[Bug 1003841] [NEW] (regression) cannot contact ldaps server

Launchpad Bug Tracker 1003841 at bugs.launchpad.net
Fri Jun 8 13:42:11 UTC 2012


You have been subscribed to a public bug by Sebastien Bacher (seb128):

Impact:

gnutls-cli (linked with libgnutls26, like the OpenLDAP client libraries)
cannot contact our LDAP server securely in precise

Test case:

if you generate two CA
certificates (#1 and #2) with the same DN and hash, then sign the LDAP server’s
certificate (#3) with #2, not #1, GnuTLS 2.x will not validate it.

Regression potential:

the fix is coming from upstream and is available in Debian

---

Hi,

while trying to debug NSS with LDAP and SSL (not LP#423252 because it
failed even for nōn-suid programmes) I found that gnutls-cli (linked
with libgnutls26, like the OpenLDAP client libraries) cannot contact our
LDAP server securely in precise. More testing resulted in determining
this to be a regression between natty and oneiric, still present in
precise. I’m in contact with upstream about this already. More
information will thus follow.

** Affects: gnutls13 (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: gnutls26 (Ubuntu)
     Importance: High
         Status: Fix Released

** Affects: gnutls13 (Ubuntu Lucid)
     Importance: Undecided
         Status: New

** Affects: gnutls26 (Ubuntu Lucid)
     Importance: High
         Status: New

** Affects: gnutls13 (Ubuntu Oneiric)
     Importance: Undecided
         Status: New

** Affects: gnutls26 (Ubuntu Oneiric)
     Importance: High
         Status: Fix Committed

** Affects: gnutls13 (Ubuntu Precise)
     Importance: Undecided
         Status: New

** Affects: gnutls26 (Ubuntu Precise)
     Importance: High
         Status: Fix Committed

** Affects: gnutls26 (Debian)
     Importance: Undecided
         Status: Fix Released


** Tags: patch
-- 
(regression) cannot contact ldaps server
https://bugs.launchpad.net/bugs/1003841
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list