summaryrefslogtreecommitdiffstats
path: root/base/server/python
diff options
context:
space:
mode:
authorFraser Tweedale <ftweedal@redhat.com>2016-04-27 13:35:41 +1000
committerFraser Tweedale <ftweedal@redhat.com>2016-05-03 10:56:18 +1000
commit970fcc3b14f3a3fd5579aaa0259d289d82cff13d (patch)
treeacca51773924504c41de846f326ecb598fe95a97 /base/server/python
parent1b8f5230d01499d97b874d4912c5c1a13e389c5f (diff)
downloadpki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.tar.gz
pki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.tar.xz
pki-970fcc3b14f3a3fd5579aaa0259d289d82cff13d.zip
Fix NSSDB certificate search method
'getX509CertFromToken' erroneously compares Issuer DN of given cert with Subject DNs of cert in NSSDB. It falsely returns the parent of the target cert, if the certs have the same serial number. In the context of how this method is used, it causes the deletion of an external CA certificate from the NSSDB if the serial numbers match, and subsequent certificate verification failure when connecting to LDAP. Update the method to check the Issuer DN. Fixes: https://fedorahosted.org/pki/ticket/2301
Diffstat (limited to 'base/server/python')
0 files changed, 0 insertions, 0 deletions