Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1204375 - squid sends incorrect ssl chain breaking newer gnutls using applications
squid sends incorrect ssl chain breaking newer gnutls using applications
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: squid (Show other bugs)
7.1
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Luboš Uhliarik
Ondřej Pták
: Patch
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-03-21 09:17 EDT by Kevin Fenzi
Modified: 2017-05-17 06:20 EDT (History)
5 users (show)

See Also:
Fixed In Version: squid-3.3.8-13.el7
Doc Type: Bug Fix
Doc Text:
Cause: SSL certificate is received twice from Squid. Consequence: SSL negotiation is failing for some client applications. Fix: SSL certificate is sent only once. Result: SSL client applications are not failing anymore.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-11-19 07:20:29 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
This is a backported patch which should fix bug #1204375 (2.35 KB, patch)
2015-04-07 04:56 EDT, Luboš Uhliarik
no flags Details | Diff
SRPM of squid containing patch (2.15 MB, application/x-rpm)
2015-04-07 07:37 EDT, Luboš Uhliarik
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:2378 normal SHIPPED_LIVE Moderate: squid security and bug fix update 2015-11-19 05:51:27 EST

  None (edit)
Description Kevin Fenzi 2015-03-21 09:17:44 EDT
This bug: 

http://bugs.squid-cache.org/show_bug.cgi?id=3849

was fixed upstream, but doesn't seem to be in the current RHEL7 squid package. 

This means if you use ssl with a cert chain, any clients using newer gnutls will be unable to use your proxy. ;( 

We have hit this with a proxy in Fedora, see: https://fedorahosted.org/fedora-infrastructure/ticket/4682 

Please consider backporting this fix. Thanks.
Comment 2 Luboš Uhliarik 2015-04-07 04:56:45 EDT
Created attachment 1011660 [details]
This is a backported patch which should fix bug #1204375
Comment 3 Luboš Uhliarik 2015-04-07 05:00:42 EDT
Hi Kevin,

which version of squid and RHEL are you exactly using? I backported this patch, for the latest squid (3.3.8) in RHEL 7.1. I'm attaching the PATCH, so you can try, if it fixes this bug in your squid configuration.
Comment 5 Luboš Uhliarik 2015-04-07 07:37:55 EDT
Created attachment 1011700 [details]
SRPM of squid containing patch
Comment 6 Kevin Fenzi 2015-04-07 14:02:59 EDT
We can confirm this fixes the issue. ;) Thanks!
Comment 12 errata-xmlrpc 2015-11-19 07:20:29 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-2378.html

Note You need to log in before you can comment on or make changes to this bug.