Alpha Software Mobile Development Tools:   Alpha Anywhere    |   Alpha TransForm subscribe to our YouTube Channel  Follow Us on LinkedIn  Follow Us on Twitter  Follow Us on Facebook

Announcement

Collapse

The Alpha Software Forum Participation Guidelines

The Alpha Software Forum is a free forum created for Alpha Software Developer Community to ask for help, exchange ideas, and share solutions. Alpha Software strives to create an environment where all members of the community can feel safe to participate. In order to ensure the Alpha Software Forum is a place where all feel welcome, forum participants are expected to behave as follows:
  • Be professional in your conduct
  • Be kind to others
  • Be constructive when giving feedback
  • Be open to new ideas and suggestions
  • Stay on topic


Be sure all comments and threads you post are respectful. Posts that contain any of the following content will be considered a violation of your agreement as a member of the Alpha Software Forum Community and will be moderated:
  • Spam.
  • Vulgar language.
  • Quotes from private conversations without permission, including pricing and other sales related discussions.
  • Personal attacks, insults, or subtle put-downs.
  • Harassment, bullying, threatening, mocking, shaming, or deriding anyone.
  • Sexist, racist, homophobic, transphobic, ableist, or otherwise discriminatory jokes and language.
  • Sexually explicit or violent material, links, or language.
  • Pirated, hacked, or copyright-infringing material.
  • Encouraging of others to engage in the above behaviors.


If a thread or post is found to contain any of the content outlined above, a moderator may choose to take one of the following actions:
  • Remove the Post or Thread - the content is removed from the forum.
  • Place the User in Moderation - all posts and new threads must be approved by a moderator before they are posted.
  • Temporarily Ban the User - user is banned from forum for a period of time.
  • Permanently Ban the User - user is permanently banned from the forum.


Moderators may also rename posts and threads if they are too generic or do not property reflect the content.

Moderators may move threads if they have been posted in the incorrect forum.

Threads/Posts questioning specific moderator decisions or actions (such as "why was a user banned?") are not allowed and will be removed.

The owners of Alpha Software Corporation (Forum Owner) reserve the right to remove, edit, move, or close any thread for any reason; or ban any forum member without notice, reason, or explanation.

Community members are encouraged to click the "Report Post" icon in the lower left of a given post if they feel the post is in violation of the rules. This will alert the Moderators to take a look.

Alpha Software Corporation may amend the guidelines from time to time and may also vary the procedures it sets out where appropriate in a particular case. Your agreement to comply with the guidelines will be deemed agreement to any changes to it.



Bonus TIPS for Successful Posting

Try a Search First
It is highly recommended that a Search be done on your topic before posting, as many questions have been answered in prior posts. As with any search engine, the shorter the search term, the more "hits" will be returned, but the more specific the search term is, the greater the relevance of those "hits". Searching for "table" might well return every message on the board while "tablesum" would greatly restrict the number of messages returned.

When you do post
First, make sure you are posting your question in the correct forum. For example, if you post an issue regarding Desktop applications on the Mobile & Browser Applications board , not only will your question not be seen by the appropriate audience, it may also be removed or relocated.

The more detail you provide about your problem or question, the more likely someone is to understand your request and be able to help. A sample database with a minimum of records (and its support files, zipped together) will make it much easier to diagnose issues with your application. Screen shots of error messages are especially helpful.

When explaining how to reproduce your problem, please be as detailed as possible. Describe every step, click-by-click and keypress-by-keypress. Otherwise when others try to duplicate your problem, they may do something slightly different and end up with different results.

A note about attachments
You may only attach one file to each message. Attachment file size is limited to 2MB. If you need to include several files, you may do so by zipping them into a single archive.

If you forgot to attach your files to your post, please do NOT create a new thread. Instead, reply to your original message and attach the file there.

When attaching screen shots, it is best to attach an image file (.BMP, .JPG, .GIF, .PNG, etc.) or a zip file of several images, as opposed to a Word document containing the screen shots. Because Word documents are prone to viruses, many message board users will not open your Word file, therefore limiting their ability to help you.

