL9.6b engine is ...
    (comp.os.linux.security)
  • Re: Apache, mod_ssl and openssl?
    ... Bryan wrote: ... time to upgrade!!! ... > about the apache stuff... ... > the openssl source because the mod_ssl module needs it. ...
    (comp.os.linux.security)
  • Re: Apache, mod_ssl and openssl?
    ... time to upgrade!!! ... ]about the apache stuff... ... ]the openssl source because the mod_ssl module needs it. ... Get the Redhat openssl patches As far as I ...
    (comp.os.linux.security)
  • Re: Apache, mod_ssl and openssl?
    ... >about the apache stuff... ... >the openssl source because the mod_ssl module needs it. ... upgrade to that version instead. ... As noted in the OpenSSL advisory, separate patches ...
    (comp.os.linux.security)
  • Re: HP-OpenSSL 1.4-471
    ... The OpenSSL APIs saw some incompatible changes from the upstream sources at V1.4 and are not upward-compatible. ... Which means the 1.4 upgrade can be a mildly disruptive upgrade, as you have to upgrade Apache and some other pieces that have dependencies on OpenSSL.) ... When the OpenSSL 1.0 APIs are ported and released, that'll likely entail another incompatible API change and related shuffle, AFAIK. ...
    (comp.os.vms)