I read in many places that it is a good idea to keep openSSL up to date to the latest version. I can easily find the latest version on the openssl.org website with the notes about features and fixes. But, nowhere do I find any advice about how to do it.
I am running my brand new FreeBSD 9.0 webserver, and I have everything working perfectly with no errors anywhere. However, I see that the base installation of openSSL is at 0.9.8q 2 Dec 2010. That's several updates behind already, and I see that 1.0.1 has now been released just a few days ago.
Of course, I would like to take all the advice and keep my openSSL up to date, but as I search the web for info about doing that, even on the openSSL website itself, I find almost nothing! The most recent post about it on this forum that I can find is dated three years ago! What I DO find are some "horror stories" about users having tried it with terrible results, breaking what already works resulting in the usual week-long struggle to get everything working correctly again.
So, I am terrifed to even give it a go. I do not want to spend the next several days fighting if things go wrong.
What do you think about this? Does anyone here on the forum have any comments about upgrading openSSL and keeping it up to date? Have any of you tried it? Did it work? Does it work?
Does anyone have some good instructions or advice about how to do it without grief? I would like very much to hear your comments before I try it.
Thank you.
I am running my brand new FreeBSD 9.0 webserver, and I have everything working perfectly with no errors anywhere. However, I see that the base installation of openSSL is at 0.9.8q 2 Dec 2010. That's several updates behind already, and I see that 1.0.1 has now been released just a few days ago.
Of course, I would like to take all the advice and keep my openSSL up to date, but as I search the web for info about doing that, even on the openSSL website itself, I find almost nothing! The most recent post about it on this forum that I can find is dated three years ago! What I DO find are some "horror stories" about users having tried it with terrible results, breaking what already works resulting in the usual week-long struggle to get everything working correctly again.
So, I am terrifed to even give it a go. I do not want to spend the next several days fighting if things go wrong.
What do you think about this? Does anyone here on the forum have any comments about upgrading openSSL and keeping it up to date? Have any of you tried it? Did it work? Does it work?
Does anyone have some good instructions or advice about how to do it without grief? I would like very much to hear your comments before I try it.
Thank you.