A security scan may return a flag for the following files on the r12.8.8.1 and Older SiteMinder Access Gateway Server:
LINUX
/<Install_Dir>/CA/secure-proxy/agentframework/CAPKI/CAPKI5/Linux/amd64/64/lib/libcaopenssl_ssl.so
/<Install_Dir>/CA/secure-proxy/agentframework/CAPKI/CAPKI5/Linux/amd64/64/lib/libcaopenssl_crypto.so
WINDOWS
/<Install_Dir>\CA\secure-proxy\agentframework\CAPKI\CAPKI5\Windows\amd64\64\lib\libcaopenssl_ssl.dll
/<Install_Dir>\CA\secure-proxy\agentframework\CAPKI\CAPKI5\Windows\amd64\64\lib\libcaopenssl_crypto.dll
CAPKI (Previously known as ETPKI) is a C language-based Software Development Kit (SDK) that provides CA Development Community with features required to implement Information Security services in its products. CAPKI is a wrapper on OpenSSL which is robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.
NOTE: SiteMinder r12.9 Access Gateway Server uses CAPKI 6. For CAPKI 6 on SiteMinder 12.9 use KB 453050 Vulnerability in OpenSSL 3.0.20 in CAPKI 6.0.3 and older on SiteMinder Access Gateway Server 12.9
PRODUCT: Symantec SiteMinder
COMPONENT: Access Gateway Server
VERSION: r12.8.8.1 and Older
OPERATING SYSTEM: Windows and Linux
CAPKI (Previously known as ETPKI) is a wrapper on OpenSSL. CAPKI 5.2.x is built with OpenSSL 1.0.2.
The SiteMinder Access Gateway Server ships with the following versions of CAPKI:
SiteMinder Access Gateway Server 12.8.7 uses CAPKI 5.2.11 which uses OpenSSL 1.0.2zf
SiteMinder Access Gateway Server12.8.8 uses CAPKI 5.2.13 which uses OpenSSL 1.0.2zi
SiteMinder Access Gateway Server12.8.8.1 uses CAPKI 5.2.13 which uses OpenSSL 1.0.2zj
KB427910 (archived) delivered CAPKI 5.2.16
KB409256 (archived) delivered CAPKI 5.2.17
KB441106 (archived) delivered CAPKI 5.2.18
CAPKI 5.2.18 and older are compiled with versions of OpenSSL 1.0.2zp and older which have vulnerabilities (CVE's) published.
Upgrade to CAPKI 5.2.20 on the SiteMinder Access Gateway using this KB.
CAPKI 5.2.20 has been compiled with OpenSSL 1.0.2zq.
This solution applies to the following SiteMinder Access Gateway Server versions:
LINUX
1) Download "etpki-install_5_2_20_linux.zip" from this KB.
2) Copy "etpki-install_5_2_20_linux.zip" to the SiteMinder Access Gateway Server on Linux and decompress it. This will create the directory /etpki-install/ in the same directory you placed "etpki-install_5_2_20_linux.zip"
3) Run the Access Gateway environment variable scripts
cd /<Install_Dir>/CA/secure-proxy
. ./ca_sps_env.sh
4) Verify the Access Gateway environment variables
echo $NETE_SPS_ROOT
echo $CAPKIHOME
5) Stop the Access Gateway Server
6) Change to the following directory:
cd $NETE_SPS_ROOT/agentframework/
7) Backup the '/CAPKI/' directory by renaming it '/CAPKI.BAK'
mv CAPKI CAPKI.BAK
8) Copy the '/etpki-install/' directory from "etpki-install_5_2_20_linux.zip" to $NETE_SPS_ROOT/agentframework/
9) Change to the following directory:
cd $NETE_SPS_ROOT/agentframework/etpki-install/redistrib/
10) Ensure the user has execute permissions on the installation media (setup)
11) Run the following command:
./setup install caller=sps12 instdir=$NETE_SPS_ROOT/agentframework/
12) Verify/Modify the $CAPKIHOME variable in the environment variable script:
/<Install_Dir>/CA/secure-proxy/ca_sps_env.sh
CAPKIHOME=$NETE_SPS_ROOT/agentframework/CAPKI
export CAPKIHOME
13) Run the updated Access Gateway Environment variable script.
cd /<Install_Dir>/CA/secure-proxy/
. ./ca_sps_env.sh
14) Start the Access Gateway Server
15) Validate Access Gateway Server functionality
16) Delete the following files:
$NETE_SPS_ROOT/agentframework/CAPKI.BAK
17) Check for the to the following directories:
/<Install_Dir>/CA/SharedComponents/CAPKI
/<Install_Dir>/CA/SC/CAPKI
NOTE: These directories may not exist in your system. If they do, you will need to determine which application is using them. If there are no other applications using these CAPKI instances, then they can be removed.
