Issued:
2013-11-20
Updated:
2013-11-20

RHBA-2013:1682 - pki-core bug fix update


Synopsis

pki-core bug fix update

Type/Severity

Bug Fix Advisory

Topic

Updated pki-core packages that fix three bugs are now available for Red Hat Enterprise Linux 6.

Description

Red Hat Certificate System is an enterprise software system designed to manage enterprise public key infrastructure (PKI) deployments. PKI Core contains fundamental packages required by Red Hat Certificate System, which comprise the Certificate Authority (CA) subsystem.

Note: The Certificate Authority component provided by this advisory cannot be used as a standalone server. It is installed and operates as a part of Identity Management (the IPA component) in Red Hat Enterprise Linux.

This update fixes the following bugs:

  • Previously, the /var/run/pki/ca/ directory was assigned an incorrect SElinux context after the installation of the pki-ca package. With this update, the restorecon command is applied on /var/run/pki/ca/ during the post-installation process. As a result, this directory is now labeled with the correct SElinux context. (BZ#887305)

  • Prior to this update, when the pki-ca daemon was restarted on the Red Hat Enterprise Linux 6.4 Identity Management server, AVC denials were reported. With this update, pki-ca has been modified and AVC denials are no longer reported in the aforementioned scenario. (BZ#895702, BZ#999055)

  • The pki-selinux package sets the file context for certain default paths, so that the context need not be set when Red Hat Certificate System instances are created. Prior to this update, when pki-selinux was installed, unnecessary warning messages were displayed if these paths did not yet exist. These messages are now suppressed. (BZ#998715)

All users of pki-core are advised to upgrade to these updated packages, which fix these bugs.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for Scientific Computing6x86_64
Red Hat Enterprise Linux Workstation6x86_64
Red Hat Enterprise Linux Workstation6i386
Red Hat Enterprise Linux Server6x86_64
Red Hat Enterprise Linux Server6i386
Red Hat Enterprise Linux Server from RHUI6x86_64
Red Hat Enterprise Linux Server from RHUI6i386
Red Hat Enterprise Linux Server - Extended Life Cycle Support6x86_64
Red Hat Enterprise Linux Server - Extended Life Cycle Support6i386
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension6x86_64
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension6i386
Red Hat Enterprise Linux Desktop6x86_64
Red Hat Enterprise Linux Desktop6i386

Updated Packages

  • pki-core-debuginfo-9.0.3-32.el6.x86_64.rpm
  • pki-ca-9.0.3-32.el6.noarch.rpm
  • pki-selinux-9.0.3-32.el6.noarch.rpm
  • pki-symkey-9.0.3-32.el6.x86_64.rpm
  • pki-core-9.0.3-32.el6.src.rpm
  • pki-symkey-9.0.3-32.el6.i686.rpm
  • pki-util-9.0.3-32.el6.noarch.rpm
  • pki-native-tools-9.0.3-32.el6.i686.rpm
  • pki-common-javadoc-9.0.3-32.el6.noarch.rpm
  • pki-util-javadoc-9.0.3-32.el6.noarch.rpm
  • pki-silent-9.0.3-32.el6.noarch.rpm
  • pki-java-tools-javadoc-9.0.3-32.el6.noarch.rpm
  • pki-core-debuginfo-9.0.3-32.el6.i686.rpm
  • pki-setup-9.0.3-32.el6.noarch.rpm
  • pki-java-tools-9.0.3-32.el6.noarch.rpm
  • pki-common-9.0.3-32.el6.noarch.rpm
  • pki-native-tools-9.0.3-32.el6.x86_64.rpm

Fixes

CVEs

(none)

References

(none)


Additional information