Skip to content

Conversation

albertzaharovits
Copy link
Contributor

There was a NONE certificate validation creeping. NONE Certificate validation is a no-no on a fips JVM, thanks @jkakavas for the pointer!

Closes #32673

@albertzaharovits albertzaharovits added >test-failure Triaged test failures from CI v7.0.0 :Security/Security Security issues without another label v6.5.0 v6.4.1 labels Aug 9, 2018
@albertzaharovits albertzaharovits self-assigned this Aug 9, 2018
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security

Copy link
Contributor

@bizybot bizybot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thank you.

@albertzaharovits
Copy link
Contributor Author

Forgot to unmute test 😠 ....
Thanks Yogesh!

@albertzaharovits albertzaharovits merged commit 1dcf807 into elastic:master Aug 10, 2018
@albertzaharovits albertzaharovits deleted the fix-32673 branch August 10, 2018 16:37
albertzaharovits added a commit that referenced this pull request Aug 10, 2018
Certificate NONE not allowed when running in a FIPS JVM
albertzaharovits added a commit that referenced this pull request Aug 10, 2018
Certificate NONE not allowed when running in a FIPS JVM
jasontedor added a commit to jasontedor/elasticsearch that referenced this pull request Aug 13, 2018
…listeners

* elastic/master: (58 commits)
  [ML] Partition-wise maximum scores (elastic#32748)
  [DOCS] XContentBuilder#bytes method removed, using BytesReference.bytes(docBuilder) (elastic#32771)
  HLRC: migration get assistance API (elastic#32744)
  Add a task to run forbiddenapis using cli (elastic#32076)
  [Kerberos] Add debug log statement for exceptions (elastic#32663)
  Make x-pack core pull transport-nio (elastic#32757)
  Painless: Clean Up Whitelist Names (elastic#32791)
  Cat apis: Fix index creation time to use strict date format (elastic#32510)
  Clear Job#finished_time when it is opened (elastic#32605) (elastic#32755)
  Test: Only sniff host metadata for node_selectors (elastic#32750)
  Update scripted metric docs to use `state` variable (elastic#32695)
  Painless: Clean up PainlessCast (elastic#32754)
  [TEST] Certificate NONE not allowed in FIPS JVM (elastic#32753)
  [ML] Refactor ProcessCtrl into Autodetect and Normalizer builders (elastic#32720)
  Access build tools resources (elastic#32201)
  Tests: Disable rolling upgrade tests with system key on fips JVM (elastic#32775)
  HLRC: Ban LoggingDeprecationHandler (elastic#32756)
  Fix test reproducability in AbstractBuilderTestCase setup (elastic#32403)
  Only require java<version>_home env var if needed
  Tests: Muted ScriptDocValuesDatesTests.testJodaTimeBwc
  ...
@jimczi jimczi added v7.0.0-beta1 and removed v7.0.0 labels Feb 7, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Security/Security Security issues without another label >test-failure Triaged test failures from CI v6.4.1 v6.5.0 v7.0.0-beta1
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants