Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1150645 - Importing an RSA private key fails if p < q [rhel-7]
Importing an RSA private key fails if p < q [rhel-7]
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: nss-softokn (Show other bugs)
7.0
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Elio Maldonado Batiz
Hubert Kario
: Reopened
: 1146592 (view as bug list)
Depends On: 1165525
Blocks: 1167426 1167427
  Show dependency treegraph
 
Reported: 2014-10-08 11:03 EDT by Elio Maldonado Batiz
Modified: 2015-03-05 03:28 EST (History)
6 users (show)

See Also:
Fixed In Version: nss-softokn-3.16.2-7.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1167426 1167427 (view as bug list)
Environment:
Last Closed: 2015-03-05 03:28:38 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Change RSA_PrivateKeyCheck to not require p > q (5.08 KB, patch)
2014-10-08 11:05 EDT, Elio Maldonado Batiz
rrelyea: review+
Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Mozilla Foundation 1049435 None None None Never
Mozilla Foundation 1174527 None None None Never
Red Hat Product Errata RHBA-2015:0364 normal SHIPPED_LIVE nss, nss-softokn, nss-util, and nspr bug fix and enhancement update 2015-03-05 07:51:43 EST

  None (edit)
Description Elio Maldonado Batiz 2014-10-08 11:03:09 EDT
Description of problem: This problem was reprted upstream. For the original report see https://bugzilla.mozilla.org/show_bug.cgi?id=1049435#c0


Version-Release number of selected component (if applicable):

How reproducible: see above link

Steps to Reproduce: link anove

Actual results:
Following message will appear in dialog:
  The PKCS #12 operation failed for unknown reasons.
On the other hand,
* "openssl pkcs12" can extract key and certificates.
* "openssl verify" can verify signature in EE certificate.


Expected results:
Key and certificates should be imported.

Additional info:

From https://bugzilla.mozilla.org/show_bug.cgi?id=1049435#c42

The NSS change that broke this was in NSS 3.16.2. See
bug 1021102 and the two bugs named in bug 1021102 comment 0.
At that time I thought p > q was required, and any
incompatibility would be discovered quickly during testing
of mozilla-central nightly builds.
Comment 1 Elio Maldonado Batiz 2014-10-08 11:05:33 EDT
Created attachment 945050 [details]
Change RSA_PrivateKeyCheck to not require p > q

patch applied upstream https://hg.mozilla.org/projects/nss/rev/358730f7261d
Comment 2 Kai Engert (:kaie) (inactive account) 2014-10-09 16:33:07 EDT
*** Bug 1146592 has been marked as a duplicate of this bug. ***
Comment 20 errata-xmlrpc 2015-03-05 03:28:38 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2015-0364.html

Note You need to log in before you can comment on or make changes to this bug.