Skip to main content

Bug (security): Jailshell is missing /etc/crypto-policies so breaks crypto-policies(7) enforcement

Comments

3 comments

  • cPRex Jurassic Moderator
    Hey there! Unless I'm not troubleshooting this correct, I see this working well in version 102, as I see the crypto-policies directory listed in /home/virtfs/username for the user with jailshell access on my test system. Since 102 will be the next version going to the LTS tier, it's not likely this will get changed in 94 at this point. Would you have a way to check and confirm on a version 102 system that this is working how you expect?
    0
  • Brian N
    Sigh... No, I didn't think to check for it in a newer version. It seemed major enough to be a 'if they knew about it it would be fixed in LTS' type of issue. Seems not. From v96 (!): CPANEL-36575: Add '/etc/crypto-policies/back-ends' to virtfs. I'm continually disappointed at how little 'support' LTS seems to get. What fixes do or don't get backported seems to be mostly arbitrary. This is the fourth or fifth bug I've had to chase down in recent memory only to find out "Oh it's fixed is a newer version...". Well why isn't it fixed in LTS? Especially something like this where I'd all but guarantee that the fix from 96 would work on 94 without modification. Not really much effort required there. Oh well. Thanks for looking at it.
    0
  • cPRex Jurassic Moderator
    It's always a combination of time, effort, and necessity, and how those all balance out. Some cases absolutely have to be backported, but many don't. There is still going to be at least one LTS build and I've let our team know you're interested in seeing this case make that build. I'm following along with the case now and I'll post here again if I do get an update.
    0

Please sign in to leave a comment.