在 Linux 上“修复 OpenSSL 漏洞”通常不是重装 OpenSSL,而是升级到已修复的安全版本。下面按常见场景说明。
openssl version -a
常见漏洞示例:
可对照:
sudo yum update openssl
# 或
sudo dnf update openssl
验证:
rpm -q openssl
openssl version
注意:
- 不要手动覆盖系统 OpenSSL,否则会导致 yum / ssh / 证书失效
- CentOS 6 已 EOL,只能升级系统或自行编译(不推荐)
sudo apt update
sudo apt upgrade openssl
验证:
dpkg -l | grep openssl
openssl version
如果只升级 openssl 不够:
sudo apt full-upgrade
sudo zypper up openssl
OpenSSL 是动态库,升级后正在运行的服务不会自动生效。
常见需要重启的服务:
sudo systemctl restart sshd
sudo systemctl restart nginx
sudo systemctl restart apache2
sudo systemctl restart postfix
sudo systemctl restart docker
检查谁在用旧版本:
lsof | grep libssl
FROM ubuntu:22.04
RUN apt update && apt upgrade -y openssl
仅用于:
示例(谨慎):
wget https://www.openssl.org/source/openssl-3.0.14.tar.gz
tar xzf openssl-3.0.14.tar.gz
cd openssl-3.0.14
./config --prefix=/usr/local/openssl
make
sudo make install
⚠️ 风险:
openssl version
testssl.sh yourdomain.com
✅ 用发行版官方更新
✅ 升级后重启服务
❌ 不要随意手动替换系统 OpenSSL
❌ 不要忽略运行中的进程
如果你愿意,可以告诉我:
openssl version 输出我可以给你精确的一条命令修复方案。