Project

General

Profile

Actions

Bug #8512

closed

don't put certificate metadata in PEM files

Added by Adam Price about 10 years ago. Updated over 5 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Difficulty:
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

"The final conversion output shouldn’t contain anything apart from the encoded key and certificates. Although some tools are smart enough to ignore what isn’t needed, other tools are not. Leaving extra data in PEM files might result in problems that are difficult to troubleshoot." from OpenSSL Cookbook [1].

[1] https://www.feistyduck.com/books/openssl-cookbook/

Actions #1

Updated by Alex Wood about 10 years ago

Affected certs can be found by searching for words like "Signature" or "Validity"

[root@katello-centos6-2 katello]# grep -r -l 'Signature' /etc/pki/katello/
/etc/pki/katello/certs/katello-apache.crt
/etc/pki/katello/certs/java-client.crt
/etc/pki/katello/certs/katello-centos6-2.0.example.com-qpid-broker.crt
/etc/pki/katello/certs/katello-default-ca.crt
/etc/pki/katello/qpid_client_striped.crt
Actions #2

Updated by Eric Helms about 10 years ago

  • Translation missing: en.field_release set to 23
  • Triaged changed from No to Yes
Actions #3

Updated by Eric Helms almost 10 years ago

  • Translation missing: en.field_release deleted (23)
Actions #4

Updated by Eric Helms about 9 years ago

  • Translation missing: en.field_release set to 114
Actions #5

Updated by John Mitsch over 5 years ago

  • Status changed from New to Closed

Thanks for reporting this issue. This issue was created over 4 years ago and hasn't seen an update in 1 year. We are closing this in an effort to keep a realistic backlog. Please open up a new issue that includes a link to this issue if you feel this still needs to be addressed. We can then triage the new issue and reassess.

Actions #6

Updated by Justin Sherrill over 5 years ago

  • Target version deleted (Katello Backlog)
Actions #7

Updated by Justin Sherrill over 5 years ago

  • Status changed from Closed to Rejected
Actions

Also available in: Atom PDF