[#58149] [ruby-trunk - Feature #9076][Open] New one-argument block syntax: &. — "asterite (Ary Borenszweig)" <ary@...>

23 messages 2013/11/04

[#58176] [ruby-trunk - Bug #9082][Open] popen3 hangs when stderr gets lots of output — "rosenfeld (Rodrigo Rosenfeld Rosas)" <rr.rosas@...>

15 messages 2013/11/05

[#58207] [ruby-trunk - Bug #9089][Open] rb_fix2uint no longer raises a RangeError when given negative values — "NoKarma (Arthur Schreiber)" <schreiber.arthur@...>

9 messages 2013/11/06

[#58243] [ruby-trunk - Feature #9098][Open] Indent heredoc against the left margin by default when "indented closing identifier" is turned on. — "sikachu (Prem Sichanugrist)" <s@...>

24 messages 2013/11/09

[#58306] [ruby-trunk - Bug #9106][Open] 'gem install' doesn't copy .so files of ext libs — "tagomoris (Satoshi TAGOMORI)" <tagomoris@...>

15 messages 2013/11/13

[#58324] [ruby-trunk - Feature #9108][Open] Hash sub-selections — "wardrop (Tom Wardrop)" <tom@...>

28 messages 2013/11/14

[#58342] [ruby-trunk - Feature #9112][Open] Make module lookup more dynamic (Including modules into a module after it has already been included) — "PragTob (Tobias Pfeiffer)" <pragtob@...>

16 messages 2013/11/14

[#58350] [ruby-trunk - Feature #9113][Open] Ship Ruby for Linux with jemalloc out-of-the-box — "sam.saffron (Sam Saffron)" <sam.saffron@...>

59 messages 2013/11/15

[#58374] [ruby-trunk - Bug #9115][Open] Logger traps all exceptions; breaks Timeout — "cphoenix (Chris Phoenix)" <cphoenix@...>

10 messages 2013/11/16

[#58375] [ruby-trunk - Feature #9116][Open] String#rsplit missing — "artagnon (Ramkumar Ramachandra)" <artagnon@...>

12 messages 2013/11/16

[#58396] [ruby-trunk - Bug #9121][Open] [PATCH] Remove rbtree implementation of SortedSet due to performance regression — "xshay (Xavier Shay)" <contact@...>

15 messages 2013/11/18

[#58404] [ruby-trunk - Feature #9123][Open] Make Numeric#nonzero? behavior consistent with Numeric#zero? — "sferik (Erik Michaels-Ober)" <sferik@...>

40 messages 2013/11/18

[#58411] [ruby-trunk - Bug #9124][Open] TestSocket errors in test-all on Arch 64-bit — "jonforums (Jon Forums)" <redmine@...>

14 messages 2013/11/18

[#58438] [ruby-trunk - Bug #9129][Open] Regression in support for IPv6 literals in URIs with Net::HTTP — "kallistec (Daniel DeLeo)" <dan@...>

11 messages 2013/11/19

[#58545] [ruby-trunk - Feature #9145][Open] Queue#pop(true) return nil if empty instead of raising ThreadError — "jsc (Justin Collins)" <redmine@...>

9 messages 2013/11/24

[#58653] [ruby-trunk - Bug #9170][Open] Math.sqrt returns different types when mathn is included; breaks various gems - this bug can be reproduced in Ruby 1.8 as well — "kranzky (Jason Hutchens)" <JasonHutchens@...>

7 messages 2013/11/28

[ruby-core:58571] [ruby-trunk - Bug #9154][Open] Support for OpenSSL with MD5 disabled for certificate verification

From: "vo.x (Vit Ondruch)" <v.ondruch@...>
Date: 2013-11-25 15:29:12 UTC
List: ruby-core #58571
Issue #9154 has been reported by vo.x (Vit Ondruch).

----------------------------------------
Bug #9154: Support for OpenSSL with MD5 disabled for certificate verification
https://bugs.ruby-lang.org/issues/9154

Author: vo.x (Vit Ondruch)
Status: Open
Priority: Normal
Assignee: 
Category: 
Target version: 
ruby -v: ruby 2.0.0p247 (2013-06-27) [x86_64-linux]
Backport: 1.9.3: UNKNOWN, 2.0.0: UNKNOWN


=begin
In Fedora Rawhide, there was disable support for verification of certificate, CRL, and OCSP signatures using MD5 in OpenSSL [1, 2], therefore I observe following test errors:

   7) Error:
 test_sign_and_verify(OpenSSL::TestX509Request):
 OpenSSL::X509::RequestError: unknown message digest algorithm
     /builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509req.rb:111:in `verify'
     /builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509req.rb:111:in `test_sign_and_verify'
   8) Error:
 test_sign_and_verify(OpenSSL::TestX509Certificate):
 OpenSSL::X509::CertificateError: unknown message digest algorithm
     /builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509cert.rb:140:in `verify'
     /builddir/build/BUILD/ruby-2.0.0-p247/test/openssl/test_x509cert.rb:140:in `test_sign_and_verify'
 
I was suggested by OpenSSL maintainer, that MD5 is obsolete and for modernization, it would be more useful to test SHA256 instead of MD5 for example. Any chance to make this test could pass out of the box and support more modern hashing algorithms?


[1] http://pkgs.fedoraproject.org/cgit/openssl.git/commit/?id=dcd0fb1ec9e2ef9bace5473cb3924a8d867ce84b

[2] http://pkgs.fedoraproject.org/cgit/openssl.git/commit/?id=9caf868063fd085ed4b2246f5f8dde91873d1c15
=end



-- 
http://bugs.ruby-lang.org/

In This Thread

Prev Next