diff options
| author | Fraser Tweedale <ftweedal@redhat.com> | 2016-04-27 13:35:41 +1000 |
|---|---|---|
| committer | Fraser Tweedale <ftweedal@redhat.com> | 2016-05-03 10:56:18 +1000 |
| commit | 970fcc3b14f3a3fd5579aaa0259d289d82cff13d (patch) | |
| tree | acca51773924504c41de846f326ecb598fe95a97 /base/server/python | |
| parent | 1b8f5230d01499d97b874d4912c5c1a13e389c5f (diff) | |
| download | pki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.tar.gz pki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.tar.xz pki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.zip | |
Fix NSSDB certificate search method
'getX509CertFromToken' erroneously compares Issuer DN of given cert
with Subject DNs of cert in NSSDB. It falsely returns the parent of
the target cert, if the certs have the same serial number.
In the context of how this method is used, it causes the deletion of
an external CA certificate from the NSSDB if the serial numbers
match, and subsequent certificate verification failure when
connecting to LDAP.
Update the method to check the Issuer DN.
Fixes: https://fedorahosted.org/pki/ticket/2301
Diffstat (limited to 'base/server/python')
0 files changed, 0 insertions, 0 deletions
