Created attachment 772220 [details] Patch against neon-0.29.6 to fix use of uninitialised size_t Description of problem: x509_crt_copy function passes uninitialized data to subroutine, resulting in failure to authenticate with client certificates Version-Release number of selected component (if applicable): 0.29.6 How reproducible: Always on F19, probably varies with compiler/memory initialisation/etc Steps to Reproduce: 1. "svn ls https://server.requiring.client.certificate" 2. 3. Actual results: No handshake Expected results: Subversion provides client certificate to Neon to use during handshake Additional info: Patch provided. See also bug 981431 and possibly 577976
See full description in bug 981431, comment 3
This bug was reported to the neon mailing list in November by someone else: http://lists.manyfish.co.uk/pipermail/neon/2012-November/001518.html
Any progress?
(In reply to Mattias Ellert from comment #3) > Any progress? Nope. The mailing list seems like a ghost town. I posted a query here: http://lists.manyfish.co.uk/pipermail/neon/2013-July/001550.html Can Red Hat maintain their own patch to the neon RPM and issue an errata update?
neon-0.30.0-2.fc19 has been submitted as an update for Fedora 19. https://admin.fedoraproject.org/updates/neon-0.30.0-2.fc19
Sorry for the delay and thanks for the nags - can you test this build? https://koji.fedoraproject.org/koji/buildinfo?buildID=439962
*** Bug 981431 has been marked as a duplicate of this bug. ***
(In reply to Joe Orton from comment #6) > Sorry for the delay and thanks for the nags - can you test this build? > > https://koji.fedoraproject.org/koji/buildinfo?buildID=439962 Glad to help. This Koji build works fine on my Fedora 19 install; I can now access SVN repos via SSL client certificates... Thanks.
Thanks, Simon.
Package neon-0.30.0-2.fc19: * should fix your issue, * was pushed to the Fedora 19 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing neon-0.30.0-2.fc19' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2013-14149/neon-0.30.0-2.fc19 then log in and leave karma (feedback).
neon-0.30.0-2.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.