Bug 538222 - RHEL's ca-bundle.crt doesn't contain the CAcert CA certificates
Summary: RHEL's ca-bundle.crt doesn't contain the CAcert CA certificates
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: openssl
Version: 5.4
Hardware: All
OS: Linux
low
medium
Target Milestone: rc
: ---
Assignee: Tomas Mraz
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-11-17 23:34 UTC by Robert Scheck
Modified: 2009-11-25 12:17 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-11-25 12:00:45 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Robert Scheck 2009-11-17 23:34:07 UTC
Description of problem:
RHEL's ca-bundle.crt doesn't contain the CAcert CA certificates.

Since the Thawte Web of Trust was shut down two days ago, the only remaining
Web of Trust seems to be CAcert. I'm wondering, that the community project is
not included in RHEL's ca-bundle.crt right now.

Using the CAcert certificates, you e.g. can sign and encrypt your e-mails by
using the S/MIME standard. Without the root CA of CAcert, the path is broken.

- http://www.cacert.org/certs/root.txt
- http://www.cacert.org/certs/class3.txt

Please ensure that both CAcert CAs (Class 1 and 3) are added to RHEL's
ca-bundle.crt.

Version-Release number of selected component (if applicable):
openssl-0.9.8e-12

How reproducible:
Everytime, see above.

Actual results:
RHEL's ca-bundle.crt doesn't contain the CAcert CA certificates.

Expected results:
RHEL is shipping the CAcert CA certificates.

Additional info:
Please add the missing CAs at openssl with the next openssl update/errata.

Comment 1 Robert Scheck 2009-11-18 00:48:54 UTC
As the same issue exists in Fedora, the Fedora issue is tracked in bug #538219

Comment 2 Tomas Mraz 2009-11-25 11:56:11 UTC
We will not include CA certs which are not in the mozilla CA bundle.

Comment 3 Robert Scheck 2009-11-25 11:58:05 UTC
There ARE already CAs included, which are not in the Mozilla CA bundle.

Comment 4 Tomas Mraz 2009-11-25 12:00:45 UTC
Red Hat CAs

Comment 5 Robert Scheck 2009-11-25 12:17:38 UTC
Sure and you're right, but they are CAs which are not in the Mozilla CA bundle.


Note You need to log in before you can comment on or make changes to this bug.