Similarly, if you are uploading a zipped archive, you should simply create a .ZIP file and not a self-extracting .EXE as many users will not run your EXE file.
See more
See less

OpenSSL update to address DROWN now available

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    OpenSSL update to address DROWN now available

    Issue
    OpenSSL issued a security advisory on March 1, 2016. This advisory covers a number of issues, the most significant of which is commonly referred to as DROWN. The full text of this advisory is at http://openssl.org/news/secadv/20160301.txt


    Affected Products
    All versions of Alpha Five and Alpha Anywhere released prior to March 3, 2016 are affected as they use an OpenSSL release with the vulnerabilities discussed in the security advisory.


    Remediation - Customer Action Required
    Along with this advisory, OpenSSL 1.0.2g was released to address these problems. OpenSSL 1.0.2g is now included with Alpha Anywhere and the Alpha Anywhere Application Server pre-releases as of March 3, 2016.

    While there is no way we could have anticipated these third party, industry-wide security vulnerabilities, we have taken immediate action to ensure that Alpha Anywhere subscribers with up-to-date licenses are covered. To that end, we have issued a new pre-release build of Alpha Anywhere that is patched with Open SSL 1.0.2g. Subscribers with an up-to-date license are now able to download and install this build which will automatically address all known security issues.

    Additionally, for subscribers who do not wish to install a pre-release build, we have made the security patch available for download separately. These DLL files are also compatible with Alpha Five v11 applications that our users are still running but do not wish to upgrade to a new server. These DLLs are compatible with Alpha Anywhere and Alpha Five v11 only. To request these files, email [email protected].

    Special note for users still running applications on Alpha Five v10 and earlier versions

    If you still have legacy applications running on Alpha Five v10 or earlier versions, it is STRONGLY advised that you upgrade at least their Application Servers to Alpha Anywhere as soon as possible. Alpha Five v10 and earlier versions are vulnerable to a number of exploits and no security updates will be available.

    The OpenSSL updates we are providing are NOT compatible with Alpha Five versions earlier than v11. At that time, Alpha Five and the Application Server used the 0.9.8 tree of OpenSSL. The newer 1.0.1 and 1.0.2 DLLs will not work in these older versions of Alpha. Furthermore, OpenSSL set the "end of life" for 0.9.8 as December 31, 2015 and no further updates will be released. This means there is no way to secure v10 and prior against these newer exploits.

    It is STRONGLY advised that users still running Alpha Five v10 or earlier versions upgrade at least their Application Servers to Alpha Anywhere as soon as possible.

    #2
    Re: OpenSSL update to address DROWN now available

    A similar announcement was in the forum a week ago but I see that that post was deleted. In that post the separate files were included as an attachment anyone could download. Has anything changed between last Friday and now? ....I've already installed the 1.0.2g from the original post.
    Mike Brown - Contact Me
    Programmatic Technologies, LLC
    Programmatic-Technologies.com
    Independent Developer & Consultant​​

    Comment


      #3
      Re: OpenSSL update to address DROWN now available

      In addition to what Mike said, what is the current recommended cipher list. I had developed a good one for my needs, but that list does not work at all with this update.

      BTW, the server is back to a "c-" rating from Qualys SSL Labs after putting on 1.0.2g and reverting back to a Cipher List that the update would take. :-(
      Last edited by RichCPT; 03-11-2016, 10:43 PM.

      Comment


        #4
        Re: OpenSSL update to address DROWN now available

        Mike, the 1.0.2g files have not changed since the prior announcement.

        Rich, your old cipher list should still be functional with this update. Unfortunately if there is something in it that causes a problem, OpenSSL doesn't work at all. In this case, it becomes a case of trial-and-error to make minor edits and identify the cause of the problem. If you'd like to share your prior cipher list, we can attempt to help you with this.

        Lenny Forziati
        Vice President, Internet Products and Technical Services
        Alpha Software Corporation

        Comment


          #5
          Re: OpenSSL update to address DROWN now available

          I'm still on v11 and don't subscribe to alpha anywhere. I guess I'm screwed..
          Creating Healthcare Work-Flow Solutions Since 2005

          Comment


            #6
            Re: OpenSSL update to address DROWN now available

            Originally posted by omagarc View Post
            I'm still on v11 and don't subscribe to alpha anywhere. I guess I'm screwed..
            Why, the notice says you can download the dll's without having to upgrade?
            Alpha Anywhere v12.4.6.5.2 Build 8867-5691 IIS v10.0 on Windows Server 2019 Std in Hyper-V

