Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:3401 - Bug Fix Advisory
Issued:
2025-03-31
Updated:
2025-03-31

RHBA-2025:3401 - Bug Fix Advisory

  • Overview
  • Updated Packages

Synopsis

CA bug fix and enhancement update

Type/Severity

Bug Fix Advisory

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated CA packages that fix several bugs and add various enhancements are now available.

Description

Red Hat Certificate System (RHCS) is a complete implementation of an
enterprise software system designed to manage enterprise Public Key
Infrastructure (PKI) deployments.

Many of the subcomponents that comprise RHCS, such the Tomcat servlet
container, the RESTEasy framework, and the Network Security Services (NSS)
libraries, are provided by the base operating system. RHCS only supports
the default versions of these subcomponents that ship with Red Hat
Enterprise Linux 8.10.

This update fixes the following bugs:

Enhancement(s) and Bug fix(es):

Unable to add TPS profile via TPS UI (BZ1875637)

Cloning KRA with HSM is failing with the error 'auditSigningCert cert-topology-02-KRA KRA is invalid: Invalid certificate: (-8101) Certificate type not approved for application.' in KRA clone debug log (BZ1911262)

ca-profile-add failing for profile with 1day validity (BZ2012873)

Directory authentication plugin requires directory admin password just for user authentication (rhcs-10.8) (BZ2017514)

[RFE] kra-key-find CLI doesn't have the option to fetch keys corresponding to a specific token owner (BZ2045101)

Unable to list/search certificates based on Token ID in the TPS UI (BZ2049901)

Unable to enroll certificate with JSON inputs (BZ2053189)

TPS web UI not accessible using default admin cert (BZ2054227)

certificate decoding - Identifier: 2.5.29.54 / inhibitAnyPolicy "pretty print" is not interpreted (BZ2061596)

<subsystem>-user-membership-add allows adding members that do not exist (BZ2070335)

change the redhat-pki module Summary field to show the product version (BZ2079635)

CVE-2022-2393 redhat-pki:10/pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [certificate_system_10] (BZ2101897)

Unable to start PKI subsystems while DS is down (BZ2104161)

CVE-2022-2393 pki-core: When using the caServerKeygen_DirUserCert profile, user can get certificates for other UIDs by entering name in Subject field [rhcs_10.8] (BZ2111476)

pkcs7-encryptedData parsing error (BZ2115765)

Some unsusable profiles are present in CA's EE page [RHCS 10.8] (BZ2118663)

"Request in queue" listener no longer listens (BZ2126212)

pki pkcs12-key-del operation converting the hex key to decimal in output result (BZ2127190)

TPS token status cannot be changed from the web UI (BZ2165098)

TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False [RHCS 10.8] (BZ2166002)

module install redhat-pki fetching resteasy from RHEL Appstream instead of RHCS repo (BZ2177616)

Unable to use the TPS UI "Token Filter" to filter a list of tokens [RHCS 10.8] (BZ2178816)

Unable to use the TPS UI "Token Filter" to filter a list of tokens [RHCS 10.3] (BZ2179306)

add AES support for TMS server-side keygen on latest HSM / FIPS environment [RHCS 10.8] (BZ2180922)

Coolkey Hardcoded RSA Max Key Size [RHCS 10.6] (BZ2180926)

TPS Not allowing Token Status Change based on Revoke True/False and Hold till last True/False (part 2) [RHCS 10.6] (BZ2181144)

SHA1 is not working with RHCS 10.8 (BZ2182085)

Request id and cert serial num are shown in Dec number instead of hex in Audit logs (BZ2182836)

Generate a CSR in two step installation with non default SKI value in CA config file is failing (BZ2184288)

pki instance creation fails for IPA server in FIPS mode [rhcs-10.8] (BZ2184486)

User-friendly error and error message optimization required at PKI ca-audit-mod --input junk_file.conf instead of 'com.fasterxml.jackson.core.JsonParseException: Unrecognized token' error [rhcs-10.8] (BZ2184488)

PKI CLI operation parses the wrong result for i18n characters like 'OrjanAke' [rhcs-10.8] (BZ2184490)

pki-healthcheck ClonesConnectivyAndDataCheck fails [rhcs-10.8] (BZ2184491)

pki pkcs12-cert-add command failing with 'Unable to validate PKCS #12 file: Digests do not match' exception [rhcs-10.8] (BZ2184493)

IdM Install fails on RHEL 8.5 Beta when DISA STIG is applied [rhcs-10.8] (BZ2184494)

kra-key-retrieve failed to accept xml input format to generate .p12 key through cli [rhcs-10.8] (BZ2184497)

