Bug 45949 - MD5 and aNULL ciphers are not supported anymore
MD5 and aNULL ciphers are not supported anymore
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Apache
UCS 4.3
Other Linux
: P5 normal (vote)
: UCS 4.3
Assigned To: Florian Best
Daniel Tröder
: interim-1
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-12-22 15:08 CET by Florian Best
Modified: 2018-03-14 14:38 CET (History)
1 user (show)

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2017-12-22 15:08:20 CET
The test case 23_apache/21_ssl-ciphers fails.

MD5 and aNULL ciphers are not supported by openssl anymore.
Comment 1 Florian Best univentionstaff 2017-12-22 15:10:05 CET
I removed them from the test.

ucs-test (8.0.3-1)
3ccaadb8d602 | Bug #45949: fix test case 23_apache/21_ssl-ciphers
Comment 2 Florian Best univentionstaff 2017-12-22 15:12:07 CET
The UCR variable in apache needs to be adjusted, too.
Comment 3 Florian Best univentionstaff 2017-12-22 15:51:12 CET
(In reply to Florian Best from comment #2)
> The UCR variable in apache needs to be adjusted, too.
Well, not necessarily. They are excluded (!MD5).

The QA should decide.
Comment 4 Daniel Tröder univentionstaff 2018-01-08 08:59:50 CET
OK: previous code ran in 4.2 and fails in 4.3
OK: new code works in 4.3
OK: keep UCRV default, as users expect those ciphers to be excluded and they'd just unnecessarily set the UCRV to exclude them
Comment 5 Stefan Gohmann univentionstaff 2018-03-14 14:38:51 CET
UCS 4.3 has been released:
 https://docs.software-univention.de/release-notes-4.3-0-en.html
 https://docs.software-univention.de/release-notes-4.3-0-de.html

If this error occurs again, please use "Clone This Bug".