Updated the openssl version, but the old version still appears as being usedhow to upgrade openssl for apache 2.2.29 - still using old 0.9.8 versionHow to get httrack to work with SSL on mac os x? (libssl.so not found)Fixing nginx 1.4.6 dependency on old openssl version (libssl0.9.8)?Heartbleed: how to reliably and portably check the OpenSSL version?Server still vulnerable to HeartBleed after Openssl updateCan I upgrade OpenSSL version used by apache without recompiling the server but just mod_ssl?OpenSSL Header Version != OpenSSL Library Version affecting HTTP/2 for APNSopenssl version keeps the old oneCentos 5.11 OpenSSL TLS 1.2 for PaypalWhy is there openSSL version difference?TLS1.3 not working on nginx 1.15.2 with OpenSSL 1.1.1-pre9

Compaq Portable vs IBM 5155 Portable PC

Is it true that cut time means "play twice as fast as written"?

My players want to grind XP but we're using milestone advancement

Why does Mjolnir fall down in Age of Ultron but not in Endgame?

Why would Ryanair allow me to book this journey through a third party, but not through their own website?

Is it legal to meet with potential future employers in the UK, whilst visiting from the USA

Did 20% of US soldiers in Vietnam use heroin, 95% of whom quit afterwards?

Is Jon Snow the last of his House?

The art of clickbait captions

Apt - strange requests to d16r8ew072anqo.cloudfront.net:80

I know that there is a preselected candidate for a position to be filled at my department. What should I do?

What is a fully qualified name?

Does pair production happen even when the photon is around a neutron?

Can a British citizen living in France vote in both France and Britain in the European Elections?

Should one buy new hardware after a system compromise?

How to let other coworkers know that I don't share my coworker's political views?

Count rotary dial pulses in a phone number (including letters)

NIntegrate doesn't evaluate

Defining the standard model of PA so that a space alien could understand

In the 3D Zeldas, is it faster to roll or to simply walk?

Why isn't 'chemically-strengthened glass' made with potassium carbonate to begin with?

Can I summon an otherworldly creature with the Gate spell without knowing its true name?

Can I tell a prospective employee that everyone in the team is leaving?

Why did Jon Snow do this immoral act if he is so honorable?



Updated the openssl version, but the old version still appears as being used


how to upgrade openssl for apache 2.2.29 - still using old 0.9.8 versionHow to get httrack to work with SSL on mac os x? (libssl.so not found)Fixing nginx 1.4.6 dependency on old openssl version (libssl0.9.8)?Heartbleed: how to reliably and portably check the OpenSSL version?Server still vulnerable to HeartBleed after Openssl updateCan I upgrade OpenSSL version used by apache without recompiling the server but just mod_ssl?OpenSSL Header Version != OpenSSL Library Version affecting HTTP/2 for APNSopenssl version keeps the old oneCentos 5.11 OpenSSL TLS 1.2 for PaypalWhy is there openSSL version difference?TLS1.3 not working on nginx 1.15.2 with OpenSSL 1.1.1-pre9






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I updated to openssl 1.0.2h, but when I hit



lsof | grep -i libssl 


I still get 1.0.1e



nginx 19645 nginx mem REG 182,420273 441256 398853 /usr/lib64/libssl.so.1.0.1e


I tried restarting nginx, apache and mysql, but the old version still remains although openssl version returns



OpenSSL 1.0.2h 3 May 2016


I followed the tutorial from here.



Also, before I posted this, I followed the answer from here.



Do you know how I can make it use the latest version?










share|improve this question



















  • 1





    Did you restart nginx?

    – garethTheRed
    Jul 13 '16 at 15:52











  • Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

    – Punct Ulica
    Jul 13 '16 at 15:52












  • In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

    – EEAA
    Jul 13 '16 at 15:52






  • 3





    Can you answer @EEAA's question about how you installed it?

    – garethTheRed
    Jul 13 '16 at 16:09






  • 1





    Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

    – garethTheRed
    Jul 14 '16 at 9:28

















0















I updated to openssl 1.0.2h, but when I hit



lsof | grep -i libssl 


I still get 1.0.1e



nginx 19645 nginx mem REG 182,420273 441256 398853 /usr/lib64/libssl.so.1.0.1e


I tried restarting nginx, apache and mysql, but the old version still remains although openssl version returns



OpenSSL 1.0.2h 3 May 2016


I followed the tutorial from here.



Also, before I posted this, I followed the answer from here.



Do you know how I can make it use the latest version?










share|improve this question



















  • 1





    Did you restart nginx?

    – garethTheRed
    Jul 13 '16 at 15:52











  • Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

    – Punct Ulica
    Jul 13 '16 at 15:52












  • In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

    – EEAA
    Jul 13 '16 at 15:52






  • 3





    Can you answer @EEAA's question about how you installed it?

