No Image

can’t start httpd(apache-2.4) with ssl module

2015-12-15 KENNETH 0

  아파치에 SSL모듈 및 가상호스트 설정후 아래 로그와 함께 아파치가 시작이 되지 않음   환경 OS : linux apache : 2.4   로그 [ssl:emerg] [pid 11900] AH02572: Failed to configure at least one certificate and key for notssldomain.com:443 [ssl:emerg] [pid 11900] SSL Library Error: error:140A80B1:SSL routines:SSL_CTX_check_private_key:no certificate assigned [ssl:emerg] [pid 11900] AH02312: Fatal error initialising mod_ssl, exiting. AH00016: Configuration Failed 일단 SSL관련 오류가 발생 특이한 것은 SSL적용 대상이 아닌 도메인에 대해 (notssldomain.com:443) 으로 에러 로그가 기록됨   의문 인증서 파일에 문제가 있어도 발생할 수 있는 에러이지만… 아무리 확인을 해봐도 인증서에는 문제가 없고(동일한 환경에서 잘 사용중인 인증서) 환경도 별다른 문제가 없어 보였는데…     문제점 SSLEngine On 설정이 전역으로 들어간 것이 문제;;;;;;;   정상 <VirtualHost *:443> ServerName ssldomain.com . . SSLEngine on SSLCertificateFile …. SSLCertificateKeyFile …. </VirtualHost>   문제 SSLEngine on . <VirtualHost *:443> ServerName ssldomain.com . . SSLCertificateFile …. SSLCertificateKeyFile [ more… ]

No Image

USN-2834-1: libxml2 vulnerabilities

2015-12-14 KENNETH 0

Ubuntu Security Notice USN-2834-1 14th December, 2015 libxml2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary libxml2 could be made to crash if it opened a specially crafted file. Software description libxml2 – GNOME XML library Details Kostya Serebryany discovered that libxml2 incorrectly handled certainmalformed documents. If a user or automated system were tricked intoopening a specially crafted document, an attacker could possibly causelibxml2 to crash, resulting in a denial of service. (CVE-2015-5312,CVE-2015-7497, CVE-2015-7498, CVE-2015-7499,CVE-2015-7500) Hugh Davenport discovered that libxml2 incorrectly handled certainmalformed documents. If a user or automated system were tricked intoopening a specially crafted document, an attacker could possibly causelibxml2 to crash, resulting in a denial of service. (CVE-2015-8241,CVE-2015-8242) Hanno Boeck discovered that libxml2 incorrectly handled certainmalformed documents. If a user or automated [ more… ]

No Image

RHSA-2015:2619-1: Moderate: libreoffice security update

2015-12-14 KENNETH 0

Red Hat Enterprise Linux: Updated libreoffice packages that fixes multiple security issues are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2015-4551, CVE-2015-5212, CVE-2015-5213, CVE-2015-5214 Source: rhn-errata

No Image

RHSA-2015:2618-1: Important: chromium-browser security update

2015-12-14 KENNETH 0

Red Hat Enterprise Linux: Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2015-6788, CVE-2015-6789, CVE-2015-6790, CVE-2015-6791 Source: rhn-errata