Siteminder Default: <Install_Dir>/CA/secure-proxy/agentframework/CAPKI
Directory Server Default: <Install_Dir>/CA/Directory/dxserver/lib/capki/
WINDOWS
1) Download "etpki-install_5_2_20_win64.zip" from this KB.
2) Copy "etpki-install_5_2_20_win64.zip" to the Access Gateway Server on Windows and decompress it. This will create the directory 'etpki-install' in the same directory you placed "etpki-install_5_2_20_win64.zip"
3) Stop the Access Gateway Server
4) Change to the following directory:
<Drive>:\<Install_Dir>\CA\secure-proxy\agentframework\ETPKI\
5) Backup the '\CAPKI\' directory by renaming it '\CAPKI.BAK\'
ren CAPKI CAPKI.BAK
6) Copy the 'etpki-install' directory from "etpki-install_5_2_20_win64.zip" to <Drive>:\<Install_Dir>\CA\secure-proxy\agentframework\ETPKI\
7) Open a command prompt using cmd.exe as an administrator (Run As Administrator)
8) Change to the following directory:
<Drive>:\<Install_Dir>\CA\secure-proxy\
9) Run the SiteMinder Access Gateway environment variable script
ca_sps_env.bat
10) Change to the following directory:
<Drive>:\<Install_Dir>\CA\secure-proxy\agentframework\ETPKI\etpki-install\redistrib\
11) Run the following command:
setup.exe install caller=sps12 instdir="%NETE_SPS_ROOT%\agentframework\install\"
NOTE: This will create the following directories:
'<Drive>:\<Install_Dir>\CA\secure-proxy\agentframework\ETPKI\CAPKI\CAPKI6\Windows\amd64\64\
12) Start the Access Gateway Server
13) Validate Access Gateway Server functionality
14) Delete the following files:
<Drive>:\<Install_Dir>\CA\secure-proxy\agentframework\ETPKI\CAPKI.BAK
15) Check for the to the following directories:
<Install_Dir>\CA\SharedComponents\CAPKI
<Install_Dir>\CA\SC\CAPKI
NOTE: These directories may not exist in your system. If they do, you will need to determine which application is using them. If there are no other applications using these CAPKI instances, then they can be removed.
SiteMinder Access Gateway Default: <Install_Dir>\CA\secure-prox\agentframework\CAPKI
SiteMinder Policy Server Default: <Install_Dir>\CA\siteminder\CAPKI
Symantec Directory Server Default: <Install_Dir>\CA\Directory\dxserver\lib\capki/
SiteMinder r12.9
KB 453050 Vulnerability in OpenSSL 3.0.20 in CAPKI 6.0.3 and older on SiteMinder Access Gateway Server 12.9
KB 452920 Vulnerabilities in OpenSSL 3.0.20 delivered in CAPKI 6.0.3 bundled with SiteMinder 12.9 Policy Server
SiteMinder r12.8.8.1 and Older
KB 453623 Vulnerability in OpenSSL 1.0.2zp and older in CAPKI 5.2.18 and older on SiteMinder 12.8.x Agent for Sharepoint
KB 453596 Vulnerability in OpenSSL 1.0.2zp and older in CAPKI 5.2.18 and older on SiteMinder Web Agents
KB 453595 Vulnerability in OpenSSL 1.0.2zp and older in CAPKI 5.2.18 and older on SiteMinder Access Gateway Server 12.8.8.1 and older
KB 453434 Vulnerability in OpenSSL 1.0.2zp and older in CAPKI 5.2.18 and older on SiteMinder Policy Server Server 12.8.8.1 and older
OpenSSL 1.0.2zq within CAPKI 5.2.20 remediates the following CVE's:
CVE-2026-34180
CVE-2026-42766
CVE-2026-45447
CVE-2026-7383
CVE-2026-9076
CVE-2026-28388
CVE-2026-28389
CVE-2026-28390
CVE-2026-68160
CVE-2025-69421
CVE-2025-22796
CVE-2025-9230
CVE-2024-13176
CVE-2024-9143
CVE-2024-5535
CVE-2024-0727
CVE-2023-5678
CVE-2023-3817
CVE-2023-3446
CVE-2023-2650
CVE-2023-0465
CVE-2023-0464
CVE-2023-0466
CVE-2022-4304
CVE-2023-0215
CVE-2023-0286