Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-98723

SSLKEYLOGFILE creates file with with lax permissions

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • openssl-3.5.1-1.el9
    • No
    • Moderate
    • 1
    • rhel-security-crypto
    • 19
    • 26
    • 0.1
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • Crypto25July
    • Hide

      AC1) When SSLKEYLOGFILE env variable is set, a file with the conversation secrets is created

      AC2) The created file has permissions of code "600"

      Show
      AC1) When SSLKEYLOGFILE env variable is set, a file with the conversation secrets is created AC2) The created file has permissions of code "600"
    • Pass
    • Not Needed
    • Automated
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Running httpd/Regression/bz1704317-mod_ssl-SSLKEYLOGFILE-support

      Test is checking permissions of /var/log/httpd/ssl_key_log. In previous rhel-9.6, permissions are 600. In rhel-9.7, file is also readable for group and others (644).

      Please provide the package NVR for which the bug is seen:

      httpd-2.4.62-4.el9

      How reproducible is this bug?:

      By running test httpd/Regression/bz1704317-mod_ssl-SSLKEYLOGFILE-support

      Expected results

      Test should pass, /var/log/httpd/ssl_key_log should have 600 permissions.

      Actual results

      rw-rr-. 1 root root 0 Jun 3 09:30 /var/log/httpd/ssl_key_log

      :: [ 09:30:46 ] :: [ PASS ] :: Command 'ls -l /var/log/httpd/ssl_key_log | awk '{print }'' (Expected 0, got 0)

      :: [ 09:30:46 ] :: [ FAIL ] :: File '/var/tmp/rlRun_LOG.sbugxMQV' should contain 'rw------.'

              dbelyavs@redhat.com Dmitry Belyavskiy
              bnater@redhat.com Branislav NĂ¡ter
              Dmitry Belyavskiy Dmitry Belyavskiy
              Georgios Stavros Pantelakis Georgios Stavros Pantelakis
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: