Back to bug 746118

Who When What Removed Added
Dave Malcolm 2011-10-14 19:33:49 UTC CC lmacken
Tomas Pelka 2011-10-14 21:10:45 UTC CC tpelka
Jeremy West 2011-10-28 16:53:50 UTC Priority unspecified medium
CC jwest
Severity unspecified medium
Siddharth Nagar 2012-07-17 03:53:46 UTC Blocks 782183
Ranjith Rajaram 2013-02-19 07:42:27 UTC CC rrajaram
Dave Malcolm 2013-04-12 16:38:05 UTC Assignee dmalcolm python-maint
Jan Pokorný [poki] 2013-06-27 17:39:44 UTC See Also https://bugzilla.redhat.com/show_bug.cgi?id=956360
Jan Pokorný [poki] 2013-06-27 18:41:25 UTC Status NEW ASSIGNED
CC jpokorny
Assignee python-maint jpokorny
Fabio Massimo Di Nitto 2013-06-27 19:51:57 UTC Priority medium high
CC fdinitto
Severity medium high
Jan Pokorný [poki] 2013-07-15 21:51:48 UTC Priority high medium
Severity high medium
Jan Pokorný [poki] 2013-07-15 21:55:23 UTC Priority medium high
Severity medium high
Jan Pokorný [poki] 2013-08-05 14:24:11 UTC Blocks 956360
Jan Pokorný [poki] 2013-08-05 21:42:31 UTC Status ASSIGNED POST
John Harrigan 2013-08-08 19:26:35 UTC CC jharriga
Ales Zelinka 2013-08-20 09:49:15 UTC CC azelinka
QA Contact desktop-qa-list qe-baseos-daemons
Jan Pokorný [poki] 2013-08-20 20:32:01 UTC Status POST MODIFIED
Fixed In Version python-weberror-0.10.2-2.el6
Doc Text Cause:
WebError, a middleware handling web application's errors, used to yield
unique error identification as purpose-specific encoding of MD5 digest
of traceback-based inputs. Nowadays, this algorithm is discouraged, and
in turn implicitly refused by Python's runtime in case of FIPS mode.

Consequence:
Some web applications using Beaker for sessions handling may not work
correctly under FIPS mode.

Fix:
In parallel with upstream development, pragmatic approach to session
identification is applied -- the value is not generated automatically,
avoiding the possible failure in FIPS mode when not needed.
Applications relying on this value are still not compatible with FIPS
in favor of backward compatibility.

Result:
Unless explicitly required, WebError no longer actively computes MD5
digest, so in such case, the errors handling in respective web
applications does not suffer in FIPS mode.
errata-xmlrpc 2013-08-23 20:58:33 UTC Status MODIFIED ON_QA
Jan Pokorný [poki] 2013-08-23 21:36:06 UTC Doc Text Cause:
WebError, a middleware handling web application's errors, used to yield
unique error identification as purpose-specific encoding of MD5 digest
of traceback-based inputs. Nowadays, this algorithm is discouraged, and
in turn implicitly refused by Python's runtime in case of FIPS mode.

Consequence:
Some web applications using Beaker for sessions handling may not work
correctly under FIPS mode.

Fix:
In parallel with upstream development, pragmatic approach to session
identification is applied -- the value is not generated automatically,
avoiding the possible failure in FIPS mode when not needed.
Applications relying on this value are still not compatible with FIPS
in favor of backward compatibility.

Result:
Unless explicitly required, WebError no longer actively computes MD5
digest, so in such case, the errors handling in respective web
applications does not suffer in FIPS mode.
Cause:
WebError, a middleware handling web application's errors, used to yield
unique error identification as purpose-specific encoding of MD5 digest
of traceback-based inputs. Nowadays, this algorithm is discouraged, and
in turn implicitly refused by Python's runtime in case of FIPS mode.

Consequence:
Some web applications using WebError may not work correctly upon risen
exception under FIPS mode.

Fix:
In parallel with upstream development, pragmatic approach to session
identification is applied -- the value is not generated automatically,
avoiding the possible failure in FIPS mode when not needed.
Applications relying on this value are still not compatible with FIPS
in favor of backward compatibility.

Result:
Unless explicitly required, WebError no longer actively computes MD5
digest, so in such case, the errors handling in respective web
applications does not suffer in FIPS mode.
errata-xmlrpc 2013-09-18 13:28:17 UTC Status ON_QA VERIFIED
Jan Ščotka 2013-09-18 14:21:11 UTC CC jscotka
errata-xmlrpc 2013-11-21 23:53:01 UTC Status VERIFIED CLOSED
Resolution --- ERRATA
Last Closed 2013-11-21 18:53:01 UTC

Back to bug 746118