[eduVPN-deploy] [2021-08-27] *IMPORTANT* Package Updates

François Kooman fkooman at tuxed.net
Tue Aug 31 10:41:19 CEST 2021


On 31.08.21 10:17, Sandeep Bhagat wrote:
> Hi François,

Hello Sandeep,

> Our application security team suggested for
> ### openssl current version ###
> ### httpd current version ###

The versions of the components as used by CentOS 7 are maintained by Red 
Hat. So in case the software is vulnerable, it will be updated by them. 
This is a big reason for why we built the software on top of CentOS (and 
Debian).

I'd very much recommend *against* swapping out core components and 
running other versions, for multiple reasons, unless you really know 
what you are doing. Obviously, we cannot support this.

If you prefer to run on newer software, switching to Debian 11 would be 
a much better approach.

Regards,
François



More information about the eduVPN-deploy mailing list