Your message dated Thu, 06 Nov 2008 19:17:05 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#503833: fixed in libtasn1-3 1.5-2
has caused the Debian Bug report #503833,
regarding libgnutls26: doesn't handle firefox-exported .p12 certs
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
503833: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503833
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: libgnutls26
Version: 2.4.2-1
Severity: normal

I'm a novice when it comes to dealing with certificates, so don't
hestitate to let me know if this bug is missing some important
information.

There's a long-open bug reported against subversion, #480041. This
appears to have surfaced when subversion began using libneon26-gnutls
instead of openssl for PKCS12 certs.

I took a shot at debugging this, and it looks like the problem first arises
when libgnutls calls into libtasn1-3 to decode the ASN.1-encoded
PKCS12 file.

asn1_der_decoding() eventually bails out, causing an error to be
propagated up the stack.

troyh and I think we've found a way to simplify the demonstration of
this problem outside of subversion by using certtool:

1) Follow the instructions for creating a pkcs12 cert that google
   found for me on this page:
     http://hausheer.osola.com/docs/9
2) Run:
     $ certtool --p12-info --infile /tmp/client.p12  --inraw
   (To demonstrate that we can process this cert)
3) Imported the cert into iceweasel (aka firefox)
4) Use the "backup" feature in iceweasel to dump the cert back out to
   another .p12 file
5) Run:
    $ certtool --p12-info --infile /tmp/backup.p12  --inraw
   This time, we see an error:
     date size is 1822
     certtool: p12_import: ASN1 parser: Error in TAG.

Obviously, this doesn't prove that this is a bug in gnutls. It could
very well be that firefox is exporting a bad cert. However, openssl
seems to handle the firefox-exported certs just fine, as seen in:
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480041#130
That suggests to me that this bug likely lies either in gnutls or
libtasn.

I'm filing a new bug instead of reassigning the subversion one because
subversion could theoretically fix the problem by reverting back to
openssl.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: ia64

Kernel: Linux 2.6.26-1-mckinley (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages libgnutls26 depends on:
ii  libc6.1                2.7-15            GNU C Library: Shared libraries
ii  libgcrypt11            1.4.1-1           LGPL Crypto library - runtime libr
ii  libgpg-error0          1.4-2             library for common error values an
ii  libtasn1-3             1.5-1             Manage ASN.1 structures (runtime)
ii  zlib1g                 1:1.2.3.3.dfsg-12 compression library - runtime

libgnutls26 recommends no packages.

Versions of packages libgnutls26 suggests:
ii  gnutls-bin                    2.4.2-1    the GNU TLS library - commandline 

-- no debconf information




--- End Message ---
--- Begin Message ---
Source: libtasn1-3
Source-Version: 1.5-2

We believe that the bug you reported is fixed in the latest version of
libtasn1-3, which is due to be installed in the Debian FTP archive:

