openssl: which version to upgrade to
Hi,
I have been asked to upgrade a RHEL 6.4 server's openssl package from openssl-1.0.0-27.el6 to openssl-1.0.1m.
I have worked out that the request is based on the OpenSSL Software Foundation versions rather than the Red Hat ones.
I have done a fair bit of browsing, both here and elsewhere, but I cannot find a specific latest (and secure) version for RHEL 6.4, all I find are errata pages that just list the openssl version for RHEL 6.
I have downloaded the 6.4 installation ISO and checked, it contains the same version as my server has, I have also looked on the CentOS mirror site and the 6.4 tree shows the same version.
My question is:
Is there a latest version specifically for RHEL 6.4 or do I go with the latest version for RHEL 6 ?
Part of my hesitation to go for the latter is that it's quite a jump and I am concerned that it might introduce incompatibilities, but maybe I'm just being overly cautious.
Another piece of my confusion is whether a version of RHEL (i.e. 6.4) that is shipped with an openssl in the 1.0.0 branch should stay in that branch and not stray out into the 1.0.1 branch ... if that makes any sense?
Yours appreciatively,
Nick