Welcome to FreeBSDFreaks.net!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

HEADS UP: ca_root_nss seems to trip up OpenSSL on FreeBSD ..

 
   FreeBSD Hosting (Home) -> FreeBSD Ports RSS
Next:  libreoffice-3.4.3 fails to upgrade  
Author Message
Matthias Andree

External


Since: Sep 07, 2011
Posts: 1



(Msg. 1) Posted: Tue Sep 06, 2011 7:25 pm
Post subject: HEADS UP: ca_root_nss seems to trip up OpenSSL on FreeBSD 7.3
Archived from groups: mailing>freebsd>ports (more info?)

Greetings,

apparently the new /etc/ssl/cert.pem file installed by
security/ca_root_nss trips up the OpenSSL 0.9.8e in the 7.3-RELEASE base
system. I haven't tested 7.4, 8.1 or 8.2, 8-STABLE is unaffected by the
problem.

The symptom is that some certificate chains that validate properly on
OpenSSL under FreeBSD 8-STABLE, fail to validate on 7.3. OpenSSL claims
that the root certificate weren't trusted.

Manually editing the cert.pem file to reorder Entrust certificates up
front in reverse order helps according to Doug's findings, but chances
are that this breaks recognition of other root certificates in exchange.

This is also extremely hard to test because we can't possibly find
enough sites to cover for all 150+ trust anchors that the ca_root_nss
ports provides.

Doug and I have been trying to debug this earlier today, to no avail
yet. The current suspicion is "bug in OpenSSL when reading certificate
bundles, and that bug got fixed between 0.9.8e and 0.9.8q (possibly
0.9.8n)" -- note though that the order of certificates in a bundle file
is not supposed to make any difference.

If someone has any insights, that will be much appreciated.

(Doug feel free to polish this text and re-post if it turned out to be
incomprehensible. Wink)

Best regards,
Matthias

_______________________________________________
freebsd-ports.DeleteThis@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-ports
To unsubscribe, send any mail to "freebsd-ports-unsubscribe@freebsd.org"

 >> Stay informed about: HEADS UP: ca_root_nss seems to trip up OpenSSL on FreeBSD .. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
openssl.3 dependency in bsd.openssl.mk can be satisfied by.. - >All ports using openssl will require openssl from ports, >if your opensll in CURRENT/STABLE/RELEASE base system >is not patched. > >Security: version in base must be 0.9.7d or have fixes..

openssh portable is still looking for openssl and not open.. - =3D=3D=3D> Compressing manual pages for openssl-stable-0.9.7i =3D=3D=3D> Running ldconfig /sbin/ldconfig -m /usr/local/lib =3D=3D=3D> Registering installation for openssl-stable-0.9.7i =3D=3D=3D> SECURITY REPORT: This port has ins...

OpenSSL updated in -current, Mk/bsd.openssl.mk needs update - --AqsLC8rIMeq19msA Content-Type: text/plain; charset=big5 Content-Disposition: inline Apply attached patch to avoid bogus dependancy on security/openssl. Jiawei Ye -- "Without the userland, the kernel is useless." --inspired by...

FreeBSD Port: openssl-0.9.7e_2 - Hi, I am having some problems compiling OpenSSL 0.9.7d on FreeBSD 5.3 amd64. I see that my OS already has openssl-0.9.7d installed ...but my attempt to ./config and compile from openssl src fails with ..

FreeBSD Port: php4-openssl-4.3.11 - I have the following install error with the current php4-openssl port: checking for nawk... nawk checking for OpenSSL support... yes, shared checking for Kerberos support... no ../configure.lineno: 2702: Syntax error: word unexpected (expecting ")&...
   FreeBSD Hosting (Home) -> FreeBSD Ports All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]