Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1974715

Summary: httpd with mod_ssl doesn't work with openssl-3.0.0-0.alpha16.4.el9.x86_64
Product: Red Hat Enterprise Linux 9 Reporter: Alfredo Moralejo <amoralej>
Component: opensslAssignee: Sahana Prasad <sahana>
Status: CLOSED DUPLICATE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: CentOS StreamCC: apevec, bstinson, hkario, jwboyer, vashirov
Target Milestone: beta   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-06-24 17:11:34 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Alfredo Moralejo 2021-06-22 11:29:16 UTC
Description of problem:


http gets on httpd with mod_ssl enabled fails after updating to openssl-3.0.0-0.alpha16.4.el9.x86_64.

Version-Release number of selected component (if applicable):

openssl-3.0.0-0.alpha16.4.el9.x86_64
httpd-2.4.48-3.el9.x86_64


How reproducible:

Allways

Steps to Reproduce:


This test is part of RDO tests on CentOS Stream 9 last composes. After applying apache configuration it fails to GET http call on httpd with ssl enabled (on ipv6, i'm not sure if it's related):


# curl -v "https://[::1]:5000/v3/" 
*   Trying ::1:5000...                                                   
* Connected to ::1 (::1) port 5000 (#0)              
* ALPN, offering h2                                                      
* ALPN, offering http/1.1                                                
*  CAfile: /etc/pki/tls/certs/ca-bundle.crt         
* TLSv1.0 (OUT), TLS header, Certificate Status (22):                                                                                              
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.2 (IN), TLS header, Certificate Status (22):                                                                                               
* TLSv1.3 (IN), TLS handshake, Server hello (2):
 TLSv1.2 (IN), TLS header, Certificate Status (22):                                                                                       [0/1911]
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS header, Finished (20):
* TLSv1.2 (IN), TLS header, Unknown (23):           
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):                                                                                           
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Certificate (11):                                                                                                   
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, CERT verify (15):                         
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Finished (20):                            
* TLSv1.2 (OUT), TLS header, Finished (20):                              
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):              
* TLSv1.2 (OUT), TLS header, Unknown (23):                               
* TLSv1.3 (OUT), TLS handshake, Finished (20):                           
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384                  
* ALPN, server accepted to use http/1.1                                  
* Server certificate:
*  subject: CN=::1; C=US; ST=North Carolina; L=Raleigh; O=Red Hat Inc.; OU=OpenStack                                                               
*  start date: Mar 15 15:46:15 2018 GMT                                  
*  expire date: Mar 12 15:46:15 2028 GMT                                 
*  subjectAltName: host "::1" matched cert's IP address!                 
*  issuer: CN=::1; C=US; ST=North Carolina; L=Raleigh; O=Red Hat Inc.; OU=OpenStack                                                                
*  SSL certificate verify ok.
* TLSv1.2 (OUT), TLS header, Unknown (23):                               
> GET /v3/ HTTP/1.1 
> Host: [::1]:5000  
> User-Agent: curl/7.76.1
> Accept: */*       
>                   
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing                                  
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS alert, unexpected_message (522):
* OpenSSL SSL_read: error:0A0003F2:SSL routines::sslv3 alert unexpected message, errno 0                                                           
* Closing connection 0                                                   
curl: (56) OpenSSL SSL_read: error:0A0003F2:SSL routines::sslv3 alert unexpected message, errno 0      


Note that if i revert to httpd-2.4.48-2.el9.x86_64, same httpd config and curl call works fine:


# curl -v "https://[::1]:5000/v3/"                      
*   Trying ::1:5000...                                                   
* Connected to ::1 (::1) port 5000 (#0)              
* ALPN, offering h2                                                      
* ALPN, offering http/1.1                                                
*  CAfile: /etc/pki/tls/certs/ca-bundle.crt
* TLSv1.0 (OUT), TLS header, Certificate Status (22):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.2 (IN), TLS header, Certificate Status (22):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS header, Finished (20):
* TLSv1.2 (IN), TLS header, Unknown (23):                         
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS header, Unknown (23):                                                                                                          * TLSv1.3 (IN), TLS handshake, CERT verify (15):                                                                                                   * TLSv1.2 (IN), TLS header, Unknown (23):                                                                                                          * TLSv1.3 (IN), TLS handshake, Finished (20):                                                                                                      * TLSv1.2 (OUT), TLS header, Finished (20):                                                                                                        * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):                                                                                        * TLSv1.2 (OUT), TLS header, Unknown (23):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):                                                                                [0/1842]
* TLSv1.2 (OUT), TLS header, Unknown (23):                            
* TLSv1.3 (OUT), TLS handshake, Finished (20):              
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384   
* ALPN, server accepted to use http/1.1                                                                                                            
* Server certificate:                                                    
*  subject: CN=::1; C=US; ST=North Carolina; L=Raleigh; O=Red Hat Inc.; OU=OpenStack
*  start date: Mar 15 15:46:15 2018 GMT                 
*  expire date: Mar 12 15:46:15 2028 GMT                                                                                                           
*  subjectAltName: host "::1" matched cert's IP address!
*  issuer: CN=::1; C=US; ST=North Carolina; L=Raleigh; O=Red Hat Inc.; OU=OpenStack
*  SSL certificate verify ok.                                            
* TLSv1.2 (OUT), TLS header, Unknown (23):
> GET /v3/ HTTP/1.1      
> Host: [::1]:5000  
> User-Agent: curl/7.76.1
> Accept: */*                                                            
>                                                                                                                                                  
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.2 (IN), TLS header, Unknown (23):                                
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):                    
* old SSL session ID is stale, removing    
* TLSv1.2 (IN), TLS header, Unknown (23):            
* Mark bundle as not supporting multiuse         
< HTTP/1.1 200 OK                                                        
< Date: Tue, 22 Jun 2021 11:04:50 GMT           
< Server: Apache                                                         
< Content-Length: 246                                                    
< Vary: X-Auth-Token,Accept-Encoding                    
< x-openstack-request-id: req-f8f54173-f7c7-4ef7-810a-d5bb399037e7
< Content-Type: application/json                                         
<                                                                                                                                                  
* Connection #0 to host ::1 left intact                                                                                                            {"version": {"id": "v3.14", "status": "stable", "updated": "2020-04-07T00:00:00Z", "links": [{"rel": "self", "href": "https://[::1]:5000/v3/"}], "media-types": [{"base": "application/json", "type": "application/vnd.openstack.identity-v3+json"}]}}

Comment 1 Alicja Kario 2021-06-24 14:49:16 UTC
Why do you think that the bug is in OpenSSL, not in how httpd uses OpenSSL 3.0.0?
We have tests with openssl s_server where it successfully interoperates with curl.

Comment 2 Alicja Kario 2021-06-24 16:06:14 UTC
looks like duplicate of bug 1975201

Comment 3 Alfredo Moralejo 2021-06-24 16:54:46 UTC
same version of httpd built agains openssl 1.1.1 worked fine. Said this, it may be in both sides.

Looks duplicated of 1975201, you can close this as duplicated, btw.

Comment 4 Alicja Kario 2021-06-24 17:11:34 UTC
Yes, it may be some more advanced API that's used by mod_ssl and isn't by s_server that's broken.
But given that it's the server that sends then alert message, I'd guess at this point that the issues is with how httpd configures openssl.

*** This bug has been marked as a duplicate of bug 1975201 ***