    – garethTheRed
    Jul 13 '16 at 16:09






  • 1





    Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

    – garethTheRed
    Jul 14 '16 at 9:28













0












0








0








I updated to openssl 1.0.2h, but when I hit



lsof | grep -i libssl 


I still get 1.0.1e



nginx 19645 nginx mem REG 182,420273 441256 398853 /usr/lib64/libssl.so.1.0.1e


I tried restarting nginx, apache and mysql, but the old version still remains although openssl version returns



OpenSSL 1.0.2h 3 May 2016


I followed the tutorial from here.



Also, before I posted this, I followed the answer from here.



Do you know how I can make it use the latest version?










share|improve this question
















I updated to openssl 1.0.2h, but when I hit



lsof | grep -i libssl 


I still get 1.0.1e



nginx 19645 nginx mem REG 182,420273 441256 398853 /usr/lib64/libssl.so.1.0.1e


I tried restarting nginx, apache and mysql, but the old version still remains although openssl version returns



OpenSSL 1.0.2h 3 May 2016


I followed the tutorial from here.



Also, before I posted this, I followed the answer from here.



Do you know how I can make it use the latest version?







ssh ssl openssl






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Apr 13 '17 at 12:14









Community

1




1










asked Jul 13 '16 at 15:49









Punct UlicaPunct Ulica

11




11







  • 1





    Did you restart nginx?

    – garethTheRed
    Jul 13 '16 at 15:52











  • Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

    – Punct Ulica
    Jul 13 '16 at 15:52












  • In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

    – EEAA
    Jul 13 '16 at 15:52






  • 3





    Can you answer @EEAA's question about how you installed it?

    – garethTheRed
    Jul 13 '16 at 16:09






  • 1





    Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

    – garethTheRed
    Jul 14 '16 at 9:28












  • 1





    Did you restart nginx?

    – garethTheRed
    Jul 13 '16 at 15:52











  • Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

    – Punct Ulica
    Jul 13 '16 at 15:52












  • In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

    – EEAA
    Jul 13 '16 at 15:52






  • 3





    Can you answer @EEAA's question about how you installed it?

    – garethTheRed
    Jul 13 '16 at 16:09






  • 1





    Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

    – garethTheRed
    Jul 14 '16 at 9:28







1




1





Did you restart nginx?

– garethTheRed
Jul 13 '16 at 15:52





Did you restart nginx?

– garethTheRed
Jul 13 '16 at 15:52













Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

– Punct Ulica
Jul 13 '16 at 15:52






Yep. Unfortunately, it didn't do the trick. Not only nginx uses the old version of ssl, but also apache, mysql, postfix, root etc.

– Punct Ulica
Jul 13 '16 at 15:52














In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

– EEAA
Jul 13 '16 at 15:52





In additon to @garethTheRed's question, how did you install openssl and nginx? What OS is this?

– EEAA
Jul 13 '16 at 15:52




3




3





Can you answer @EEAA's question about how you installed it?

– garethTheRed
Jul 13 '16 at 16:09





Can you answer @EEAA's question about how you installed it?

– garethTheRed
Jul 13 '16 at 16:09




1




1





Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

– garethTheRed
Jul 14 '16 at 9:28





Maybe you should consider reverting to using rpm for your package and install 1.0.1e from the repo? That should be patched.

– garethTheRed
Jul 14 '16 at 9:28










2 Answers
2






active

oldest

votes


















0














You may run ldd /path/to/nginx to see how it's linked.






share|improve this answer






























    0














    You are solving this problem the wrong way. You need to understand Red Hat's patching policy (CentOS following upstream as it does, this is therefore CentOS's patching policy as well).



    As long as C6 is supported (ie, until 2020-11-30), and as long as you keep your C6 box fully up-to-patch, you will be running non-vulnerable versions of OpenSSL even though the OpenSSL version number does not change.



    Once you start building your own version of OpenSSL, you will find you have to rebuild (or at least relink) lots of major tools, to get them to pick up your handbuilt version, and you will have to do this each time a new version of OpenSSL comes out. It is a slough of despond, it is completely pointless, and it is unprofessional to boot.






    share|improve this answer























      Your Answer








      StackExchange.ready(function()
      var channelOptions =
      tags: "".split(" "),
      id: "2"
      ;
      initTagRenderer("".split(" "), "".split(" "), channelOptions);

      StackExchange.using("externalEditor", function()
      // Have to fire editor after snippets, if snippets enabled
      if (StackExchange.settings.snippets.snippetsEnabled)
      StackExchange.using("snippets", function()
      createEditor();
      );

      else
      createEditor();

