RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1335097 - openssl contains time bomb
Summary: openssl contains time bomb
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: openssl
Version: 6.8
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: rc
: ---
Assignee: Tomas Mraz
QA Contact: Stanislav Zidek
URL:
Whiteboard:
Depends On:
Blocks: 1269194 1343211
TreeView+ depends on / blocked
 
Reported: 2016-05-11 11:05 UTC by Tuomo Soini
Modified: 2020-05-14 15:11 UTC (History)
12 users (show)

Fixed In Version: openssl-1.0.1e-48.el6_8.3
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-03-21 10:11:14 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
This patch updates the expired certificates. (42.72 KB, patch)
2016-07-12 09:19 UTC, Tomas Mraz
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:0660 0 normal SHIPPED_LIVE openssl bug fix update 2017-03-21 12:33:58 UTC

Description Tuomo Soini 2016-05-11 11:05:54 UTC
openssl-1.0.1e-48.el6 and openssl-1.0.1e-48.el6_8.1 both contains time bomb and they can't be rebuild any more because certificates in tests have been expired at 2016-05-10.

perl cms-test.pl
CMS => PKCS#7 compatibility tests
signed content DER format, RSA key: verify error
make: Leaving directory `/builddir/build/BUILD/openssl-1.0.1e/test'
make: *** [test_cms] Error 1

I suggest quick fix so you can continue providing security fixes for openssl.

Reference:

https://groups.google.com/forum/#!topic/mailing.openssl.dev/d1q9rY6KFtk

Comment 2 Robert Scheck 2016-05-11 22:12:53 UTC
I run into the same issue while backporting the openssl-1.0.1e-48.el6_8.1
changes to openssl101e for EPEL 5. The following upstream patch solves the
issue for me and applied without manual merging:

http://pkgs.fedoraproject.org/cgit/rpms/openssl101e.git/tree/openssl-1.0.1e-update-test-certs.patch?h=el5

Comment 3 Fedora Update System 2016-05-11 23:46:03 UTC
openssl101e-1.0.1e-8.el5 has been submitted as an update to Fedora EPEL 5. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-92e8b90065

Comment 4 Fedora Update System 2016-05-12 21:18:32 UTC
openssl101e-1.0.1e-8.el5 has been pushed to the Fedora EPEL 5 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-92e8b90065

Comment 5 Robert Scheck 2016-05-12 21:21:46 UTC
Sorry, I didn't want to hijack this RHBZ, removed the RHBZ from my update.

Could somebody please reset the state to NEW? Because this one is for the
OpenSSL as shipped by RHEL - thanks!

Comment 6 Rajesh RJ 2016-05-18 16:58:49 UTC
we hit the  smime-certs  expired issue with our rpm build process . We were using 
openssl-1.0.0-20.el6_2.5.src.rpm for our rpm builds.

Do we know when an rpm patch will be available with the updated certs ?

Thanks.

Comment 7 Tomas Mraz 2016-05-18 22:30:15 UTC
Rajesh, do you mean updated package for RHEL-6.2 EUS? Please request any such updates via the support channels.

Comment 8 Rajesh RJ 2016-05-19 02:32:39 UTC
Thomas,

I' am looking for the updated source rpm for CentOS as our rpm build gets source RPM from centos.org. I raised this issue with centos.org when I noticed this issue (https://bugs.centos.org/view.php?id=10843).

Comment 9 manuel wolfshant 2016-05-19 08:37:07 UTC
openssl-1.0.0-20.el6_2.5.src.rpm  looks like an EUS package and those are NOT available for people without a proper RHEL subscription.

Comment 13 Tomas Mraz 2016-07-12 09:19:52 UTC
Created attachment 1178815 [details]
This patch updates the expired certificates.

Comment 22 errata-xmlrpc 2017-03-21 10:11:14 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2017-0660.html


Note You need to log in before you can comment on or make changes to this bug.