pollen advertises SSLv3 support

Bug #1383738 reported by Leif Johansson
268
This bug affects 2 people
Affects Status Importance Assigned to Milestone
pollen (Ubuntu)
Fix Released
High
Dustin Kirkland 
Trusty
Fix Committed
High
Unassigned

Bug Description

It would be nice (poodle) to be able to turn off SSLv3 support in pollen and to control the ciphersuites offered.

information type: Private Security → Public Security
Changed in pollen (Ubuntu):
status: New → Confirmed
tags: added: poodle
Changed in pollen (Ubuntu):
status: Confirmed → In Progress
importance: Undecided → High
assignee: nobody → Dustin Kirkland  (kirkland)
Revision history for this message
Dustin Kirkland  (kirkland) wrote :
Revision history for this message
Dustin Kirkland  (kirkland) wrote :

Okay, looks like I have it working now:

kirkland@x230:~⟫ sudo pollinate -s https://localhost:444 -r --insecure -c "-3"
Oct 31 16:25:51 x230 pollinate[2956]: system was previously seeded at [2014-10-31 16:16:49.409696843 -0500]
Oct 31 16:25:51 x230 pollinate[2966]: client sent challenge to [https://localhost:444]
Oct 31 16:25:51 x230 pollinate[2994]: ERROR: Network communication failed [35]\n16:25:51.537240 * Rebuilt URL to: https://localhost:444/
16:25:51.537307 * Hostname was NOT found in DNS cache
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
  0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 016:25:51.541700 * Trying 127.0.0.1...
16:25:51.541883 * Connected to localhost (127.0.0.1) port 444 (#0)
16:25:51.542635 * successfully set certificate verify locations:
16:25:51.542657 * CAfile: /etc/pollinate/entropy.ubuntu.com.pem
  CApath: /dev/null
16:25:51.542788 * SSLv3, TLS handshake, Client hello (1):
16:25:51.542807 } [data not shown]
16:25:51.542861 * SSLv3, TLS alert, Server hello (2):
16:25:51.542882 } [data not shown]
16:25:51.542925 * error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
16:25:51.542942 * Closing connection 0
curl: (35) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
1 kirkland@x230:~⟫ sudo pollinate -s https://localhost:444 -r --insecure
Oct 31 16:25:55 x230 pollinate[3127]: system was previously seeded at [2014-10-31 16:16:49.409696843 -0500]
Oct 31 16:25:55 x230 pollinate[3137]: client sent challenge to [https://localhost:444]
Oct 31 16:25:55 x230 pollinate[3168]: client verified challenge/response with [https://localhost:444]
Oct 31 16:25:56 x230 pollinate[3181]: client hashed response from [https://localhost:444]
Oct 31 16:25:56 x230 pollinate[3183]: client successfully seeded [/dev/urandom]

Changed in pollen (Ubuntu):
status: In Progress → Fix Committed
Revision history for this message
Dustin Kirkland  (kirkland) wrote :

Committed in r297

Changed in pollen (Ubuntu):
status: Fix Committed → Fix Released
Revision history for this message
Chris J Arges (arges) wrote : Please test proposed package

Hello Leif, or anyone else affected,

Accepted pollen into trusty-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/pollen/4.21-0ubuntu1~14.04 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-needed to verification-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in pollen (Ubuntu Trusty):
status: New → Fix Committed
tags: added: verification-needed
Mathew Hodson (mhodson)
Changed in pollen (Ubuntu Trusty):
importance: Undecided → High
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote : [pollen/trusty] verification still needed

The fix for this bug has been awaiting testing feedback in the -proposed repository for trusty for more than 90 days. Please test this fix and update the bug appropriately with the results. In the event that the fix for this bug is still not verified 15 days from now, the package will be removed from the -proposed repository.

tags: added: removal-candidate
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.