| Summary: | nrpe connection from nagios doesnt work after last updates with crypto-policies | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Dieter Schütze <dieter> |
| Component: | RPM Packages | Assignee: | Daniel Lucio <luis.daniel.lucio> |
| Status: | RESOLVED OLD | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | jani.valimaa, ouaurelien, thierry.vignaud |
| Version: | 7 | Keywords: | Triaged |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | nrpe-3.2.1-3.2.mga7.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | 27359 | ||
| Bug Blocks: | |||
|
Description
Dieter Schütze
2020-10-04 16:54:36 CEST
Dieter Schütze
2020-10-04 17:04:51 CEST
Version:
Cauldron =>
7 Try this: 1. Install rpm-helper and change KEY_LENGTH to 4096 in /etc/sysconfig/ssl. 2. Run '/usr/share/rpm-helper/create-ssl-certificate nrpe 1 nagios -g nagios' as root. 3. Change nrpe to use created certs in /etc/nagios/nrpe.cfg: ssl_cert_file=/etc/pki/tls/certs/nagios.pem ssl_privatekey_file=/etc/pki/tls/private/nagios.pem 4. Restart nrpe (In reply to Jani Välimaa from comment #1) > Try this: > > 1. Install rpm-helper and change KEY_LENGTH to 4096 in /etc/sysconfig/ssl. > > 2. Run '/usr/share/rpm-helper/create-ssl-certificate nrpe 1 nagios -g > nagios' as root. > > 3. Change nrpe to use created certs in /etc/nagios/nrpe.cfg: > ssl_cert_file=/etc/pki/tls/certs/nagios.pem > ssl_privatekey_file=/etc/pki/tls/private/nagios.pem > > 4. Restart nrpe Thank you, this works on my test environment. But a question for my understanding, why i have to expand the key lenght ? if you look at /etc/crypto-policies/state/CURRENT.po the lenght of 2048 is enough.
Aurelien Oudelet
2020-10-05 15:57:51 CEST
Depends on:
(none) =>
27359 Hi, thanks for reporting this bug. Assigned to the package maintainer. No update required. 27259 blocks this. Will close this after 27259 will be fixed. Keywords:
(none) =>
Triaged (In reply to Dieter Schütze from comment #2) > (In reply to Jani Välimaa from comment #1) > > Try this: > > > > 1. Install rpm-helper and change KEY_LENGTH to 4096 in /etc/sysconfig/ssl. > > > > 2. Run '/usr/share/rpm-helper/create-ssl-certificate nrpe 1 nagios -g > > nagios' as root. > > > > 3. Change nrpe to use created certs in /etc/nagios/nrpe.cfg: > > ssl_cert_file=/etc/pki/tls/certs/nagios.pem > > ssl_privatekey_file=/etc/pki/tls/private/nagios.pem > > > > 4. Restart nrpe > > Thank you, this works on my test environment. > But a question for my understanding, why i have to expand the key lenght ? > if you look at /etc/crypto-policies/state/CURRENT.po the lenght of 2048 is > enough. Can you also try the same with KEY_LENGTH=2048? It might be that there is something else happening with nrpe and how it is working if certs are not used/configured. CC:
(none) =>
jani.valimaa (In reply to Jani Välimaa from comment #5) > (In reply to Dieter Schütze from comment #2) > > Can you also try the same with KEY_LENGTH=2048? > > It might be that there is something else happening with nrpe and how it is > working if certs are not used/configured. With the given certificate, nrpe is forced to use an ssl connection with a given key length. this gives you the opportunity to adapt it to the crypto policies. Thank you Also works in the production environment, tested today. I also used the 4096 long key. That makes sense for stricter regulations in the future. (In reply to Aurelien Oudelet from comment #4) > Hi, thanks for reporting this bug. > Assigned to the package maintainer. > > No update required. 27259 blocks this. > > Will close this after 27259 will be fixed. Fixing bug 27259 doesn't fix the issue automatic. nrpe needs to be also configured/patched to use SSL cert and private key as it doesn't do it by default. Status comment:
No update required. 27259 blocks this. =>
(none) (In reply to Jani Välimaa from comment #8) > (In reply to Aurelien Oudelet from comment #4) > > Hi, thanks for reporting this bug. > > Assigned to the package maintainer. > > > > No update required. 27259 blocks this. > > > > Will close this after 27259 will be fixed. > > Fixing bug 27359 doesn't fix the issue automatic. > > nrpe needs to be also configured/patched to use SSL cert and private key as > it doesn't do it by default. It's bug 27359 and not 27259. Mageia 7 is EOL since July 1st 2021. There will not have any further bugfix for this release. You are encouraged to upgrade to Mageia 8 as soon as possible. @reporter, if this bug still apply with Mageia 8, please let us know it. @packager, if you work on the Mageia 7 version of your package, please check the Mageia 8 package if issue is also present. In this case, please fix the Mageia 8 version instead. This bug report will be closed OLD if there is no further notice within 1st September 2021. Hi bug reporter and hi assignee and others involved, Please reopen this bug report if it is still valid for Mageia 8 or 9(cauldron), and change "Version:" in the upper left of this report accordingly. This report is being closed as OLD because it was filed against Mageia 7, for which support ended on June 30th 2021. Thanks, Marja Resolution:
(none) =>
OLD |