Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[TEST] Certificate NONE not allowed in FIPS JVM #32753

Merged
merged 2 commits into from
Aug 10, 2018

Conversation

albertzaharovits
Copy link
Contributor

There was a NONE certificate validation creeping. NONE Certificate validation is a no-no on a fips JVM, thanks @jkakavas for the pointer!

Closes #32673

@albertzaharovits albertzaharovits added >test-failure Triaged test failures from CI v7.0.0 :Security/Security Security issues without another label v6.5.0 v6.4.1 labels Aug 9, 2018
@albertzaharovits albertzaharovits self-assigned this Aug 9, 2018
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security

Copy link
Contributor

@bizybot bizybot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thank you.

@albertzaharovits
Copy link
Contributor Author

Forgot to unmute test 😠 ....
Thanks Yogesh!

@albertzaharovits albertzaharovits merged commit 1dcf807 into elastic:master Aug 10, 2018
@albertzaharovits albertzaharovits deleted the fix-32673 branch August 10, 2018 16:37
albertzaharovits added a commit that referenced this pull request Aug 10, 2018
Certificate NONE not allowed when running in a FIPS JVM
albertzaharovits added a commit that referenced this pull request Aug 10, 2018
Certificate NONE not allowed when running in a FIPS JVM
jasontedor added a commit to jasontedor/elasticsearch that referenced this pull request Aug 13, 2018
…listeners

* elastic/master: (58 commits)
  [ML] Partition-wise maximum scores (elastic#32748)
  [DOCS] XContentBuilder#bytes method removed, using BytesReference.bytes(docBuilder) (elastic#32771)
  HLRC: migration get assistance API (elastic#32744)
  Add a task to run forbiddenapis using cli (elastic#32076)
  [Kerberos] Add debug log statement for exceptions (elastic#32663)
  Make x-pack core pull transport-nio (elastic#32757)
  Painless: Clean Up Whitelist Names (elastic#32791)
  Cat apis: Fix index creation time to use strict date format (elastic#32510)
  Clear Job#finished_time when it is opened (elastic#32605) (elastic#32755)
  Test: Only sniff host metadata for node_selectors (elastic#32750)
  Update scripted metric docs to use `state` variable (elastic#32695)
  Painless: Clean up PainlessCast (elastic#32754)
  [TEST] Certificate NONE not allowed in FIPS JVM (elastic#32753)
  [ML] Refactor ProcessCtrl into Autodetect and Normalizer builders (elastic#32720)
  Access build tools resources (elastic#32201)
  Tests: Disable rolling upgrade tests with system key on fips JVM (elastic#32775)
  HLRC: Ban LoggingDeprecationHandler (elastic#32756)
  Fix test reproducability in AbstractBuilderTestCase setup (elastic#32403)
  Only require java<version>_home env var if needed
  Tests: Muted ScriptDocValuesDatesTests.testJodaTimeBwc
  ...
@jimczi jimczi added v7.0.0-beta1 and removed v7.0.0 labels Feb 7, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Security/Security Security issues without another label >test-failure Triaged test failures from CI v6.4.1 v6.5.0 v7.0.0-beta1
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants