[Bug 794742] New: novell/attachmate infrastructure ssl certificate woes

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c0 Summary: novell/attachmate infrastructure ssl certificate woes Classification: openSUSE Product: openSUSE 12.2 Version: RC 2 Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: Other AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: abittner@abittner.de QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11 dont know exactly where to report, but googlechrome browser complains heavily about some non-matching hostnames and certificates for ssl when for example logging out of bugreporting here the desired address in the browser location field is https://esp.novell.com/AGLogout but the ssl certificates are assigned for *.attachmate.... whatever so googlechrome doesnt execute the url and the logout. Reproducible: Always Steps to Reproduce: 1. 2. 3. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c1 Jiaying ren <jren@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |jren@suse.com Resolution| |FIXED --- Comment #1 from Jiaying ren <jren@suse.com> 2012-12-19 09:12:33 UTC --- (In reply to comment #0)
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11
dont know exactly where to report, but googlechrome browser complains heavily about some non-matching hostnames and certificates for ssl when for example logging out of bugreporting here
Please check your ca-certificates package version by : rpm -qa | grep ca-certificates If you've edit them before,try to reinstall it.If you still had this problem,please reopen this report,thx. :-) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c2 andreas bittner <abittner@abittner.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED Resolution|FIXED | --- Comment #2 from andreas bittner <abittner@abittner.de> 2012-12-19 09:44:18 UTC --- what do you mean? I am just checking it again, I am accessing bugzilla.novell.com via a windows machine with google chrome as an example. there is no use checking any packages on whatever linux machine in this scenario :) so I accessed the https://bugzilla.novell.com/show_bug.cgi?id=794742 link from my mail, that comes up with the browser (e.g. googlechrome) and allows me to log in, the login link in the html generated by the bugzilla.novell.com webserver was pointing to some attachmategroup address, with https certificate matching for the login process that was okay. but now that I am here writing this bugreport reply, the page displays at the top a logout link that link in html points to: https://esp.novell.com/AGLogout and when I click that, my googlechrome browser still/again complains, as the URL is not matching with the certificate represented. the certificate is probably still for attachmate, but the bugzilla rendered html output points me to esp.novell.com thats what I am reporting about hope you understand please forward to some webserver administrator or infrastructure people at novell, attachmate or however your companies work and consist of at the moment. regards. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c3 --- Comment #3 from andreas bittner <abittner@abittner.de> 2012-12-19 09:49:16 UTC --- I just re-verified it again: when surfing anonymously to bugzilla.novell (not logged in) the login link is in html https://bugzilla.novell.com/show_bug.cgi?GoAheadAndLogIn=1&id=794742 that redirects me to (with googlechrome browser) https://login.attachmategroup.com/nidp/idff/sso?id=5&sid=0&option=credential... that certificate for that URL/address/server is fine, googlechrome doesnt complain about it. its for *.attachmategroup.com so I login there with my credentials and I land at first here https://login.attachmategroup.com/nidp/idff/sso?sid=0 then it forwards me via redirect to https://bugzilla.novell.com/show_bug.cgi?GoAheadAndLogIn=1&id=794742 and certificate for this last address is *.novell.com so now there on this page (where I also write this reply) there is in the top-bar a link called "Log out", and right next to it my username/mailaddress I click that (html reads: https://esp.novell.com/AGLogout) and then there is the googlechrome complaining about certificate mismatch and potential attack etc.... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c4 --- Comment #4 from Jiaying ren <jren@suse.com> 2012-12-19 10:47:17 UTC --- (In reply to comment #3)
and then there is the googlechrome complaining about certificate mismatch and potential attack etc....
Hi~Andreas.The issue you mentioned can't be reproduced by my host.But I'll forward this for my colleague.Thank you for your report. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c5 Jiaying ren <jren@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |NEEDINFO InfoProvider| |abittner@abittner.de --- Comment #5 from Jiaying ren <jren@suse.com> 2012-12-20 11:12:14 UTC --- (In reply to comment #2)
what do you mean? I am just checking it again, I am accessing bugzilla.novell.com via a windows machine with google chrome as an example. there is no use checking any packages on whatever linux machine in this scenario :)
so I accessed the https://bugzilla.novell.com/show_bug.cgi?id=794742 link from my mail, that comes up with the browser (e.g. googlechrome) and allows me to log in, the login link in the html generated by the bugzilla.novell.com webserver was pointing to some attachmategroup address, with https certificate matching for the login process that was okay.
Hi~Andreas.Does this happen only with chrome? Would you do me a favor to have a try on firefox? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c6 andreas bittner <abittner@abittner.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |REOPENED InfoProvider|abittner@abittner.de | --- Comment #6 from andreas bittner <abittner@abittner.de> 2012-12-20 11:32:25 UTC --- I think there is multiple sides to this stuff, and one very simple aspect is, that single logout URL I have just tried with Firefox on a completely different Network, just by visting that Address https://esp.novell.com/AGLogout and it also complains about bad certificate So there is no way other than your dns/ip/networks/filters maybe within the company network or some rules give you a different ip/address/redirect than us external users. then there might be a second issue inside bugzilla maybe depending on useraccounts and usergroups visiting bugzilla, maybe you novell/attachmate/suse folks get a differently rendered bugzilla output with other links, internal server addresses or whatever else.. you can simply tell me what certificate gets displayed in your firefox, chrome, opera or even internetexplorer or whatever else when you visit that https://esp.novell.com/AGLogout address in a fresh browser, in an anonymous borwser session, and so on. you can debug it all yourself and will most likely see the problem yourself. at all my networks and machines I have the following results: host esp.novell.com esp.novell.com has address 130.57.66.3 when I visit that e.g. by wget or curl or something C:\>wget -vS https://esp.novell.com/AGLogout -O NULL --2012-12-20 12:29:22-- https://esp.novell.com/AGLogout Resolving esp.novell.com... 130.57.66.3 Connecting to esp.novell.com|130.57.66.3|:443... connected. ERROR: cannot verify esp.novell.com's certificate, issued by `/C=US/O=DigiCert Inc/OU=www. digicert.com/CN=DigiCert High Assurance CA-3': Unable to locally verify the issuer's authority. ERROR: certificate common name `*.attachmategroup.com' doesn't match requested host name ` esp.novell.com'. To connect to esp.novell.com insecurely, use `--no-check-certificate'. Unable to establish SSL connection. in contrast to that "debugging" the https://bugzilla.novell.com address gives a different result, NOT complaining about hostname mismatch C:\>wget -vS https://bugzilla.novell.com -O NULL --2012-12-20 12:29:57-- https://bugzilla.novell.com/ Resolving bugzilla.novell.com... 130.57.66.9 Connecting to bugzilla.novell.com|130.57.66.9|:443... connected. ERROR: cannot verify bugzilla.novell.com's certificate, issued by `/C=US/O=DigiCert Inc/OU =www.digicert.com/CN=DigiCert High Assurance CA-3': Self-signed certificate encountered. To connect to bugzilla.novell.com insecurely, use `--no-check-certificate'. Unable to establish SSL connection. disregard the certificate/selfsigned warnings here, as my wget on windows isnt setup to know about certificates and certificate authorities etc... so there is clearly some hostname<->certificate mismatch here on the esp.novell.com when doing SSL/TLS with it. and thats the logout URL that gets rendered by the bugzilla pages at novell at least when I use my bugzilla account. very simple. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c7 --- Comment #7 from andreas bittner <abittner@abittner.de> 2012-12-20 11:50:59 UTC --- https://www.ssllabs.com/ssltest/analyze.html?d=esp.novell.com compare it to https://www.ssllabs.com/ssltest/analyze.html?d=bugzilla.novell.com -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c Marcus Rückert <mrueckert@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |mrueckert@suse.com AssignedTo|bnc-team-screening@forge.pr |mehle@novell.com |ovo.novell.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c8 Matthew Ehle <mehle@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|mehle@novell.com |rywilson@novell.com --- Comment #8 from Matthew Ehle <mehle@novell.com> 2012-12-26 17:51:21 UTC --- The single logout URL is incorrect. This needs to go to Ryan. He is already aware of the issue. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.

https://bugzilla.novell.com/show_bug.cgi?id=794742 https://bugzilla.novell.com/show_bug.cgi?id=794742#c9 Ryan Wilson <rywilson@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |RESOLVED Resolution| |FIXED --- Comment #9 from Ryan Wilson <rywilson@novell.com> 2013-01-02 16:40:36 UTC --- Necessary logout URL change has been made. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com