Project

General

Profile

Bug #25451

Certificate extraction service can't handle joined lines

Added by Ewoud Kohl van Wijngaarden 6 months ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Difficulty:
Triaged:
No
Bugzilla link:
Team Backlog:
Fixed in Releases:
Found in Releases:

Description

When using Apache as a reverse proxy, it joins the lines in the certificate. Then OpenSSL::X509::Certificate fails to handle it with a nested x509 asn error.

Associated revisions

Revision 401aac82 (diff)
Added by Ewoud Kohl van Wijngaarden 6 months ago

Fixes #25451 - Make certificate loading robust

This is copied from Katello's app/services/cert/rhsm_client.rb with
added tests.

History

#1 Updated by The Foreman Bot 6 months ago

  • Assignee set to Ewoud Kohl van Wijngaarden
  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/6239 added

#2 Updated by Timo Goebel 6 months ago

  • Fixed in Releases 1.21.0 added

#3 Updated by Ewoud Kohl van Wijngaarden 6 months ago

  • Status changed from Ready For Testing to Closed

#4 Updated by Tomer Brisker 4 months ago

  • Subject changed from Certificate extraction serivce can't handle joined lines to Certificate extraction service can't handle joined lines

Also available in: Atom PDF