Forum archive
Heartbleed Issue
My server is clearly affected by the heartbleed bug (basic LAMP appliance) but I see no security changes at all. How do I fix this since the fixes are the responsibility of Turnkey? I checked the logs and even rebooted the server but I am still shown as vulnerable. There isn't much here anyone would want to steal but how can I trust the security of the appliance if the single biggest issue in the history of Linux seems to have no fixes?
TBH I'm not sure what is going on with that. I tested the v12.1 LAMP release as well and (until security updates are applied - using cron-apt - the script that runs nightly) it also reports as vulnerable. Once the updates are done though it reports as ok.
FWIW whilst technically v11.1 should still be ok to use (it's based on Ubuntu 10.04 which should still get another year of security updates) it is not supported by TurnKey Linux. V12.1 is considered legacy, but support for that ends this month anyway...