Bug 1172461 - gnutls fails to verify certificate chains that contain an expired cross-signed intermediate in alternate chains
gnutls fails to verify certificate chains that contain an expired cross-signe...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P5 - None : Major (vote)
: ---
Assigned To: Vítězslav Čížek
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-06-03 13:40 UTC by Andreas Schwab
Modified: 2021-07-27 12:36 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Schwab 2020-06-03 13:40:22 UTC
With the recent expiration of the AddTrust root certificate gnutls fails to verify a lot of TLS connections because that certificate is being sent as part of the certificte chain.  See <https://gitlab.com/gnutls/gnutls/-/issues/1008> for details.
Comment 2 Andreas Stieger 2020-06-08 20:52:51 UTC
https://build.opensuse.org/request/show/811395, but blocked on bug 1171565
Comment 3 Vítězslav Čížek 2020-06-09 08:02:20 UTC
(In reply to Andreas Stieger from comment #2)
> https://build.opensuse.org/request/show/811395, but blocked on bug 1171565

I temporarily disabled the test in order to get the recent security fixes to Factory (bug 1172506, bug 1172663), so this bug will get fixed by request https://build.opensuse.org/request/show/812790.
Comment 5 Swamp Workflow Management 2020-06-09 22:13:36 UTC
SUSE-SU-2020:1584-1: An update that solves one vulnerability and has one errata is now available.

Category: security (important)
Bug References: 1172461,1172506
CVE References: CVE-2020-13777
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    gnutls-3.6.7-6.29.1
SUSE Linux Enterprise Server 15-LTSS (src):    gnutls-3.6.7-6.29.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    gnutls-3.6.7-6.29.1
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    gnutls-3.6.7-6.29.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    gnutls-3.6.7-6.29.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    gnutls-3.6.7-6.29.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2020-06-10 20:46:09 UTC
openSUSE-SU-2020:0790-1: An update that solves one vulnerability and has one errata is now available.

Category: security (important)
Bug References: 1172461,1172506
CVE References: CVE-2020-13777
Sources used:
openSUSE Leap 15.1 (src):    gnutls-3.6.7-lp151.2.18.1