Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1390154 - SECMOD_OpenUserDB will allow multiple opens of the same database. [rhel-7]
SECMOD_OpenUserDB will allow multiple opens of the same database. [rhel-7]
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: nss (Show other bugs)
7.3
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Daiki Ueno
Hubert Kario
:
Depends On: 1387811
Blocks: 1352109 1378209 1425841 1425952
  Show dependency treegraph
 
Reported: 2016-10-31 06:38 EDT by Hubert Kario
Modified: 2017-08-01 12:47 EDT (History)
6 users (show)

See Also:
Fixed In Version: nss-3.28.3-4.el7
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1387811
Environment:
Last Closed: 2017-08-01 12:47:42 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Patch cleans up handling different login states when more than one token is in use (4.38 KB, patch)
2017-05-05 18:59 EDT, Bob Relyea
no flags Details | Diff
Add ecc defaults to nss util (1.87 KB, patch)
2017-05-05 19:23 EDT, Bob Relyea
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Mozilla Foundation 1312141 None None None 2016-10-31 06:38 EDT
Red Hat Product Errata RHEA-2017:1977 normal SHIPPED_LIVE nss bug fix and enhancement update 2017-08-01 13:57:47 EDT

  None (edit)
Description Hubert Kario 2016-10-31 06:38:09 EDT
+++ This bug was initially created as a clone of Bug #1387811 +++

Description of problem:
It's not always safe to have multiple instances of the same database open in the same process. Because of this, the NSS initialization code will automatically combine multiple database opens into a single one. There is another way, however, to open databases: SECMOD_OpenUserDB().

This multiple open combined with a bug in softoken leads to the issue in the slapd in FIPS mode described in bug https://bugzilla.redhat.com/show_bug.cgi?id=1352109.
Comment 3 Kai Engert (:kaie) (inactive account) 2016-11-15 07:39:43 EST
RHEL 7.4 will be rebased to NSS 3.28, which contains this bugfix.
Comment 16 Bob Relyea 2017-05-05 18:59 EDT
Created attachment 1276706 [details]
Patch cleans up handling different login states when more than one token is in use
Comment 18 Bob Relyea 2017-05-05 19:23 EDT
Created attachment 1276709 [details]
Add ecc defaults to nss util

This patch is relative to nss/lib/util . I think this code didn't make it upstream with the rest of the ECC default code.
Comment 20 mreynolds 2017-05-09 08:02:28 EDT
Created new bug as requested to track the new fix:

https://bugzilla.redhat.com/show_bug.cgi?id=1449195
Comment 23 errata-xmlrpc 2017-08-01 12:47:42 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:1977

Note You need to log in before you can comment on or make changes to this bug.