Bug 1375751 - libreswan should fetch CRLs from EE, subCA and rootCA distributionpoints
Summary: libreswan should fetch CRLs from EE, subCA and rootCA distributionpoints
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: libreswan
Version: 7.4
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Paul Wouters
QA Contact: Ondrej Moriš
URL:
Whiteboard:
Depends On:
Blocks: 1377248
TreeView+ depends on / blocked
 
Reported: 2016-09-13 22:27 UTC by Paul Wouters
Modified: 2017-08-01 12:31 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-08-01 12:31:06 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:2101 0 normal SHIPPED_LIVE libreswan bug fix and enhancement update 2017-08-01 16:07:26 UTC

Description Paul Wouters 2016-09-13 22:27:19 UTC
Description of problem:
Currently. libreswan does not fetch CRLs defined oin intermediate CA certificates.

It should fetch CRLs from EE, subCA and rootCA CRLdistributionpoints 

Support for will be added upstream to libreswan-3.19

Comment 2 Paul Wouters 2017-02-07 18:46:36 UTC
this work was completed in upstream 3.19 and will come in via the rebase

Comment 4 Ondrej Moriš 2017-03-29 09:08:51 UTC
Paul, by any chance - is this tested upstream?

Comment 5 Paul Wouters 2017-04-04 14:59:05 UTC
unfortunately, I don't see a test case for it. It requires extending our test certificates.

Comment 6 Ondrej Moriš 2017-06-23 08:15:41 UTC
Verified SanityOnly. This should be tested in the future, unfortunately our testing PKI tools do not support intermediate CA at the time being.

Comment 7 errata-xmlrpc 2017-08-01 12:31:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:2101


Note You need to log in before you can comment on or make changes to this bug.