[Spacewalk-list] m2crypto and SSL Certificates with SAN

Steve Meier email at steve-meier.de
Wed Nov 21 10:20:29 UTC 2012


Dear all,

today I came across an interesting bug in the m2crypto package. When a
certificate has a Subject Alternative Name (SAN) the hostname verification
fails which causes a traceback and therefore interferes with
yum-rhn-plugin.

I have tested the different versions and this seems to be fixed in
m2crypto-0.16-6.el5.3 while m2crypto-0.16-6.el5.1 (and probably below) is
broken.

I would therefore like to recommend to update the dependencies of
yum-rhn-plugin to require m2crypto >= 0.16-6.el5.3 instead of >= 0.16-6.

Kind regards,
  Steve




More information about the Spacewalk-list mailing list