Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1396985 - dhcpd only supports insecure HMAC-MD5 algorhitm for DDNS
dhcpd only supports insecure HMAC-MD5 algorhitm for DDNS
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: dhcp (Show other bugs)
7.3
Unspecified Unspecified
medium Severity medium
: rc
: ---
Assigned To: Pavel Zhukov
Release Test Team
Ioanna Gkioka
: FutureFeature, Patch
Depends On:
Blocks: 1465887 1465928
  Show dependency treegraph
 
Reported: 2016-11-21 05:29 EST by Tuomo Soini
Modified: 2018-04-10 04:01 EDT (History)
7 users (show)

See Also:
Fixed In Version: dhcp-4.2.5-61.el7
Doc Type: Release Note
Doc Text:
`DDNS` now supports additional algorithms Previously, the `dhcpd` daemon supported only the `HMAC-MD5` hashing algorithm which is considered insecure for critical applications. As a consequence, the `Dynamic DNS (DDNS)` updates were potentially insecure. This update adds support for additional algorithms: `HMAC-SHA1`, `HMAC-SHA224`, `HMAC-SHA256`, `HMAC-SHA384`, or `HMAC-SHA512`.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-04-10 04:00:52 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Backported upstream fix (3.77 KB, text/plain)
2016-11-21 05:29 EST, Tuomo Soini
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0658 None None None 2018-04-10 04:01 EDT

  None (edit)
Description Tuomo Soini 2016-11-21 05:29:55 EST
Created attachment 1222357 [details]
Backported upstream fix

dhcp-4.2.5-47.el7 only supports known to be insecure HMAC-MD5 algorhitm for dynamic dns upates. I'd suggest backporting upstream fix which add support for HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512.

From e4a2cb79b2679738f56b3803a44c9899f6982c09 Mon Sep 17 00:00:00 2001
From: Thomas Markwalder <tmark@isc.org>
Date: Mon, 8 Sep 2014 11:41:44 -0400
Subject: [PATCH] [v4_2] Addes addtional HMAC TSIG algorithms to DDNS

    Merges in rt36947
Comment 12 Tuomo Soini 2018-01-24 15:35:38 EST
Fix for Doc Text: "HMAC-MD5" - not MD5.
Comment 13 Ioanna Gkioka 2018-01-25 03:09:46 EST
Fixed. The Doc text updated. Thanks, Tuono.
Comment 16 errata-xmlrpc 2018-04-10 04:00:52 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0658

Note You need to log in before you can comment on or make changes to this bug.