- Issued:
- 2013-11-20
- Updated:
- 2013-11-20
RHBA-2013:1682 - pki-core bug fix update
Synopsis
pki-core bug fix update
Type/Severity
Bug Fix Advisory
Topic
Updated pki-core packages that fix three bugs are now available for Red Hat Enterprise Linux 6.
Description
Red Hat Certificate System is an enterprise software system designed to manage enterprise public key infrastructure (PKI) deployments. PKI Core contains fundamental packages required by Red Hat Certificate System, which comprise the Certificate Authority (CA) subsystem.
Note: The Certificate Authority component provided by this advisory cannot be used as a standalone server. It is installed and operates as a part of Identity Management (the IPA component) in Red Hat Enterprise Linux.
This update fixes the following bugs:
-
Previously, the /var/run/pki/ca/ directory was assigned an incorrect SElinux context after the installation of the pki-ca package. With this update, the restorecon command is applied on /var/run/pki/ca/ during the post-installation process. As a result, this directory is now labeled with the correct SElinux context. (BZ#887305)
-
Prior to this update, when the pki-ca daemon was restarted on the Red Hat Enterprise Linux 6.4 Identity Management server, AVC denials were reported. With this update, pki-ca has been modified and AVC denials are no longer reported in the aforementioned scenario. (BZ#895702, BZ#999055)
-
The pki-selinux package sets the file context for certain default paths, so that the context need not be set when Red Hat Certificate System instances are created. Prior to this update, when pki-selinux was installed, unnecessary warning messages were displayed if these paths did not yet exist. These messages are now suppressed. (BZ#998715)
All users of pki-core are advised to upgrade to these updated packages, which fix these bugs.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for Scientific Computing | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | i386 |
| Red Hat Enterprise Linux Server | 6 | x86_64 |
| Red Hat Enterprise Linux Server | 6 | i386 |
| Red Hat Enterprise Linux Server from RHUI | 6 | x86_64 |
| Red Hat Enterprise Linux Server from RHUI | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | i386 |
| Red Hat Enterprise Linux Desktop | 6 | x86_64 |
| Red Hat Enterprise Linux Desktop | 6 | i386 |
Updated Packages
- pki-core-debuginfo-9.0.3-32.el6.x86_64.rpm
- pki-ca-9.0.3-32.el6.noarch.rpm
- pki-selinux-9.0.3-32.el6.noarch.rpm
- pki-symkey-9.0.3-32.el6.x86_64.rpm
- pki-core-9.0.3-32.el6.src.rpm
- pki-symkey-9.0.3-32.el6.i686.rpm
- pki-util-9.0.3-32.el6.noarch.rpm
- pki-native-tools-9.0.3-32.el6.i686.rpm
- pki-common-javadoc-9.0.3-32.el6.noarch.rpm
- pki-util-javadoc-9.0.3-32.el6.noarch.rpm
- pki-silent-9.0.3-32.el6.noarch.rpm
- pki-java-tools-javadoc-9.0.3-32.el6.noarch.rpm
- pki-core-debuginfo-9.0.3-32.el6.i686.rpm
- pki-setup-9.0.3-32.el6.noarch.rpm
- pki-java-tools-9.0.3-32.el6.noarch.rpm
- pki-common-9.0.3-32.el6.noarch.rpm
- pki-native-tools-9.0.3-32.el6.x86_64.rpm
Fixes
- This content is not included.BZ - 887305
- This content is not included.BZ - 998715
- This content is not included.BZ - 999055
CVEs
(none)
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.