Bug 1425972
| Summary: | Simple problem unwrapping AES sym keys on token | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Matthew Harmsen <mharmsen> |
| Component: | jss | Assignee: | Jack Magne <jmagne> |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.4 | CC: | aakkiang, cfu, edewata, emaldona, extras-qa, jmagne, kwright, mharmsen, nkinder, rmeggins, rpattath, spoore |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | jss-4.2.6-44.el7 | Doc Type: | No Doc Update |
| Doc Text: |
This problem was discovered in development. No need to alert people to a problem they never knew existed.
|
Story Points: | --- |
| Clone Of: | 1425971 | Environment: | |
| Last Closed: | 2017-08-01 22:32:03 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1425971, 1455617, 1458043 | ||
| Bug Blocks: | |||
|
Description
Matthew Harmsen
2017-02-22 22:30:50 UTC
Matthew, How can we test this? Thanks, Scott (In reply to Scott Poore from comment #2) > Matthew, > > How can we test this? > > Thanks, > Scott Soctt, The JSS component is generally tested as a part of the Dogtag PKI tests, not standalone by itself. CC'ing aakkiang on this bug so that she can provide you with the PKI test that should verify this. -- Matt Asha, It sounds like this should just be verified per your normal procedures? I think I had misinterpreted it as something we needed to test with IPA and the Smart Card testing. Thanks, Scott Scott, Yeah, CS QE normal testing procedure should verify this. Changing QE contact info. Thanks, Asha This bug cannot be verified unless Can be verified only after https://bugzilla.redhat.com/show_bug.cgi?id=1458043 is verified [root@nocp1 ~]# rpm -qi jss Name : jss Version : 4.4.2 Release : 2.fc27 Architecture: x86_64 Install Date: Wed 07 Jun 2017 10:37:30 PM EDT Group : System Environment/Libraries Size : 1030404 License : MPLv1.1 or GPLv2+ or LGPLv2+ Signature : (none) Source RPM : jss-4.4.2-2.fc27.src.rpm Build Date : Wed 07 Jun 2017 10:26:46 PM EDT Build Host : f25-2.ipa.local Relocations : (not relocatable) URL : http://www.mozilla.org/projects/security/pki/jss/ Summary : Java Security Services (JSS) [root@nocp1 ~]# rpm -qi pki-tps Name : pki-tps Version : 10.4.1 Release : 10.el7pki Architecture: x86_64 Install Date: Wed 21 Jun 2017 11:05:25 AM EDT Group : System Environment/Daemons Size : 1866565 License : GPLv2 Signature : (none) Source RPM : pki-core-10.4.1-10.el7pki.src.rpm Build Date : Tue 20 Jun 2017 01:59:47 AM EDT Build Host : x86-017.build.eng.bos.redhat.com Relocations : (not relocatable) Packager : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla> Vendor : Red Hat, Inc. URL : http://pki.fedoraproject.org/ Summary : Certificate System - Token Processing Service Verification steps: 1. Verified automatic key recovery Temporary token issued to a user had the encryption cert/key from lost token. Same behavior was observed when a token was physically damaged. 2. Cert/key recovery works with externalReg, delegateISE, userKey and delegateIE token types. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2090 |