Hide Forgot
We should consider to stop trusting the legacy CAs in RHEL 7, in order to increase security, and to restore alignment with the Mozilla CA list by default. The original motiviation for having introduced the legacy CA trust is described at https://fedoraproject.org/wiki/CA-Certificates and which was added to RHEL 7.2 with bug 1200934. This work requires that other software in RHEL gets updated to work without having to trusted the legacy CAs. GnuTLS has already been fixed in an earlier RHEL release. OpenSSL intends to rebase to version 1.0.2 which contains the required fixes. Another affected software is glib-networking. It's currently undecided if it can be rebased to include a fix, or if it should block this removal initiative. If agreed to do, as a result, the legacy CA list in RHEL 7.4 would be changed to be "empty".
*** Bug 1335930 has been marked as a duplicate of this bug. ***
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2073