Mike#1,
Can you comment on whether X2Go is affected by this vulnerability? I am not sure how the session brokers handles certs for HTTPS.
https://www.openssl.org/news/secadv_20150709.txt
The research I did for Heartbleed may be relevant: http://wiki.x2go.org/doku.php/security:cve-announcements:heartbleed?further_details_not_posted_to_the_x2go-announcement_list
-Mike#2