ClearFoundation Tracker - ClearOS
View Issue Details
0013151ClearOSopenvpnpublic2017-02-21 09:212017-04-18 11:48
user2 
user2 
highmajoralways
closedfixed 
 
7.3.1 Updates7.3.1 Updates 
0013151: Consider pushing through OpenVPN - EPEL override
The Sweet32 vulnerability exists in OpenVPN. We should consider getting ahead of the curve instead of waiting on an EPEL update.

More info: https://sweet32.info/ [^]
No tags attached.
Issue History
2017-02-21 09:21user2New Issue
2017-02-21 09:27user2Statusnew => confirmed
2017-02-21 10:29NickHNote Added: 0004831
2017-02-21 14:37NickHNote Edited: 0004831bug_revision_view_page.php?bugnote_id=4831#r1551
2017-02-21 14:40NickHNote Added: 0004851
2017-04-14 12:06NickHNote Added: 0005371
2017-04-17 12:31user2Prioritynormal => high
2017-04-18 11:47user2Statusconfirmed => resolved
2017-04-18 11:47user2Fixed in Version => 7.3.1 Updates
2017-04-18 11:47user2Resolutionopen => fixed
2017-04-18 11:47user2Assigned To => user2
2017-04-18 11:48user2Statusresolved => closed

Notes
(0004831)
NickH   
2017-02-21 10:29   
(edited on: 2017-02-21 14:37)
I've done some more investigating and reading of https://sweet32.info/ [^] and the OpenVPN site. It looks like the changelog for 2.3.13, https://forums.openvpn.net/viewtopic.php?f=20&t=22742, [^] limits the reneg-bytes to 64MB anyway which would make upgrading OpenVPN not so necessary.

I've also posted a question requesting clarifying of the reneg-bytes unit of measure https://forums.openvpn.net/viewtopic.php?f=4&t=23490&e=1 [^]

(0004851)
NickH   
2017-02-21 14:40   
Link fixed to my post in the OpenVPN forum in the previous comment.

Summary:
- reneg-bytes should be 64000000 and not 64000 (was a typo on their wiki)
- Upgrade to 2.4 all round if you can.
(0005371)
NickH   
2017-04-14 12:06   
openvpn-2.4.1-2.el7 has made its way through to epel-unverified. Can this now be pushed into a clearos repo?