[Puppet - Bug #1842] (Needs design decision) Net::HTTP#enable_post_connection_check doesn't work anymore

4 views
Skip to first unread message

red...@reductivelabs.com

unread,
Jun 12, 2009, 12:06:21 PM6/12/09
to and...@reductivelabs.com, puppe...@googlegroups.com, cai_...@emc.com, lu...@madstop.com
Issue #1842 has been updated by James Turnbull.
  • Category set to SSL
  • Status changed from Accepted to Needs design decision
  • Assigned to set to Luke Kanies

Luke?


Bug #1842: Net::HTTP#enable_post_connection_check doesn't work anymore

  • Author: Kevin Cai
  • Status: Needs design decision
  • Priority: High
  • Assigned to: Luke Kanies
  • Category: SSL
  • Target version:
  • Complexity: Unknown
  • Affected version: 0.24.7
  • Keywords: enable_post_connection_check

one of the #896 bug fixing, adding http_enable_post_connection_check option against the requested host name in new versions of ruby (see revision 36c947, f94d6d).

However, below changelog can be found from ruby rpms:

ruby-1.8.6.111-CVE-2007-5162.patch: Update a bit with backporting the changes
at trunk to enable the fix without any modifications on the users' scripts.
Note that Net::HTTP#enable_post_connection_check isn't available anymore.
If you want to disable this post-check, you should give OpenSSL::SSL::VERIFY_NONE
to Net::HTTP#verify_mode= instead of.

Since HTTP#enable_post_connection_check isn't avaiable anymore, but puppet doesn't give the corresponding fix.


You have received this notification because you have either subscribed to it, or are involved in it.
To change your notification preferences, please click here: http://reductivelabs.com/redmine/my/account

red...@reductivelabs.com

unread,
Jun 12, 2009, 12:11:46 PM6/12/09
to and...@reductivelabs.com, puppe...@googlegroups.com, cai_...@emc.com, lu...@madstop.com
Issue #1842 has been updated by James Turnbull.
  • Status changed from Needs design decision to Accepted
  • Affected version changed from 0.24.7 to 0.24.8
  • Author: Kevin Cai
  • Status: Accepted
  • Priority: High
  • Assigned to: Luke Kanies
  • Category: SSL
  • Target version:
  • Complexity: Unknown
  • Affected version: 0.24.8
  • Keywords: enable_post_connection_check

red...@reductivelabs.com

unread,
Dec 23, 2009, 5:09:12 PM12/23/09
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by Markus Roberts.
  • Status changed from Accepted to Investigating
  • Assigned to changed from Luke Kanies to Jesse Wolfe
  • Target version set to Puppet - 0.25.3

Set to investigating, as this was reported on 0.24.8 and may have been fixed already.

  • Author: Kevin Cai
  • Status: Investigating
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.3
  • Affected version: 0.24.8
  • Keywords: enable_post_connection_check
  • Branch:

red...@reductivelabs.com

unread,
Dec 29, 2009, 3:38:37 PM12/29/09
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by Jesse Wolfe.
  • Status changed from Investigating to Accepted

We're still setting this deprecated flag in 0.25.x

  • Author: Kevin Cai
  • Status: Accepted
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.3
  • Affected version: 0.24.8
  • Keywords: enable_post_connection_check
  • Branch:

red...@reductivelabs.com

unread,
Dec 29, 2009, 5:11:35 PM12/29/09
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by Jesse Wolfe.
  • Author: Kevin Cai
  • Status: Accepted
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.3
  • Affected version: 0.24.8
  • Keywords: enable_post_connection_check

red...@reductivelabs.com

unread,
Dec 29, 2009, 5:11:46 PM12/29/09
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by Jesse Wolfe.
  • Status changed from Accepted to Ready for Testing
  • Author: Kevin Cai
  • Status: Ready for Testing

red...@reductivelabs.com

unread,
Jan 7, 2010, 9:22:53 PM1/7/10
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by Markus Roberts.
  • Target version changed from Puppet - 0.25.3 to Puppet - 0.25.4
  • Author: Kevin Cai
  • Status: Ready for Testing
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.4

red...@reductivelabs.com

unread,
Jan 8, 2010, 9:53:11 PM1/8/10
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by James Turnbull.
  • Target version changed from Puppet - 0.25.4 to Puppet - 0.25.3
  • Author: Kevin Cai
  • Status: Ready for Testing
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.3

red...@reductivelabs.com

unread,
Jan 11, 2010, 6:36:10 PM1/11/10
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by James Turnbull.
  • Target version changed from Puppet - 0.25.3 to Puppet - 0.25.4
  • Author: Kevin Cai
  • Status: Ready for Testing
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.4

red...@reductivelabs.com

unread,
Jan 13, 2010, 10:09:26 PM1/13/10
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by James Turnbull.
  • Target version changed from Puppet - 0.25.4 to Puppet - 0.25.5
  • Author: Kevin Cai
  • Status: Ready for Testing
  • Priority: High
  • Assigned to: Jesse Wolfe
  • Category: SSL
  • Target version: 0.25.5

red...@reductivelabs.com

unread,
Jan 29, 2010, 5:34:52 PM1/29/10
to ja...@lovedthanlost.net, r...@devco.net, cai_...@emc.com, jes...@gmail.com, puppe...@googlegroups.com
Issue #1842 has been updated by James Turnbull.
  • Status changed from Ready for Testing to Closed

Pushed in commit:"b473264fe76f92b8eddeed7175c4283c9f8484d2" in branch 0.25.x

  • Author: Kevin Cai
  • Status: Closed
Reply all
Reply to author
Forward
0 new messages