Latest Stories

Ohai Chefs, Last Tuesday 04-08-2014 7:12 PM, we released Chef Client 11.12.0 which contained 3 regressions (CHEF-5198, CHEF-5199 and OHAI-562). Subsequently, we released a new version of Chef Client which addressed these issues on Wednesday 04-09-2014 6:28 PM.

Ohai Chefs! As most of you are already aware, the OpenSSL Heartbleed bug has exposed a giant hole in the security of the Internet over the past few days.

Hello! We are pleased to announce the release of a new version of the Management Console for Enterprise Chef 11, 1.3.1. Please contact support@getchef.com for details on obtaining this release. Security Updates Update OpenSSL (CVE-2014-0160) Update Rack::SSL (CVE-2014-2538) Update libyaml (CVE-2014-2525) About the OpenSSL Update OpenSSL was updated to 1.0.1g to address The Heartbleed Bug.

Nathan Smith

I’m continuing my blog series on enterprise IT being too slow for business today. There are no half measures when it comes to automating a company’s technology. This post explains why. Automation is a prerequisite for success today. There is simply no way of getting around it.

Barry Crist

Ohai folks, We have had 3 regressions for the Chef Client 11.12.0 release that we’ve shipped on Tuesday: CHEF-5198 – Content Length Mismatch against gzip url CHEF-5199 – Unable to preform cookbook upload with any cookbook that has “return” in it. OHAI-562 – Reloading v6 plugins in chef fails (a.k.a.

Ohai Chefs, Yesterday (2014-04-08) at 22:39 UTC to 23:16 UTC, Hosted Enterprise Chef search API requests were returning 502 HTTP response codes. One of the “killer features” of using a Chef Server is the search capability, so I know many of our customers rely on that API.

Joshua Timberman

Ohai Chefs! Today we’re releasing patched versions of Open Source Chef Server and Enterprise Chef that address the OpenSSL security vulnerability CVE-2014-0160, also known as Heartbleed. We recommend that you upgrade your Chef Server install immediately.

Enterprise Chef 1.4.9 is a security release that includes an updated version of OpenSSL that patches CVE-2014-0160, also known as the Heartbleed bug. All installs of Enterprise Chef should be upgraded immediately. The result of this bug is a trivial exploit that allows an attacker to read secrets from the memory of a compromised server.

Enterprise Chef 11.1.3 is a security release that includes an updated version of OpenSSL that patches CVE-2014-0160, also known as the Heartbleed bug. All installs of Enterprise Chef should be upgraded immediately. The result of this bug is a trivial exploit that allows an attacker to read secrets from the memory of a compromised server.