Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-78057

keylime revocation notifier fails to connect over TLS

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-9.6
    • rhel-9.6
    • keylime
    • None
    • keylime-7.3.0-15.el9
    • Yes
    • Moderate
    • 1
    • rhel-security-special-projects
    • ssg_security
    • 27
    • 2
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • SECENGSP Cycle 14
    • Release Note Not Required
    • Covered by RHEL-78313
    • All
    • None

      What were you trying to do that didn't work?

       

      This error is due to python-requests update:

      • Fri Jan 10 2025 Lumír Balhar <lbalhar@redhat.com> - 2.25.1-9
      • Security fix for CVE-2024-35195
        Resolves: RHEL-37609

        A consequence of this fix is that keylime revocation notifier gets broken.

      We have already encountered this issue on RHEL-10 https://issues.redhat.com/browse/RHEL-45478 but in the end had to fix/workaround it in keylime.

      This is now the same issue on RHEL-9.

      What is the impact of this issue to you?

      revocation notifier cannot connect over TLS.

      Please provide the package NVR for which the bug is seen:

      keylime-7.3.0-13.el9_3.x86_64
      python3-requests-2.25.1-9.el9.noarch

      How reproducible is this bug?:

      always

      Steps to reproduce

      1. with keylime /functional/basic-attestation-with-custom-certificates test
      2.  
      3.  

      Expected results

      TLS connection works

      Actual results

      TLS connection doesn't work

              scorreia@redhat.com Sergio Correia
              ksrot@redhat.com Karel Srot
              Sergio Correia Sergio Correia
              Karel Srot Karel Srot
              Jan Fiala Jan Fiala
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: