Bug 510515 - mod_ssl cannot handle more than 85 CAs
Summary: mod_ssl cannot handle more than 85 CAs
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: httpd
Version: 5.3
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Joe Orton
QA Contact: BaseOS QE
URL:
Whiteboard:
Depends On:
Blocks: 510518
TreeView+ depends on / blocked
 
Reported: 2009-07-09 15:23 UTC by Martin Poole
Modified: 2018-10-27 14:55 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 510518 (view as bug list)
Environment:
Last Closed: 2010-03-30 08:28:20 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Apache Bugzilla 46952 0 None None None Never
Red Hat Product Errata RHEA-2010:0252 0 normal SHIPPED_LIVE httpd bug fix and enhancement update 2012-05-17 17:57:35 UTC

Description Martin Poole 2009-07-09 15:23:42 UTC
There is an issue in the interaction of the mod_ssl/openssl
buffer handling which results in a hanging connection, when the
server is using a certificate from the CERN CA and there are more
than 85 trusted CA certificates.

The original issue with a suggested workaround:
  https://savannah.cern.ch/bugs/?48458

mod_ssl follow up with test case:
  https://issues.apache.org/bugzilla/show_bug.cgi?id=46952

related openssl bug (guest/guest):
  http://rt.openssl.org/Ticket/Display.html?id=1949

upstream mod_ssl patch
  http://svn.apache.org/viewvc?view=rev&revision=787722

Comment 3 Joe Orton 2009-08-24 09:47:06 UTC
Note that the fix required for this is:

http://svn.apache.org/viewvc?view=rev&revision=788715

not r787722 as indicated above, which only helps with if the associated OpenSSL patch is applied.  It is sufficient to apply r788715 and we'll backport just that change.

Comment 11 Chris Ward 2010-02-11 10:30:34 UTC
~~ Attention Customers and Partners - RHEL 5.5 Beta is now available on RHN ~~

RHEL 5.5 Beta has been released! There should be a fix present in this 
release that addresses your request. Please test and report back results 
here, by March 3rd 2010 (2010-03-03) or sooner.

Upon successful verification of this request, post your results and update 
the Verified field in Bugzilla with the appropriate value.

If you encounter any issues while testing, please describe them and set 
this bug into NEED_INFO. If you encounter new defects or have additional 
patch(es) to request for inclusion, please clone this bug per each request
and escalate through your support representative.

Comment 13 errata-xmlrpc 2010-03-30 08:28:20 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2010-0252.html


Note You need to log in before you can comment on or make changes to this bug.