Bug 1025598

Summary: Openssl advertises support for curves it doesn't actually support in Client Hello
Product: Red Hat Enterprise Linux 6 Reporter: Jan Kurik <jkurik>
Component: opensslAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Alicja Kario <hkario>
Severity: urgent Docs Contact:
Priority: high    
Version: 6.6CC: chorn, hkario, jsvarova, ksrot, ltroan, pm-eus, pm-rhel, sforsber, sgrubb, tmraz
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openssl-1.0.1e-16.el6_5 Doc Type: Bug Fix
Doc Text:
Prior to this update, the Transport Layer Security (TLS) client advertised support for some elliptic curves that are not supported by it. As a consequence, server could choose unsupported elliptic curve and client would not be able to communicate with the server over the TLS. With this update, OpenSSL TLS client advertises only the curves that are supported by it, and TLS communication with server (using also curves not supported by the Red Hat Enterprise Linux OpenSSL TLS client) can now be established.
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-22 00:25:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1022468    
Bug Blocks:    

Description Jan Kurik 2013-11-01 03:49:32 UTC
This bug has been copied from bug #1022468 and has been proposed
to be backported to 6.5 z-stream (EUS).

Comment 12 errata-xmlrpc 2013-11-22 00:25:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1751.html