Hide Forgot
Description of problem: When configuring crypto-policy to enable or disable algorithms, configuration files that don't end with two consecutive new-line characters are ignored by NSS. Version-Release number of selected component (if applicable): nss-util-3.27.1-2.el6. How reproducible: Always Steps to Reproduce: cat > /etc/pki/nss-legacy/nss-rhel6.config <<EOF library= name=Policy NSS=flags=policyOnly,moduleDB config="allow=md5" EOF' Connect to server that uses MD5 certificates Actual results: Connection is aborted Expected results: Connection succeeds, server certificate is validated Additional info: Marking as medium as this kind of newline sensitivity is uncommon and unexpected, making silent misconfigurations likely.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2017-0671.html