openssldoesn't -overwrite-base again (was: FreeBSD-SA-08:05.openssh)

Roger Marquis marquis at roble.com
Thu Apr 17 18:35:04 UTC 2008


I'd like to thank the openssh-portable port maintainer/s for
preserving the -overwrite-base option. This eases our systems and
security update jobs measurably.

Unfortunately, openSSL has dropped the -overwrite-base option
(again), leaving us with two versions of openssl and some
confusion over A) which version of openssl a new port or upgrade
(i.e., openssh) will use, and B) how to update systems with
openssl-overwrite-base installed.

Is there a best practice/recommendation for updating
openssl-overwrite-base without having to maintain multiple
versions?

Roger Marquis
Roble Systems Consulting


More information about the freebsd-security mailing list