LWN.net Logo

myproxy: invalid certificate hostname check

Package(s):myproxy CVE #(s):
Created:January 27, 2011 Updated:February 2, 2011
Description:

From the MyProxy advisory:

The myproxy-logon program (also called myproxy-get-delegation) in MyProxy versions 5.0 through 5.2 does not abort connections when it finds that the myproxy-server's certificate is valid and signed by a trusted certification authority but the certificate does not contain the expected hostname (or identity given in the MYPROXY_SERVER_DN environment variable), unless the myproxy-logon -T or myproxy-logon -b options are given.

Alerts:
Fedora FEDORA-2011-0514 2011-01-18
Fedora FEDORA-2011-0512 2011-01-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds