Bug 1367434 (rhel7-remove-legacy-cas)
Summary: | No longer trust legacy CAs in RHEL 7.x | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Kai Engert (:kaie) (inactive account) <kengert> |
Component: | ca-certificates | Assignee: | Kai Engert (:kaie) (inactive account) <kengert> |
Status: | CLOSED ERRATA | QA Contact: | Alicja Kario <hkario> |
Severity: | unspecified | Docs Contact: | Mirek Jahoda <mjahoda> |
Priority: | unspecified | ||
Version: | 7.4 | CC: | alex.gaynor, bressers, carl, hannsj_uhl, hkario, jkoten, mcepl, mgrepl, nmavrogi, redhat-bugzilla, redhat-bugzilla, szidek, tpelka |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | ca-certificates-2017.2.11-73.el7 | Doc Type: | Deprecated Functionality |
Doc Text: |
Previously, to allow older versions of the GnuTLS, OpenSSL and glib-networking libraries to remain compatible with the public web PKI, the ca-certificates package had included a set of legacy CA certificates with 1024-bit RSA keys as trusted by default, although Mozilla had already deprecated them.
Because RHEL 7.4.0 contains updated versions of the OpenSSL, GnuTLS and glib-networking libraries, which are able to correctly identify the replacement root CA certificates, trusting these legacy CA certificates is no longer required to be compatible with the public web PKI.
This update ca-certificates package removes the legacy CA certificates.
The legacy configuration mechanism, which could previously be used to disable the legacy CA certificates, has no longer an effect with this updated ca-certificates package, because the list of legacy CA certificates has been changed to be empty.
The ca-certificates packages continues to ship the ca-legacy tool and will keep the current configuration settings, to potentially be reused in the future.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-08-01 21:05:27 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1276310, 1367484, 1386616, 1386848 | ||
Bug Blocks: | 1335929, 1377248 |
Description
Kai Engert (:kaie) (inactive account)
2016-08-16 11:53:07 UTC
*** Bug 1335930 has been marked as a duplicate of this bug. *** Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2073 |