            Comment


              #7
              Re: OpenSSL update to address DROWN now available

              Originally posted by iRadiate View Post
              Why, the notice says you can download the dll's without having to upgrade?
              It says subscribers can download...
              Creating Healthcare Work-Flow Solutions Since 2005

              Comment


                #8
                Re: OpenSSL update to address DROWN now available

                Originally posted by omagarc View Post
                It says subscribers can download...
                Hmmm. Maybe you could simply download OpenSSL 1.0.2g direct from OpenSSL.org ?
                Alpha Anywhere v12.4.6.5.2 Build 8867-5691 IIS v10.0 on Windows Server 2019 Std in Hyper-V

                Comment


                  #9
                  Re: OpenSSL update to address DROWN now available

                  I don't think v11 is a subscription service, is it? What would there be to subscribe to?? ...the last supported version is years old. "Subscribers" are Alpha 12 users if I'm not mistaken.

                  Just e-mail [email protected] like the post suggests.
                  Mike Brown - Contact Me
                  Programmatic Technologies, LLC
                  Programmatic-Technologies.com
                  Independent Developer & Consultant​​

                  Comment


                    #10
                    Re: OpenSSL update to address DROWN now available

                    I've sent them an email for clarification as the email received suggests the need to upgrade..
                    Creating Healthcare Work-Flow Solutions Since 2005

                    Comment


                      #11
                      Re: OpenSSL update to address DROWN now available

                      Originally posted by omagarc View Post
                      I've sent them an email for clarification as the email received suggests the need to upgrade..
                      I got a quick reply from customer service and it is confirmed. I do need to have an 'active' subscription to v12+ in order to obtain the OpenSSL patch files that are compatible with my v11. I did look at OpenSSL and it looks like there is a lot of compiling to perform and I can only guess there is one or two .dll files in A5 that need updating. Which ones or how to escapes me.

                      I'm hosting only one application on my server and my client connects to me via vpn. I have another customer for another app and I was wanting to skip the vpn but this came up. I guess i'll just stick with the vpn for now unless Alpha has a sweet deal.

                      Is v12 and Alpha Anywhere one in the same? Does anyone know if v13 or Alpha Anywhere plus is on the horizon? I always seem to upgrade close to the end of one version life cycle. Urghh..
                      Creating Healthcare Work-Flow Solutions Since 2005

                      Comment


                        #12
                        Re: OpenSSL update to address DROWN now available

                        Originally posted by omagarc View Post
                        I did look at OpenSSL and it looks like there is a lot of compiling to perform and I can only guess there is one or two .dll files in A5 that need updating. Which ones or how to escapes me.
                        Upgrading/replacing the OpenSSL DLLs is quite simple and is covered in Encryption Algorithms (Ciphers) - Adding Additional Algorithms. However non-subscribers are still responsible for building the DLLs from the OpenSSL source or obtaining trusted pre-compiled binaries elsewhere.

                        Lenny Forziati
                        Vice President, Internet Products and Technical Services
                        Alpha Software Corporation

                        Comment


                          #13
                          Re: OpenSSL update to address DROWN now available

                          V12 and AA are the same. I believe the next version is being worked on and I think it's release will be "soon" ...but I really don't know what that ETA might be. It's been about 8 months since the last official update for v12.
                          Mike Brown - Contact Me
                          Programmatic Technologies, LLC
                          Programmatic-Technologies.com
                          Independent Developer & Consultant​​

                          Comment


                            #14
                            Re: OpenSSL update to address DROWN now available

                            Originally posted by Lenny Forziati View Post
                            Upgrading/replacing the OpenSSL DLLs is quite simple and is covered in Encryption Algorithms (Ciphers) - Adding Additional Algorithms. However non-subscribers are still responsible for building the DLLs from the OpenSSL source or obtaining trusted pre-compiled binaries elsewhere.
                            Thanks Lenny!
                            Creating Healthcare Work-Flow Solutions Since 2005

                            Comment


                              #15
                              Re: OpenSSL update to address DROWN now available

                              I did put this also to the earlier similar thread that was totally deleted but here is link again: info about drown.
                              With version 11 I would just continue using server just like before.

                              Comment

                              Working...
                              X