      );

      function createEditor()
      StackExchange.prepareEditor(
      heartbeatType: 'answer',
      autoActivateHeartbeat: false,
      convertImagesToLinks: true,
      noModals: true,
      showLowRepImageUploadWarning: true,
      reputationToPostImages: 10,
      bindNavPrevention: true,
      postfix: "",
      imageUploader:
      brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
      contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
      allowUrls: true
      ,
      onDemand: true,
      discardSelector: ".discard-answer"
      ,immediatelyShowMarkdownHelp:true
      );



      );













      draft saved

      draft discarded


















      StackExchange.ready(
      function ()
      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f789617%2fupdated-the-openssl-version-but-the-old-version-still-appears-as-being-used%23new-answer', 'question_page');

      );

      Post as a guest















      Required, but never shown

























      2 Answers
      2






      active

      oldest

      votes








      2 Answers
      2






      active

      oldest

      votes









      active

      oldest

      votes






      active

      oldest

      votes









      0














      You may run ldd /path/to/nginx to see how it's linked.






      share|improve this answer



























        0














        You may run ldd /path/to/nginx to see how it's linked.






        share|improve this answer

























          0












          0








          0







          You may run ldd /path/to/nginx to see how it's linked.






          share|improve this answer













          You may run ldd /path/to/nginx to see how it's linked.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Jul 15 '16 at 7:45









          gbajsongbajson

          1467




          1467























              0














              You are solving this problem the wrong way. You need to understand Red Hat's patching policy (CentOS following upstream as it does, this is therefore CentOS's patching policy as well).



              As long as C6 is supported (ie, until 2020-11-30), and as long as you keep your C6 box fully up-to-patch, you will be running non-vulnerable versions of OpenSSL even though the OpenSSL version number does not change.



              Once you start building your own version of OpenSSL, you will find you have to rebuild (or at least relink) lots of major tools, to get them to pick up your handbuilt version, and you will have to do this each time a new version of OpenSSL comes out. It is a slough of despond, it is completely pointless, and it is unprofessional to boot.






              share|improve this answer



























                0














                You are solving this problem the wrong way. You need to understand Red Hat's patching policy (CentOS following upstream as it does, this is therefore CentOS's patching policy as well).



                As long as C6 is supported (ie, until 2020-11-30), and as long as you keep your C6 box fully up-to-patch, you will be running non-vulnerable versions of OpenSSL even though the OpenSSL version number does not change.



                Once you start building your own version of OpenSSL, you will find you have to rebuild (or at least relink) lots of major tools, to get them to pick up your handbuilt version, and you will have to do this each time a new version of OpenSSL comes out. It is a slough of despond, it is completely pointless, and it is unprofessional to boot.






                share|improve this answer

























                  0












                  0








                  0







                  You are solving this problem the wrong way. You need to understand Red Hat's patching policy (CentOS following upstream as it does, this is therefore CentOS's patching policy as well).



                  As long as C6 is supported (ie, until 2020-11-30), and as long as you keep your C6 box fully up-to-patch, you will be running non-vulnerable versions of OpenSSL even though the OpenSSL version number does not change.



                  Once you start building your own version of OpenSSL, you will find you have to rebuild (or at least relink) lots of major tools, to get them to pick up your handbuilt version, and you will have to do this each time a new version of OpenSSL comes out. It is a slough of despond, it is completely pointless, and it is unprofessional to boot.






                  share|improve this answer













                  You are solving this problem the wrong way. You need to understand Red Hat's patching policy (CentOS following upstream as it does, this is therefore CentOS's patching policy as well).



                  As long as C6 is supported (ie, until 2020-11-30), and as long as you keep your C6 box fully up-to-patch, you will be running non-vulnerable versions of OpenSSL even though the OpenSSL version number does not change.



                  Once you start building your own version of OpenSSL, you will find you have to rebuild (or at least relink) lots of major tools, to get them to pick up your handbuilt version, and you will have to do this each time a new version of OpenSSL comes out. It is a slough of despond, it is completely pointless, and it is unprofessional to boot.







                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Jul 15 '16 at 7:58









                  MadHatterMadHatter

                  70.8k11147207




                  70.8k11147207



























                      draft saved

                      draft discarded
















































                      Thanks for contributing an answer to Server Fault!


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid


                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.

                      To learn more, see our tips on writing great answers.




                      draft saved


                      draft discarded














                      StackExchange.ready(
                      function ()
                      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f789617%2fupdated-the-openssl-version-but-the-old-version-still-appears-as-being-used%23new-answer', 'question_page');

                      );

                      Post as a guest















                      Required, but never shown





















































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown

































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown







                      Popular posts from this blog

                      Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                      Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                      Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020