On October 14, 2014, a vulnerability was publicly announced in the Secure Sockets Layer version 3 (SSLv3) protocol when using a block cipher in Cipher Block Chaining (CBC) mode that may affect EMC Isilon OneFS customers.
The following release contains the resolution to this issue:
EMC Isilon OneFS 7.1.1.2
EMC recommends that all customers running versions prior to 7.1.1.2 upgrade to the version listed above at the earliest opportunity.
Isilon Engineering is continuing to develop fixes for the other code branches. This ESA will be updated when fixes are available for additional versions.
Note: The following versions of EMC Isilon OneFS will not be remediated:
EMC Isilon OneFS 6.5.x
EMC Isilon OneFS 7.0.1.x
EMC Isilon OneFS 7.1.0.x
I am trying to understand if version 7.1.0.x will be patched at some point ?
No, 7.1.0.x is not slated to receive a patch for this issue, at present. I believe 7.0.2.x and 7.2.0.x are slated to receive a fix in a future maintenance release. I can't speak to why 7.1.0.x was omitted.
i am rasing a stink about this with my sales team. By refusing to patch the 7.1.0.x version you are effectively saying you not supporting that version ?
While I don't have control over patch releases, I have begun a discussion with a colleague who's in the know to try to find out why 7.1.0.x isn't on the list. Please stay tuned...
fresh of the press, the latest copy of "EMC Software Release and End of Service Life Notifications". Does anyone else think it's a problem that Isilon refuses to support their product ?
Let me clarify some of the conversation that has been happening on this thread - I work within the Product Management team on EMC Isilon.
As a direct answer to the original question, you should work with support to request a 7.1.0.x patch for the specific vulnerability. We make calls on doing patches based on a bunch of circumstances (severity of the issue, ability to patch - sometimes a vulnerability cannot be patched, broadness of applicability etc). We fully support 7.1.0.x. For this specific instance, just the timing of the issue was such that it didn't allow us to patch 7.1.0.x releases and there isnt a set date for the patch.
Now going to a more general discussion so that there is clarity around how we think about releases. In Isilon parlance, let's understand what major and minor releases are. If we number a release 'a.b.c.d', for us, a major code family is a.b, and a minor code family is a.b.c. As an example, 7.1 is a major code release family and 7.1.0 or 7.1.1 are minor code release families within the 7.1 major families. Our general policy (and there are always exceptions as I described above) is that when a minor family reaches target code status, it succeeds all prior minor families. We continue to make changes and fixes to the target code branch. In general (and every customer has their set of constraints), we encourage customers to upgrade to the latest target code.
There are two rationales for doing this:
1. To enable customers to take advantage of the fixes we continually make
2. Efficiency from an engineering standpoint
So, when the prior posting says that 7.1.0 is not being fixed, that is an incomplete statement. We continue to make fixes on the 7.1 major release branch and specifically within the 7.1.1 minor code branch now that the latter has attained target code status. Of course, as I described earlier, you _always_ have the ability to request patches on a supported code branch through support.
Do let me know if there are follow on questions or concerns that I can help address. Thank you for being an EMC Isilon customer.
BernieC
76 Posts
832
0
Posted January 28th, 2015 00:00
No, 7.1.0.x is not slated to receive a patch for this issue, at present. I believe 7.0.2.x and 7.2.0.x are slated to receive a fix in a future maintenance release. I can't speak to why 7.1.0.x was omitted.