Bug 1231960
Summary: | openssl update breaks mysql ssl | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Blake <blake.a.hudson> |
Component: | mysql | Assignee: | Michal Schorm <mschorm> |
Status: | CLOSED WONTFIX | QA Contact: | qe-baseos-daemons |
Severity: | high | Docs Contact: | |
Priority: | unspecified | ||
Version: | 5.11 | CC: | bgollahe, byte, databases-maint, dukrat, erinn.looneytriggs, hhorak, howey.vernon, huzaifas, it, jherrman, kvolny, leonard-rh-bugzilla, maurizio.antillon, qe-baseos-daemons, rwilliam, thoger, tlavigne, tmraz |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
With certain versions of OpenSSL, using SSL to log into a MySQL client as root previously failed with a "ERROR 2026 (HY000): SSL connection error" message. This update increases the Diffie-Hellman (DH) key length in MySQL from 512 to 1024 bits, which meets the DH key length requirements for these OpenSSL versions. As a result, SSL can be used as expected in the described scenario.
|
Story Points: | --- |
Clone Of: | 1228755 | Environment: | |
Last Closed: | 2017-04-18 21:53:56 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1232207 |
Description
Blake
2015-06-15 17:15:19 UTC
The latest OpenSSL updates for RHEL 5 breaks MySQL SSL connections between RHEL 5 servers now as well. Please see above. Please note that this does not have to do with logging in as root. This error occurs before authentication. Version-Release number of selected component (if applicable): mysql-server.x86_64 5.0.95-5.el5_9 mysql (client) 5.0.95-5.el5_9 openssl.x86_64 0.9.8e-36.el5_11 The MySQL package for RHEL 6 got fixed a week after the openssl update breaking DH got released. Three weeks after the one for RHEL 6 a similar openssl update for RHEL 5 gets released causing identical breakage. Perhaps the communication between the development teams for 5 and 6 could be improved? This issue seems to be stuck in the NEEDINFO state. What info do you need? Is an update of MySQL for RHEL 5 similar to the one released for RHEL 6 in the pipeline? As it is unclear what info is requested and this issue seems to be stuck I unset the needinfo flag in the hope this issue gets picked up and resolved. *** Bug 1272091 has been marked as a duplicate of this bug. *** Red Hat Enterprise Linux 5 shipped it's last minor release, 5.11, on September 14th, 2014. On March 31st, 2017 RHEL 5 exited Production Phase 3 and entered Extended Life Phase. For RHEL releases in the Extended Life Phase, Red Hat will provide limited ongoing technical support. No bug fixes, security fixes, hardware enablement or root-cause analysis will be available during this phase, and support will be provided on existing installations only. If the customer purchases the Extended Life-cycle Support (ELS), certain critical-impact security fixes and selected urgent priority bug fixes for the last minor release will be provided. For more details please consult the Red Hat Enterprise Linux Life Cycle Page: https://access.redhat.com/support/policy/updates/errata This BZ does not appear to meet ELS criteria so is being closed WONTFIX. If this BZ is critical for your environment and you have an Extended Life-cycle Support Add-on entitlement, please open a case in the Red Hat Customer Portal, https://access.redhat.com ,provide a thorough business justification and ask that the BZ be re-opened for consideration of an errata. Please note, only certain critical-impact security fixes and selected urgent priority bug fixes for the last minor release can be considered. |