Authentication Manager
Customers report that their scanning software generated a report suggesting that Authentication Manager is showing one or more OpenSSL vulnerabilities.
This article provides information on Authentication Manager and OpenSSL.
SUSE Enterprise Linux (SLES) uses OpenSSL to handle security protocols and encryption across applications and services. OpenSSL is a critical component for ensuring secure data transfer, authentication, and encryption across applications in SLES. It is included and installed by default as part of the operating system’s core packages/base installation. SUSE regularly provides patches and updates for OpenSSL to address vulnerabilities, ensuring compliance with security standards and protecting against emerging threats.
To view OpenSSL versions included with different SLES releases, refer to the SUSE knowledge base here. You can also consult release notes for specific SLES versions in SUSE’s official documentation at https://documentation.suse.com/.
If your scanning tool or report indicates a potential OpenSSL vulnerability in Authentication Manager, you can verify the OpenSSL version and dependencies by following these steps:
- SSH into the server as the rsaadmin user.
- Once logged in, elevate privileges to root by running the command: sudo su -.
- Run zypper info openssl to get the SLES component version information.
- To list all dependencies, use zypper info --requires openssl or rpm -qR openssl.
Note: The output of the openssl version command only provides the publicly declared version of the tool for interface compatibility.
RSA regularly releases updates for SLES and other components. Keeping your system up to date is crucial for security. For further queries, please contact customer support.
Related Articles
RSA Authentication Manager 8.2 Setup and Configuration Guide 34Number of Views Poodle Bite, Sandworm, .NET MS14-057, and other OpenSSL Vulnerabilities and Impact in RSA products 87Number of Views When approval activities are grouped by category, they auto-complete when one of the items is rejected in RSA Identity Gov… 90Number of Views AFX is unresponsive and one or more AFX Connectors are in a Not Deployed state in RSA Identity Governance & Lifecycle 102Number of Views Poodle Bite Sandworm .Net MS14-057 OpenSSL Vulnerabilities and Impact in RSA products 4.79KNumber of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 Downloading RSA Authentication Manager license files or RSA Software token seed records AFX Server remains in a 'Not running' State, afx status shows 'timed out waiting for AFX applications to start' and mule_e… RSA Authentication Manager 8.7 SP1 Patch 1 Hotfix 1 RSA Authentication Manager 8.8 Security Configuration Guide