Red Hat Bugzilla – Bug 1158926
trust anchor complains about invalid attribute and fails when a new certificate tries to store into trust place
Last modified: 2017-08-01 12:52:09 EDT
Description of problem: "trust" won't add a new certificate into trust place when "anchor" option is used. It also drops error messages about invalid attributes. Version-Release number of selected component (if applicable): p11-kit-0.20.7-2.el7 How reproducible: Always Steps to Reproduce: 1. /etc/pki/tls/certs/make-dummy-cert mycert-tmp.pem 2. openssl x509 -in mycert-tmp.pem -addtrust clientAuth -addtrust serverAuth -addtrust emailProtection -out mycert.pem 3. trust anchor --store mycert.pem Actual results: p11-kit: the CKA_TRUSTED attribute is not valid for the object p11-kit: couldn't create object: Certain fields have invalid values Expected results: Certificate is stored in trust place. Additional info:
Created attachment 952149 [details] test certificate
https://github.com/ueno/p11-kit/commit/b22e0e6ee1bce61683883a1a8e79d06fba06ac6e
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2017:1981