Insecure digital certificates In ipa
Description
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 0:2.2.0-17.el6_3.1 | ||
rpm rhel5 | 0:2.1.3-5.el5_9.2 |
Aliases
1. 2. 3.