Red Hat Bugzilla – Bug 670274
not verbose enough error message when subject-host differs from server
Last modified: 2014-08-04 18:08:30 EDT
Description of problem:
If the client fails verification because of a subject mismatch between
supplied host and actual host, it laconicly says "SSL error 1" instead
of giving a better error message. Fix is ACKED upstream:
client: log subject-host mismatch, and raise ssl warnings to errors
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. start qemu with secure channels, with subject $A != $B, some random string.
2. connect using --host-subject $B
look at $HOME/.spicec/spicec.log, it won't say "subject host differs", but just "SSL failed"
Should say subject host verification failed.
A new spice-client-0.7.2-1.el6 fixing this has been build, moving to modified.
VERIFIED on spice-client-0.8.0-2.el6
excerpt from ~/.spicec/spicec.log:
1302269813 ERROR [3716:3717] RedPeer::verify_subject: host-subject mismatch
1302269813 ERROR [3716:3717] RedPeer::connect_secure: failed to connect w/SSL, ssl_error error:00000001:lib(0):func(0):reason(1)
1302269813 WARN [3716:3717] RedChannel::run: SSL Error:
1302269813 INFO [3716:3716] main: Spice client terminated (exitcode = 7)
Technical note added. If any revisions are required, please edit the "Technical Notes" field
accordingly. All revisions will be proofread by the Engineering Content Services team.
If the client failed verification because of a subject mismatch between the supplied host and the actual host, the error message given was too short to be useful. With this update, the error message is now sufficiently informative.
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.