Score:0

How to update OpenSSL FIPS-validated packages?

us flag

I am running FIPS for Ubuntu 18.04 which uses certified cryptographic modules. One of the modules, openssl1.1.1-1ubuntu2.fips.2.1~18.04.3.1 has vulnerabilities (CVE-2021-3711, CVE-2021-3712) that are fixed in an updated version, openssl1.1.1-1ubuntu2.1~18.04.13.

This newer package is not available to install when I run apt upgrade. I haven't been able to find any documentation or guidance at ubuntu.com, do I need to wait for Canonical to release an updated FIPS-validated package or is there a way to apply the update?

ru flag
You'll need to wait for Canonical to release an update - if they release an update. The FIPS stuff is only enabled via separate repositories from Canonical. (so Canonical Support is going to be your POC for this)
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.