Bug 1119803
Summary: | ECC supported curves list extension is missing in DTLS1 client hello | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Tomas Mraz <tmraz> |
Component: | openssl | Assignee: | Tomas Mraz <tmraz> |
Status: | CLOSED ERRATA | QA Contact: | Hubert Kario <hkario> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 7.0 | CC: | hkario, jherrman, ksrot, qe-baseos-security |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | openssl-1.0.1e-37.el7 | Doc Type: | Bug Fix |
Doc Text: |
The TLS extensions that were sent in the Datagram TLS (DTLS) ClientHello requests did previously not contain the list of the supported elliptic curves. As a consequence, the DTLS connections to servers using elliptic curves not supported by the OpenSSL client were aborted. With this update, the elliptic curve list extension is properly sent in the DTLS ClientHello requests, and DTLS connections are no longer aborted in the above circumstances.
|
Story Points: | --- |
Clone Of: | 1119800 | Environment: | |
Last Closed: | 2015-03-05 11:03:44 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tomas Mraz
2014-07-15 14:41:55 UTC
*** Bug 1153331 has been marked as a duplicate of this bug. *** Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0478.html |