# Updating OpenSSL via Debian package

**URL:** <https://hub.mender.io/t/updating-openssl-via-debian-package/7982>\
**Category:** General Discussions\
**Tags:** debian, update-modules\
**Created:** [September 2, 2025, 6:59am UTC](https://hub.mender.io/t/updating-openssl-via-debian-package/7982 "2025-09-02T06:59:30Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dylan](https://avatars.discourse-cdn.com/v4/letter/d/e95f7d/32.png) [@Dylan](https://hub.mender.io/u/Dylan)\
**Post date:** [September 2, 2025, 6:59am UTC](https://hub.mender.io/t/updating-openssl-via-debian-package/7982/1 "2025-09-02T06:59:30Z")

</div>

OTA updates are divided into **package-based** and **image-based** models. The image-based approach supports rollback through A/B partitions, whereas the package-based model installs `.deb` files directly on the active A partition, and its rollback mechanism also operates within the current A partition. It does not require image-based updates. Is my understanding correct?

There is a special case: for example, when installing a component like OpenSSL, a failure could break network connectivity, making it impossible to reach the device. For this kind of risk, should we choose the image-based approach to install OpenSSL?
