Description of problem: Inconsistent "SSLVerifyDepth" value in the following 2 Apache configuration files (Foreman and Katello) can cause Apache to request unnecessary SSL secure renegotiation to the client (such as web browser). This will trigger security alert to an environment that running IPS, such as MacAfee IPS. Change the value of this directive to '3' in both file does prevent the renegotiation. /etc/httpd/conf.d/05-foreman-ssl.conf /etc/httpd/conf.d/05-foreman-ssl.d/katello.conf
Connecting redmine issue https://projects.theforeman.org/issues/27656 from this bug
Upstream bug assigned to ekohlvan
Moving this bug to POST for triage into Satellite 6 since the upstream issue https://projects.theforeman.org/issues/27656 has been resolved.
Verified on Snap20.1 6.6.0. Verified Point: 1- Checked SSLVerifyDepth value in 05-foreman-ssl.d/katello.conf file # cat /etc/httpd/conf.d/05-foreman-ssl.d/katello.conf|grep SSLVerifyDepth SSLVerifyDepth 3 2- Checked SSLVerifyDepth value in 05-foreman-ssl.conf file # cat /etc/httpd/conf.d/05-foreman-ssl.conf|grep SSLVerifyDepth SSLVerifyDepth 3 3- Foreman-installer pacakge : foreman-installer-1.22.0.12-1.el7sat.noarch
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2019:3172