Ubuntu升级OpenSSL以保障安全,可按以下步骤操作:
sudo apt update
sudo apt upgrade openssl
或使用全系统升级(包含所有可更新软件包):sudo apt full-upgrade
openssl version
确保输出为最新版本(如OpenSSL 3.x系列)。若需特定版本,可添加PPA(如ondrej/php
):
sudo add-apt-repository ppa:ondrej/php
sudo apt update
sudo apt upgrade openssl
wget https://www.openssl.org/source/openssl-3.0.10.tar.gz
tar -xzvf openssl-3.0.10.tar.gz
cd openssl-3.0.10
./config --prefix=/usr/local/openssl --openssldir=/usr/local/openssl shared zlib
make && sudo make install
echo "/usr/local/openssl/lib" | sudo tee /etc/ld.so.conf.d/openssl.conf
sudo ldconfig
/usr/local/openssl/bin/openssl version
sudo systemctl restart apache2 # Apache
sudo systemctl restart nginx # Nginx
/etc/ssl/openssl.cnf
,禁用不安全协议(如SSLv2/SSLv3),启用强密码套件:[system_default_sect]
MinProtocol = TLSv1.2
CipherString = HIGH:!aNULL:!MD5
unattended-upgrades
并启用,确保系统自动获取安全补丁:sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrades
/etc/ssl/
下的证书和密钥)。openssl version
和系统安全公告,确保长期使用最新版本。以上步骤参考自。