ClearOS Bug Tracker


View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000418ClearOSwebconfig-phppublic2011-12-31 16:562012-04-13 18:30
Reportertimb80 
Assigned Touser2 
PrioritynormalSeverityminorReproducibilityalways
StatusclosedResolutionfixed 
PlatformOSOS Version
Product Version5.2-SP1 
Target VersionFixed in Version6.2.0 Beta 3 
Summary0000418: Change SSL default config in app-ssl from md5 to sha1
DescriptionOpenSSL now defaults to sha1 to sign certificates (/etc/pki/tls/openssl.cnf) due to the vulnerability of potential for hash collisions with md5

However the SSL config generated by the webconfig (/etc/ssl/openssl.cnf) is provided by app-ssl and still refers to md5
default_md = md5
Additional Informationhttp://www.clearfoundation.com/component/option,com_kunena/Itemid,232/catid,25/func,view/id,36290/#36302 [^]
http://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities [^]
TagsNo tags attached.
Attached Files

- Relationships

-  Notes
(0000402)
user2
2012-01-03 03:14

This was addressed in the version 6 implementation.

- Issue History
Date Modified Username Field Change
2011-12-31 16:56 timb80 New Issue
2012-01-03 02:54 user2 Status new => confirmed
2012-01-03 03:14 user2 Note Added: 0000402
2012-01-03 03:14 user2 Status confirmed => resolved
2012-01-03 03:14 user2 Fixed in Version => 6.2 Beta 3
2012-01-03 03:14 user2 Resolution open => fixed
2012-01-03 03:14 user2 Assigned To => user2
2012-04-13 18:30 user2 Status resolved => closed