[Bug 1474541] Re: sbsigntool broken by update to openssl 1.0.2c
Launchpad Bug Tracker
1474541 at bugs.launchpad.net
Tue Jul 12 06:32:09 UTC 2016
This bug was fixed in the package sbsigntool - 0.6-0ubuntu4~12.04.2
---------------
sbsigntool (0.6-0ubuntu4~12.04.2) precise; urgency=medium
* debian/patches/0001-Support-openssl-1.0.2b-and-above.patch: handle the
case where we can't get the issuer certificate, which typically happens
after 1.0.2b; but it appears that 1.0.1f includes that check too, which
fails in sbsigntool. (LP: #1474541)
* debian/patches/ignore-certificate-expiries.patch: ignore certificate
expiries when verifying signatures. (LP: #1234649)
-- Mathieu Trudel-Lapierre <cyphermox at ubuntu.com> Tue, 24 May 2016
14:41:24 -0400
** Changed in: sbsigntool (Ubuntu Precise)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to sbsigntool in Ubuntu.
https://bugs.launchpad.net/bugs/1474541
Title:
sbsigntool broken by update to openssl 1.0.2c
Status in sbsigntool package in Ubuntu:
Fix Released
Status in sbsigntool source package in Precise:
Fix Released
Status in sbsigntool source package in Trusty:
Fix Released
Status in sbsigntool source package in Wily:
Fix Released
Bug description:
[Impact]
Validating signature using sbsigntool for EFI binaries on Precise and Trusty.
[Test case]
1) pull-lp-source shim-signed
2) sbverify --cert MicCorUEFCA2011_2011-06-27.crt shim.efi.signed
[Regression potential]
Complex signing scenarios may pass validation when they should not due to the unavailability of the issuer cert; but I can't think of a specific case where this might happen.
---
An upload of shim-signed with no source changes is now failing to
build in wily, because sbverify fails:
sbverify --cert MicCorUEFCA2011_2011-06-27.crt shim.efi.signed
warning: data remaining[1170360 vs 1289424]: gaps between PE/COFF sections?
PKCS7 verification failed
139919811188368:error:21075075:PKCS7 routines:PKCS7_verify:certificate verify error:pk7_smime.c:328:Verify error:unable to get issuer certificate
Signature verification failed
(https://launchpad.net/ubuntu/+source/shim-signed/1.10/+build/7652431)
The package builds successfully on vivid but fails on wily.
sbsigntool has not changed since vivid. Upgrading to the wily version
of libssl1.0.0 in a vivid chroot reproduces the failure.
I'm not sure if this is a regression in libssl1.0.0 or a bug in
sbsigntool.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1474541/+subscriptions
More information about the foundations-bugs
mailing list