[Bug 509819] perl-IO-Socket-SSL: incorrect checking of certificate hostnames

bugzilla at redhat.com bugzilla at redhat.com
Mon Jul 6 13:38:08 UTC 2009


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=509819





--- Comment #2 from Tomas Hoger <thoger at redhat.com>  2009-07-06 09:38:07 EDT ---
Yup, I've seen and updated Fedora update requests.

As for 1.01 in EL5 and EPEL4, the situation there is bit more difficult, as
that version does not seem to any support for hostname verification.  According
to the changelog, it was only added in 1.14:

http://cpansearch.perl.org/src/SULLR/IO-Socket-SSL-1.14/Changes

v1.14
 - added support for verification of hostname from certificate
          including subjectAltNames, support for IDN etc based on patch and
          input from christopher[AT]odenbachs[DOT]de and 
          achim[AT]grolmsnet[DOT]de.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.




More information about the Fedora-perl-devel-list mailing list