Bug 2049484 - Expired certificate in bundled botocore
Summary: Expired certificate in bundled botocore
Keywords:
Status: ASSIGNED
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: python-s3transfer
Version: 7.9
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Oyvind Albrigtsen
QA Contact: cluster-qe
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-02-02 10:33 UTC by Reid Wahl
Modified: 2023-08-10 15:41 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-110686 0 None None None 2022-02-02 10:54:22 UTC

Description Reid Wahl 2022-02-02 10:33:24 UTC
Description of problem:

The cacert.pem bundled in python-s3transfer's botocore libs is expired. Customer reported. Confirmed below.

[root@fastvm-rhel-7-6-21 requests]# pwd
/usr/lib/fence-agents/bundled/botocore/vendored/requests
[root@fastvm-rhel-7-6-21 requests]# openssl verify -CAfile cacert.pem cacert.pem
cacert.pem: C = US, O = GTE Corporation, OU = "GTE CyberTrust Solutions, Inc.", CN = GTE CyberTrust Global Root
error 10 at 0 depth lookup:certificate has expired
OK

This package gets pulled in by python-boto3 (for fence-agents-aws) on RHEL 7.

-----

Version-Release number of selected component (if applicable):

python-s3transfer-0.1.13-1.el7

-----

How reproducible:

Always

-----

Steps to Reproduce:
1. cd /usr/lib/fence-agents/bundled/botocore/vendored/requests
2. openssl verify -CAfile cacert.pem cacert.pem

-----

Actual results:

cacert.pem: C = US, O = GTE Corporation, OU = "GTE CyberTrust Solutions, Inc.", CN = GTE CyberTrust Global Root
error 10 at 0 depth lookup:certificate has expired
OK

-----

Expected results:

Not expired

Comment 4 Oyvind Albrigtsen 2022-02-04 15:53:12 UTC
The cert is getting updated in bz#2050751, and seems to solve this issue.

# cd /usr/lib/fence-agents/bundled/botocore/
# openssl verify -CAfile cacert.pem cacert.pem
cacert.pem: OK


Note You need to log in before you can comment on or make changes to this bug.