Hide Forgot
Description of problem: If the client fails verification because of a subject mismatch between supplied host and actual host, it laconicly says "SSL error 1" instead of giving a better error message. Fix is ACKED upstream: http://lists.freedesktop.org/archives/spice-devel/2011-January/002205.html client: log subject-host mismatch, and raise ssl warnings to errors Version-Release number of selected component (if applicable): How reproducible: Always Steps to Reproduce: 1. start qemu with secure channels, with subject $A != $B, some random string. 2. connect using --host-subject $B Actual results: look at $HOME/.spicec/spicec.log, it won't say "subject host differs", but just "SSL failed" Expected results: Should say subject host verification failed. Additional info:
A new spice-client-0.7.2-1.el6 fixing this has been build, moving to modified.
VERIFIED on spice-client-0.8.0-2.el6 excerpt from ~/.spicec/spicec.log: 1302269813 ERROR [3716:3717] RedPeer::verify_subject: host-subject mismatch 1302269813 ERROR [3716:3717] RedPeer::connect_secure: failed to connect w/SSL, ssl_error error:00000001:lib(0):func(0):reason(1) 1302269813 WARN [3716:3717] RedChannel::run: SSL Error: 1302269813 INFO [3716:3716] main: Spice client terminated (exitcode = 7)
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: If the client failed verification because of a subject mismatch between the supplied host and the actual host, the error message given was too short to be useful. With this update, the error message is now sufficiently informative.
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2011-0583.html