# Linux Tips

**URL:** <https://forums.plex.tv/t/linux-tips/276247>\
**Category:** Tips, Tricks & How-Tos\
**Tags:** server-linux-tips, server-linux, tipstricks\
**Created:** [June 26, 2018, 5:11pm UTC](https://forums.plex.tv/t/linux-tips/276247 "2018-06-26T17:11:57Z")\
**Posts on this page:** 1\
**Showing post:** 25

<div class="post-metadata">

**Author:** ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)\
**Post date:** [April 5, 2023, 1:53am UTC](https://forums.plex.tv/t/linux-tips/276247/25 "2023-04-05T01:53:43Z")

</div>

### OpenSSL v3.0.0 and PMS.

For those using their own domains and certificates with PMS ,

PMS 1.32.0.6865 and above updates OpenSSL from v1.1.1 to v3.0.0 .  
(changed the numbering scheme in the process)

The consequence of this is OpenSSL v3 removed several “less secure” encryption methods.

The impact on you, if you’re using an older distributions where openssl v3 is not the default, if not already doing so, you will need pay special attention to how your certificates are generated

As example, upgrade (specify) a better encryption

#### PREVIOUS

```auto
# Generate p12 (Acme LE is valid until 2025)
openssl pkcs12 -export -out my-fdqn-tld.p12 \
	-inkey my-fqdn-tld.key -in my-fqdn-tld.crt \
	-certfile CertAuth.crt \
	-password pass:PASSWORD_HERE

```

#### IMPROVED

```auto
# Generate new p12 (Acme LE is valid until 2025)
openssl pkcs12 -export -out my-fdqn-tld.p12 \
	-certpbe AES-256-CBC -keypbe AES-256-CBC -macalg SHA256 \
	-inkey my-fqdn-tld.key -in my-fqdn-tld.crt \
	-certfile CertAuth.crt \
	-password pass:PASSWORD_HERE

```

The key change is to select a better encryption:

> -certpbe AES-256-CBC -keypbe AES-256-CBC -macalg SHA256 \

### To implement

1. Update certificate creation scripting to include AES-256 (or better) as shown above.
2. Regenerate P12 file and store where PMS expects it
3. Restart PMS after updated cert installation ( PMS loads certs at startup only)

### The reason for this change is the inevitability of the current libraries being EOL.

Observe:

 ![Screenshot from 2023-04-05 16-15-59](https://global.discourse-cdn.com/plex/original/4X/4/6/1/46195836df68ddb513dd09109977402ebcfde2f4.png)

REF:

> **[OpenSSL](https://en.wikipedia.org/wiki/OpenSSL)**
>
> OpenSSL is a software library for applications that provide secure communications over computer networks against eavesdropping, and identify the party at the other end. It is widely used by Internet servers, including the majority of HTTPS websites.
> OpenSSL contains an open-source implementation of the SSL and TLS protocols. The core library, written in the C programming language, implements basic cryptographic functions and provides various utility functions. Wrappers allowing the use of the...

### [Back to top](https://forums.plex.tv/t/linux-tips/276247)

---

_[View the full topic](https://forums.plex.tv/t/linux-tips/276247)._
