使用RPM升级OPENSSL、OPENSSH目的:不更新系统情况下,升级软件版本修复漏洞 查看当前系统版本 [root@localhost openssl]# cat /etc/redhat-release CentOS Linux release 7.0.1406 (Core) 查看当前软件版本 [root@localhost ~]# ssh -V OpenSSH_6.4p1, OpenSSL 1.0.1e-fips 11 Feb 2013 升级OPENSSL 需要下载的RPM包如下: dracut-033-535.el7.x86_64.rpm
krb5-devel-1.15.1-19.el7.x86_64.rpm
libselinux-utils-2.5-12.el7.x86_64.rpm
pcre-8.32-17.el7.x86_64.rpm dracut-config-rescue-033-535.el7.x86_64.rpm
krb5-libs-1.15.1-19.el7.x86_64.rpm
libsepol-2.5-8.1.el7.x86_64.rpm
pcre-devel-8.32-17.el7.x86_64.rpm dracut-network-033-535.el7.x86_64.rpm libcom_err-1.42.9-12.el7_5.x86_64.rpm
libsepol-devel-2.5-8.1.el7.x86_64.rpm
systemd-219-57.el7.x86_64.rpm e2fsprogs-1.42.9-12.el7_5.x86_64.rpm
libcom_err-devel-1.42.9-12.el7_5.x86_64.rpm libss-1.42.9-12.el7_5.x86_64.rpm
systemd-libs-219-57.el7.x86_64.rpm e2fsprogs-libs-1.42.9-12.el7_5.x86_64.rpm
libgudev1-219-57.el7.x86_64.rpm
libverto-devel-0.2.5-4.el7.x86_64.rpm
systemd-python-219-57.el7.x86_64.rpm glib2-2.54.2-2.el7.x86_64.rpm
libkadm5-1.15.1-19.el7.x86_64.rpm
lz4-1.7.5-2.el7.x86_64.rpm
systemd-sysv-219-57.el7.x86_64.rpm initscripts-9.49.41-1.el7.x86_64.rpm
libselinux-2.5-12.el7.x86_64.rpm
openssl-1.0.2k-12.el7.x86_64.rpm
zlib-1.2.7-17.el7.x86_64.rpm keyutils-libs-devel-1.5.8-3.el7.x86_64.rpm
libselinux-devel-2.5-12.el7.x86_64.rpm
openssl-devel-1.0.2k-12.el7.x86_64.rpm
zlib-devel-1.2.7-17.el7.x86_64.rpm kmod-20-21.el7.x86_64.rpm
libselinux-python-2.5-12.el7.x86_64.rpm
openssl-libs-1.0.2k-12.el7.x86_64.rpm 在/home下创建openssl目录 [root@localhost home]# mkdir openssl 将RPM包上传到/home/openssl下 [root@localhost home]# rpm *.rpm --nodeps 忽略的是升级centos版本到7.5

升级openssh需要的RPM包 libsemanage-2.5-11.el7.x86_64.rpm
openssh-server-7.4p1-16.el7.x86_64.rpm
selinux-policy-targeted-3.13.1-192.el7_5.3.noarch.rpm openssh-7.4p1-16.el7.x86_64.rpm
policycoreutils-2.5-22.el7.x86_64.rpm openssh-clients-7.4p1-16.el7.x86_64.rpm
selinux-policy-3.13.1-192.el7_5.3.noarch.rpm 在/home下创建openssh目录 [root@localhost home]# mkdir openssh 将RPM包上传到/home/openssh下 [root@localhost home]# rpm *.rpm 升级完成重启 [root@localhost ssh]# ssh -V OpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017