-
Bug
-
Resolution: Done-Errata
-
Critical
-
None
-
4.14.z, 4.15.z, 4.17.z, 4.16.z
-
None
-
False
-
-
N/A
-
Release Note Not Required
-
Done
Description of problem:
This is part of the plan to improve stability of ipsec in ocp releases.
There are several regressions identified in libreswan-4.9 (default in 4.14.z and 4.15.z) which needs to be addressed in an incremental approach. The first step is to introduce libreswan-4.6-3.el9_0.3 which is the oldest major version(4.6) that can still be released in rhel9. It includes a libreswan crash fix and some CVE backports that are present in libreswan-4.9 but not in libreswan-4.5 (so that it can pass the internal CVE scanner check).
This pinning of libreswan-4.6-3.el9_0.3 is only needed for 4.14.z since containerized ipsec is used in 4.14. Starting 4.15, ipsec is moved to host and this CNO PR (about to merge as of writing) will allow ovnk to use host ipsec execs which only requires libreswan pkg update in rhcos extension.
- blocks
-
OCPBUGS-45942 [4.16] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
- clones
-
OCPBUGS-45310 [4.16] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
- depends on
-
OCPBUGS-45313 [4.18] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
- is cloned by
-
OCPBUGS-45313 [4.18] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
-
OCPBUGS-45942 [4.16] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
- is depended on by
-
OCPBUGS-45310 [4.16] pin libreswan package to 4.6-3.el9_0.3 in ovnk
- Closed
- links to
-
RHBA-2024:11010 OpenShift Container Platform 4.17.z bug fix update