libtasn1-3-bin_1.5-2_i386.deb
  to pool/main/libt/libtasn1-3/libtasn1-3-bin_1.5-2_i386.deb
libtasn1-3-dbg_1.5-2_i386.deb
  to pool/main/libt/libtasn1-3/libtasn1-3-dbg_1.5-2_i386.deb
libtasn1-3-dev_1.5-2_i386.deb
  to pool/main/libt/libtasn1-3/libtasn1-3-dev_1.5-2_i386.deb
libtasn1-3_1.5-2.diff.gz
  to pool/main/libt/libtasn1-3/libtasn1-3_1.5-2.diff.gz
libtasn1-3_1.5-2.dsc
  to pool/main/libt/libtasn1-3/libtasn1-3_1.5-2.dsc
libtasn1-3_1.5-2_i386.deb
  to pool/main/libt/libtasn1-3/libtasn1-3_1.5-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <[EMAIL PROTECTED]> (supplier of updated libtasn1-3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 06 Nov 2008 19:18:58 +0100
Source: libtasn1-3
Binary: libtasn1-3-dev libtasn1-3-dbg libtasn1-3 libtasn1-3-bin
Architecture: source i386
Version: 1.5-2
Distribution: experimental
Urgency: low
Maintainer: Debian GnuTLS Maintainers <[EMAIL PROTECTED]>
Changed-By: Andreas Metzler <[EMAIL PROTECTED]>
Description: 
 libtasn1-3 - Manage ASN.1 structures (runtime)
 libtasn1-3-bin - Manage ASN.1 structures (binaries)
 libtasn1-3-dbg - Manage ASN.1 structures (development)
 libtasn1-3-dev - Manage ASN.1 structures (development)
Closes: 503833
Changes: 
 libtasn1-3 (1.5-2) experimental; urgency=low
 .
   * Add Simon Josefsson to uploaders.
   * Support decoding of PKCS#12 certificates. (Patch from upstream).
     Bump shlibs.
     Closes: #503833
Checksums-Sha1: 
 b0a759a0747c42b39d7621f6842854faa974d17a 1427 libtasn1-3_1.5-2.dsc
 0bd3d2cc2b21897f4cf66c78f7187870e8ee99de 29903 libtasn1-3_1.5-2.diff.gz
 b397d6ae7626c02a4e2d9ff9b9b74e6c27241f6d 375252 libtasn1-3-dev_1.5-2_i386.deb
 8a66fecca64770b9a0e55ac0de750bd3f06905d2 81960 libtasn1-3-dbg_1.5-2_i386.deb
 256987f7833b018da598cca567f9a18e81a39fcb 59986 libtasn1-3_1.5-2_i386.deb
 7c9de5d615b132a905af9bf14aac849c10169c24 41266 libtasn1-3-bin_1.5-2_i386.deb
Checksums-Sha256: 
 c1f8f51218b314898867d36b8507b8b1b6d2a9b3edeba478b334aed3d9a72eca 1427 
libtasn1-3_1.5-2.dsc
 d308f9fc04f5d347cb23b4f0568e3a2f3d563540f8d509d430a0e155909de8ff 29903 
libtasn1-3_1.5-2.diff.gz
 759b679c26a33d99a970c20a6dc7d632a93bc3c33c797155d722a28db3f1e470 375252 
libtasn1-3-dev_1.5-2_i386.deb
 723e910a0c7b90a4c1865bd11bee4957ddbd43741aceed093545265dc6cbe628 81960 
libtasn1-3-dbg_1.5-2_i386.deb
 8b7650d5b59b73d0a11a6d237919a425a5c6729d0a6520b05bd26b6267fceb12 59986 
libtasn1-3_1.5-2_i386.deb
 43fe7a08e1a4f9f5c9e839f7b2f04063c815e11c4d558b5428b8217726aa4df5 41266 
libtasn1-3-bin_1.5-2_i386.deb
Files: 
 ad1da41a2be6eaa36e677fd8ccb89a91 1427 libs important libtasn1-3_1.5-2.dsc
 5092ed6626a1fc581c94856cded5fb69 29903 libs important libtasn1-3_1.5-2.diff.gz
 653c8cf1d79888195ed7eb8265df11d3 375252 libdevel optional 
libtasn1-3-dev_1.5-2_i386.deb
 4a83c9a7c52f6b1d0d9c71cb5a4867b4 81960 devel extra 
libtasn1-3-dbg_1.5-2_i386.deb
 bce5ec1c54d85ea716209a987c60aa12 59986 libs important libtasn1-3_1.5-2_i386.deb
 693b234eaf322be9f90074c2f44ed0a2 41266 libs extra libtasn1-3-bin_1.5-2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkkTP50ACgkQHTOcZYuNdmOTQwCfXDdCm0nFhNuHGPuynFinUgxB
ZlIAniaKr6r25+hXwW2hc6QGMLoyvRcW
=AG3/
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to