fbpx
Contact Us
Blog April 11, 2014

Security Update- Are You Protected from the "Heartbleed" bug?

Connectria’s engineers are aware of the vulnerability, dubbed “Heartbleed”, which is a concern of all users of OpenSSL.  The bug has the potential to expose private information that is stored in memory of the server.  It can allow attackers to read the memory of the systems using vulnerable versions of OpenSSL library (1.0.1 through 1.0.1f).

Specific communication has gone out to all of Connectria’s customers, but if you using another cloud service read on.

This is a vulnerability with the OpenSSL library and not a flaw with SSL/TLS.  If you are running Microsoft IIS you are not vulnerable.  If your application or web server is using a web service that uses the OpenSSL library, you will need to:

1. Identify if your web servers are running a vulnerable version of OpenSSL (1.0.1 through 1.0.2f).  If your version is older than 1.0.1, then you are not vulnerable and no action is required.
2. If your server is vulnerable, you will need to update to the latest version of OpenSSL 1.0.1g.
3. Generate a new Certificate Signing Request (CSR).
4. Reissue any SSL certificates for the affected server using the new CSR.
5.  Install new SSL certificate and test.
6.  Revoke any old SSL certificates that have been replaced.

If you would like to test your web services to see if you are affected, please visit our partner GeoTrust to check your site.

Related Resources

 
Connectria’s IBM Business Recognized for Excellence, Here’s How We Do It
In 2019, the IBM Think conference garnered over 30,000 attendees. This year’s conference, like a lot of events, changed course when the COVID-19 pandemic hit.…
 
Connectria’s Green Cloud Initiative Going Strong
After the successful launch of Connectria’s Green Cloud Initiative earlier this year, we continue our work with green computing. To follow up on how the…
 
The Cloud Center of Excellence: An Essential Tool for Cloud Success
Today, it’s not a question of whether an organization has workloads housed in the cloud. Instead, the question is what percentage of their workloads they’ve…