Bug 158703
Summary: | certwatch incorrectly compares current time to UTC times in certificates | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Alexandre Oliva <oliva> | ||||
Component: | crypto-utils | Assignee: | Joe Orton <jorton> | ||||
Status: | CLOSED RAWHIDE | QA Contact: | |||||
Severity: | low | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | 4 | CC: | tmraz | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | 2.2-6 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2005-05-26 09:01:58 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Alexandre Oliva
2005-05-24 23:51:37 UTC
What is the mtime of the localhost.crt file? And what is the Not Before value printed by openssl x509 -text -in /etc/pki/tls/certs/localhost.crt? Not Before: May 24 02:26:17 2005 GMT -rw------- 1 root root 1334 May 23 23:26 /etc/pki/tls/certs/localhost.crt Seems about right... This should place it in the middle of the install. Could it be that certwatch is checking the UTC time in the certificate against localtime? In case it's not obvious, I've collected the data in my previous comment on a box different from the one that I used when preparing the original report. Both of them (and, in fact, all but one of the 6 boxes I've recently installed) had this problem. The one that didn't have the problem is one that takes 5+ hours to install, so this might explain why. This is a certwatch flaw - it incorrectly compares mktimed time (UTC) from the certificate to current time() value. Created attachment 114854 [details]
Proposed patch
This should fix it.
Thanks a lot Tomas, added in 2.2-6. |