[afnog] Time to update openssl

Randy Bush randy at psg.com
Thu Apr 10 10:36:40 UTC 2014


> The command below will give false positives if the site supports
> hearbeats.
>>> openssl s_client -connect google\.com:443  -tlsextdebug 2>&1| grep 'server extension "heartbeat" (id=15)' || echo safe

no.  you are misunderstanding what the command is intended to do.  it
tells you if the heartbleed code is there.  it does not tell you whether
or not the hole in it is present.

randy



More information about the afnog mailing list