Bug 4664 - rootcerts needs to be updated for upgrading from MDV 2010.2
Summary: rootcerts needs to be updated for upgrading from MDV 2010.2
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 1
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: validated_update
Depends on:
Blocks: 4405
  Show dependency treegraph
 
Reported: 2012-02-24 00:15 CET by David Walser
Modified: 2012-04-11 20:58 CEST (History)
5 users (show)

See Also:
Source RPM: rootcerts-20111103.00-2.1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-02-24 00:15:59 CET
In the newest Mandriva 2010.2 security update for the Mozilla apps, rootcerts was updated to the newest version.  We need to update it accordingly so that upgrading from MDV 2010.2 still works correctly.  It's possible that there are security implications with this update as well, I'm just not sure.  Also, the "nss" package apparently needs to be rebuilt whenever rootcerts is updated, so it will need a rebuild.

The version on the MDV rootcerts package is rootcerts-20120218.00-1mdv2010.2, so ours needs to be at least rootcerts-20120218.00-1.mga1.

IIRC, this package needs to be updated in Cauldron as well.
Comment 1 David Walser 2012-02-24 00:21:52 CET
Just an additional note, the timezone package is typically updated when rootcerts is, and although it wasn't updated in this MDV update, there is a newer version of that available, so now would be a good time to update it as well.
Comment 2 David Walser 2012-02-24 00:23:23 CET
Here's a link to the Mandriva advisory:
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:022
Manuel Hiebel 2012-02-24 20:53:58 CET

CC: (none) => dmorganec, jani.valimaa, pterjan

Comment 3 David Walser 2012-02-26 04:33:12 CET
Looks like not only does nss have to be rebuilt with this package, this (updating rootcerts) is generally done in conjunction with Firefox updates and nss is updated for those too.  There is a newer version of nss (now in Cauldron).

Blocks: (none) => 4405

Comment 4 David Walser 2012-02-26 04:39:55 CET
(In reply to comment #1)
> Just an additional note, the timezone package is typically updated when
> rootcerts is, and although it wasn't updated in this MDV update, there is a
> newer version of that available, so now would be a good time to update it as
> well.

Looks like that had already been updated in Mageia 1.  It hadn't been updated in Cauldron though (strange).  I just fixed that.
Jani Välimaa 2012-02-28 12:07:44 CET

CC: jani.valimaa => (none)

Comment 5 David Walser 2012-04-08 04:56:08 CEST
Updated packages uploaded.

Advisory:
========================

The rootcerts package was updated to allow updating from Mandriva 2010.2

Additionally, the nss package has been rebuilt to pick up the changes.

References:
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:022
========================

Updated packages in core/updates_testing:
========================
rootcerts-20120218.00-1.mga1
rootcerts-java-20120218.00-1.mga1
nss-3.13.1-0.3.mga1
nss-doc-3.13.1-0.3.mga1
libnss3-3.13.1-0.3.mga1
libnss-devel-3.13.1-0.3.mga1
libnss-static-devel-3.13.1-0.3.mga1

from SRPMS:
rootcerts-20120218.00-1.mga1.src.rpm
nss-3.13.1-0.3.mga1.src.rpm

Assignee: bugsquad => qa-bugs

Comment 6 Dave Hodgins 2012-04-10 23:43:25 CEST
Testing complete on i586 for the srpms
rootcerts-20120218.00-1.mga1.src.rpm
nss-3.13.1-0.3.mga1.src.rpm

Testing normal usage of rpm, and web browsing.  Also some of the examples
from
http://www.mozilla.org/projects/security/pki/nss/tools/certutil.html#1028724

CC: (none) => davidwhodgins

Comment 7 Manuel Hiebel 2012-04-11 01:28:50 CEST
Testing complete


Suggested Advisory:
-------------
The rootcerts package was updated to allow updating from Mandriva 2010.2

Additionally, the nss package has been rebuilt to pick up the changes.

References:
http://www.mandriva.com/en/support/security/advisories/?dis=2010.1&name=MDVSA-2012:022

https://bugs.mageia.org/show_bug.cgi?id=4664
-------------

SRPMs: 
rootcerts-20120218.00-1.mga1.src.rpm
nss-3.13.1-0.3.mga1.src.rpm

Could sysadmin please push from core/updates_testing to core/updates

Thankyou!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 8 Thomas Backlund 2012-04-11 20:58:29 CEST
Update pushed

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.