Ask HN: openSSL/heartbleed for internal company apps?

https://news.ycombinator.com/item?id=7598809
by engtech • 12 years ago
1 1 12 years ago

Are you bothering to check openSSL versions for internal apps like:

- revision control - wikis - tool installs like perl, python (because of LDAP authentication)

Looking around it seems like Perforce and Subversion had heartbleed vulnerabilities for specific configurations.

Looking through various LDAP plugins for different tools, they may use a version of openSSL that is vulnerable.

Should we be patching openSSL on all of the linux boxes and not just web servers?

Related Stories

Loading related stories...

Source preview

news.ycombinator.com