Bug 1396985

Summary: dhcpd only supports insecure HMAC-MD5 algorhitm for DDNS
Product: Red Hat Enterprise Linux 7 Reporter: Tuomo Soini <tis>
Component: dhcpAssignee: Pavel Zhukov <pzhukov>
Status: CLOSED ERRATA QA Contact: Release Test Team <release-test-team>
Severity: medium Docs Contact: Ioanna Gkioka <igkioka>
Priority: medium    
Version: 7.3CC: jstodola, nmavrogi, pasik, pwouters, pzhukov, sbroz, thozza
Target Milestone: rcKeywords: FutureFeature, Patch
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: dhcp-4.2.5-61.el7 Doc Type: Release Note
Doc Text:
`DDNS` now supports additional algorithms Previously, the `dhcpd` daemon supported only the `HMAC-MD5` hashing algorithm which is considered insecure for critical applications. As a consequence, the `Dynamic DNS (DDNS)` updates were potentially insecure. This update adds support for additional algorithms: `HMAC-SHA1`, `HMAC-SHA224`, `HMAC-SHA256`, `HMAC-SHA384`, or `HMAC-SHA512`.
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-04-10 08:00:52 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 1465887, 1465928    
Attachments:
Description Flags
Backported upstream fix none

Description Tuomo Soini 2016-11-21 10:29:55 UTC
Created attachment 1222357 [details]
Backported upstream fix

dhcp-4.2.5-47.el7 only supports known to be insecure HMAC-MD5 algorhitm for dynamic dns upates. I'd suggest backporting upstream fix which add support for HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512.

From e4a2cb79b2679738f56b3803a44c9899f6982c09 Mon Sep 17 00:00:00 2001
From: Thomas Markwalder <tmark>
Date: Mon, 8 Sep 2014 11:41:44 -0400
Subject: [PATCH] [v4_2] Addes addtional HMAC TSIG algorithms to DDNS

    Merges in rt36947

Comment 12 Tuomo Soini 2018-01-24 20:35:38 UTC
Fix for Doc Text: "HMAC-MD5" - not MD5.

Comment 13 Ioanna Gkioka 2018-01-25 08:09:46 UTC
Fixed. The Doc text updated. Thanks, Tuono.

Comment 16 errata-xmlrpc 2018-04-10 08:00:52 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0658