Bug 1320982

Summary: ASSERT failure in gnutls-cli-debug
Product: Red Hat Enterprise Linux 6 Reporter: Alicja Kario <hkario>
Component: gnutlsAssignee: Nikos Mavrogiannopoulos <nmavrogi>
Status: CLOSED ERRATA QA Contact: Alicja Kario <hkario>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.8CC: szidek
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: gnutls-2.12.23-8.el6 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-03-21 09:02:54 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1339222, 1343211    

Description Alicja Kario 2016-03-24 12:15:45 UTC
Description of problem:
When using gnutls-cli-debug to look at a openssl server, the application crashes

Version-Release number of selected component (if applicable):
gnutls-2.8.5-19.el6_7.x86_64
gnutls-utils-2.8.5-19.el6_7.x86_64

How reproducible:
Always

Steps to Reproduce:
1. openssl req -x509 -newkey rsa -keyout localhost.key -out localhost.crt -nodes -batch -subj /CN=localhost
2. openssl s_server -cert localhost.crt -key localhost.key
3. gnutls-cli-debug -d 100 -p 4433 localhost4

Actual results:
Resolving 'localhost'...
Connecting to '127.0.0.1:4433'...
|<2>| ASSERT: gnutls_priority.c:812
Error in %INITIAL_SAFE_RENEGOTIATION
Checking for Safe renegotiation support...

Expected results:
test successful, application not aborted

Additional info:
Disabling TLS1.2 support or enabling legacy renegotiation on server side doesn't make a difference

Comment 2 Nikos Mavrogiannopoulos 2016-08-09 12:25:34 UTC
This is addressed by the 2.12.x rebase

Comment 10 errata-xmlrpc 2017-03-21 09:02:54 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2017-0574.html