Uploaded image for project: 'OpenShift Core Networking'
  1. OpenShift Core Networking
  2. CORENET-5368

Consume libreswan-4.6 in near-term solution (>=4.15)

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • SDN Sprint 262, SDN Sprint 263, SDN Sprint 264, SDN Sprint 265

      Pinning libreswan rpm version in the near-term solution exposes the following vulnerabilities exist for the libreswan-4.5-1 installed in ovnk image and host via layered coreos image:

      RHEL team will need to backport the CVE fixes to a libreswan 4.6 version, which will be cross-tagged to OCP repo, then be consumed by ovnk image and when building layered coreos image.

      The ticket for cross-tagging the new libreswan 4.6 package in OCP: https://issues.redhat.com/browse/CWFCONF-10880

      Once new libreswan 4.6 package is cross-tagged, we need PRs in ovnk to pin the tagged version for version >= 4.15

      The procedure for building layered coreos image needs to be updated to use this new libreswan version.

      The above work needs to be completed before Dec 4th, the development cutoff date for 4.15.40.

              zshi@redhat.com Zenghui Shi
              zshi@redhat.com Zenghui Shi
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: