Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 25: 2017-d219f0e5fc Critical: sscg Race Condition Issue

fedora
Calendar Grey April 1, 2017
Dist Fedora Esm H88
The latest patch for Fedora 25 sscg resolves a race condition that previously impacted the secure processing of key and certificate files.
Addresses a potential race-condition when the key and certificate share the same file.

Summary

A utility to aid in the creation of more secure "self-signed"

certificates. The certificates created by this tool are generated in a

way so as to create a CA certificate that can be safely imported into a

client machine to trust the service certificate without needing to set

up a full PKI environment and without exposing the machine to a risk of

false signatures from the service certificate.

Update Information:

Addresses a potential race-condition when the key and certificate share the same file.

Change Log

References

Fedora Update Notification FEDORA-2017-d219f0e5fc 2017-03-31 18:32:04.960739
Name : sscg Product : Fedora 25 Version : 2.0.4 Release : 1.fc25 URL : https://github.com/sgallagher/sscg Summary : Simple SSL certificate generator Description : A utility to aid in the creation of more secure "self-signed" certificates. The certificates created by this tool are generated in a way so as to create a CA certificate that can be safely imported into a client machine to trust the service certificate without needing to set up a full PKI environment and without exposing the machine to a risk of false signatures from the service certificate.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sscg' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: sscg
Product: Fedora 25
Version: 2.0.4
Release: 1.fc25
Summary: Simple SSL certificate generator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here