What is the UnixWare 7D OpenSSL 1.0.2n Package? The OpenSSL 1.0.2n package is an updated OpenSSL for UnixWare 7D that addresses the following problems or new features. Problems Fixed -------------- 1. Addressing concerns Read/write after SSL object in error state (CVE-2017-3737) 2. Fix for rsaz_1024_mul_avx2 overflow bug on x86_64 (CVE-2017-3738) This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). References ========== URL for the OpenSSL Security Advisory: https://www.openssl.org/news/secadv/20171207.txt Features Added to OpenSSL 1.0.2n --------------------------------- 1. security release only. See OpenSSL release notes at https://www.openssl.org/news/openssl-1.0.2-notes.html Features Added to OpenSSL 1.0.2n1 --------------------------------- 1. openssl utilities can now handle files > 2GB Features Added to this package --------------------------------- 1. /etc/ssl/certs/xinuos-ca-bundle.crt certificate bundle is provided for your convenience. See text starting at line 210 of that file. If /etc/ssl/certs/ca-bundle.crt does not exist at install time, xinuos-ca-bundle.crt will be copied to ca-bundle.crt Xinuos makes no warranties as to the trustworthiness or RFC 3647 compliance of the certification authorities whose certificates are included in this package. Assessment and verification of trust is the complete responsibility of the system administrator. Contents -------- openssl-1.0.2n1-UnixWare7D-i386.pkg.gz openssl-dev-1.0.2n1-UnixWare7D-i386.pkg.gz MD5 (openssl-1.0.2n1-UnixWare7D-i386.pkg.gz) = 8471ddd727d03d0527cdea13625573ce MD5 (openssl-dev-1.0.2n1-UnixWare7D-i386.pkg.gz) = a1b3c31b67e5db078ad69495bbd9209b SHA256(openssl-1.0.2n1-UnixWare7D-i386.pkg.gz)= 9d26a16b11d265841ca9c4c1ea5423d9f5ef7526411f3598fe1eee5474a263b6 SHA256(openssl-dev-1.0.2n1-UnixWare7D-i386.pkg.gz)= 6e80b4316a8734473786002850bccf91e39d7eb390d9f19b3085e6d5a57af219 Software Notes and Recommendations ---------------------------------- The UW7D OpenSSL 1.0.2n1 package is intended for installation on UnixWare 7 Definitive 2018 Installation Instructions ------------------------- 1. Download openssl-1.0.2n1-UnixWare7D-i386.pkg.gz and openssl-dev-1.0.2n1-UnixWare7D-i386.pkg.gz files to the /tmp directory on your machine. 2. As root, add the package to your system using these commands: $ su - Password: # gzcat /tmp/openssl-1.0.2n1-UnixWare7D-i386.pkg.gz | pkgadd -qd - all If you develop software using the OpenSSL libraries, install the development package. # gzcat /tmp/openssl-dev-1.0.2n1-UnixWare7D-i386.pkg.gz | pkgadd -qd - all 3. The system should be rebooted after installing this package. 4. The upgrade process will not modify existing /etc/ssl/openssl.cnf settings if modifications have been made. OpenSSL 1.0.2n may have modified default option settings as well as have additional options than the earlier openSSL being replaced. The default configuration file is /etc/ssl/openssl.cnf.dfl. System administrators should review the 1.0.2n default options and update /etc/ssl/openssl.cnf settings accordingly. Removal Instructions -------------------- 1. As root, remove the package using these commands: $ su - Password: # pkgrm openssl 3. Your system does not contain an OpenSSL after removal of this package. Note: removing OpenSSL will break OpenSSH and any other software linked against the OpenSSL libraries. If you have questions regarding this supplement, or the product on which it is installed, please contact your Xinuos software supplier.