Bug 1294606 - certutil fails to merge SQL databases after modifying trust in a certificate
certutil fails to merge SQL databases after modifying trust in a certificate
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: nss-util (Show other bugs)
6.7
All Linux
medium Severity medium
: rc
: ---
Assigned To: Bob Relyea
Hubert Kario
:
Depends On:
Blocks: 1269194 1343211 1294607
  Show dependency treegraph
 
Reported: 2015-12-29 03:58 EST by Pavel Moravec
Modified: 2017-03-21 06:25 EDT (History)
7 users (show)

See Also:
Fixed In Version: nss-3.27.1-3.el6
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1294607 (view as bug list)
Environment:
Last Closed: 2017-03-21 06:25:57 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Mozilla Foundation 1282627 None None None 2016-08-17 14:20 EDT

  None (edit)
Description Pavel Moravec 2015-12-29 03:58:14 EST
Description of problem:
Having sql database with a certificate that has modified a trust attribute and trying to merge this db with another one, it fails with error:

certutil: Could not merge object unnamed (type Trust): Unknown code ___P 3


Version-Release number of selected component (if applicable):
nss-tools-3.19.1-3.el6_6.x86_64


How reproducible:
100%


Steps to Reproduce:
rm -rf db1 db2
mkdir db1
echo 123456 > db1/pwdfile
certutil -N -d sql:./db1 -f ./db1/pwdfile
certutil -A -d sql:./db1 -i test.crt -n test -t P,, -f ./db1/pwdfile
certutil -M -d sql:./db1 -n test -t T,, -f ./db1/pwdfile

mkdir db2
echo 123456 > db2/pwdfile
certutil -N -d sql:./db2 -f ./db2/pwdfile

certutil --merge -d sql:./db2  --source-dir sql:./db1 -f ./db2/pwdfile -@ ./db1/pwdfile


Actual results:
certutil --merge fails with:
certutil: Could not merge object unnamed (type Trust): Unknown code ___P 3


Expected results:
certutil --merge works well


Additional info:
commenting out "certutil -M" or replacing it by deletion and re-creating test's certificate prevents this bug. I.e. the problem originates in certutil modifying the trust attributes. Therefore either:
- this "-M" operation is the buggy one, 
- or at least it leaves the sql database in such (valid) state that --merge operation cant cope with
Comment 11 Kai Engert (:kaie) 2016-10-27 15:12:57 EDT
This package was reported against the nss-util package, but the fix modified the nss package (not nss-util).
Comment 15 errata-xmlrpc 2017-03-21 06:25:57 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHEA-2017-0671.html

Note You need to log in before you can comment on or make changes to this bug.