Verify bug #2046023 is resolved on RHCS 10.8 (BZ2184498)

CA installation failing with HSM [rhcs-10.8] (BZ2184504)

Error displayed should be user friendly in case RSNv3 certificate serial number collision [rhcs-10.8] (BZ2184505)

Volkswagen Siemens CardOS M4.4 and 5.0 cards display incorrect status in ESC [rhcs-10.8] (BZ2184508)

[RFE] Random Serial Number v3 Support [rhcs-10.8] (BZ2184509)

CA installation with RSA/PSS signing algorithm is failing with error 'CertificateException: Unable to parse certificate data: java.lang.Exception: java.security.NoSuchProviderException: no such provider: Mozilla-JSS' [rhcs-10.8] (BZ2184510)

PKI cert-fix operation failing [rhcs-10.8] (BZ2184511)

SKI field is not reflected back in generated CSR while performing two step installation [rhcs-10.8] (BZ2184512)

Verify bug #2107336 is resolved on RHCS 10.8 (BZ2184513)

ESC does not detect smart cards and crashes upon launch [rhcs-10.8] (BZ2184516)

Verify bug #1960143 is resolved on RHCS 10.8 (BZ2184518)

ipa cert-request ssl error [rhcs-10.8] (BZ2184520)

Reinstall of the same ipa-replica fails with 'RuntimeError: CA configuration failed.' [rhcs-10.8] (BZ2184521)

[RFE] Provide EST Responder (RFC 7030) [rhcs-10.8] (BZ2184522)

[RFE] Automatic expired certificate purging [rhcs-10.8] (BZ2184523)

JSS cannot be properly initialized after using another NSS-backed security provider [rhcs-10.8] (BZ2184524)

pki-tomcat/kra unable to decrypt when using RSA-OAEP padding in RHEL9 with FIPS enabled [rhcs-10.8] (BZ2184525)

Invalid certificates with creation of subCA (pkispawn single step) [rhcs-10.8] (BZ2184526)

javax.activation and jaxb-api jar files are not found in redhat-pki-0:11.4.0-1 module (BZ2188716)

OCSP Responder signing algorithm displayed twice for first item (BZ2193458)

Implement ServerSide KeyGen Password Complexity Checks for pkcs12 (BZ2196889)

PrettyPrintCert does not properly translate AIA information into a readable format (BZ2203136)

CC: OCSP AddCRLServlet "SEVERE...NOT SUPPORTED" log messages (BZ2203220)

PrettyPrintCert does not properly translate Subject Information Access information into a readable format (BZ2209625)

OCSP responder to serve status check for itself using latest CRL (BZ2229983)

pki_cert_chain_path does not work with cert bundle (BZ2250162)

CRMFPopClient request fails with 'Keypair Generation failed' error with FIPS enabled setup (BZ2250716)

Make key wrapping algorithm configurable between AES-KWP and AES-CBC [RHCS 10.6] (BZ2253677)

CA subsystem failed to start after the In-place update from RHCS 10.4 to 10.8 (BZ2254196)

Generating Keys with no OpsFlagMask set - ThalesHSM integration (BZ2255155)

EMBARGOED CVE-2023-4727 redhat-pki:10/pki-core: dogtag ca: token authentication bypass vulnerability [certificate_system_10.8] (BZ2268351)

pkiconsole prioritizes incompatible version of java openjdk [RHCS 10.6] (BZ2270747)

Token key recovery fails due to incorrect CBC keywrapping algorithm being used when KWP is set (BZ2275139)

pki-server subsystem-cert-export fails when exporting CSR (BZ2276139)

Rename enableOCSP to enableRevocationCheck (BZ2279576)

Enable revocation verification using CRL-DP (BZ2279577)

CC: Need to fail CRL-dp cert validation when the CRL signer is missing CRLsign Key Usage in cert (BZ2283835)

CC: Need adequate audit message for case when OCSPsign EKU is missing from the OCSP signer cert (BZ2283840)

CC: Need adequate audit message for case when OCSPsign EKU is missing from the OCSP signer cert (BZ2283842)

EST: Add installation support with pkispawn (BZ2307330)

pki-server instance-externalcert-add failure message not clear when missing trust args (BZ2313660)

Cloned CA not adhering to NextRange for serial numbers (BZ2327302)

Command pki-server subsystem-cert-find fails with error ERROR: object of type 'generator' has no len() (BZ2327705)

CA installation is failing with AVC denial (read) comm="java" name="conf" error (BZ2329318)

Error message for exhausted request range displays hexidecimal serial number from wrong variable as the maximum (BZ2332610)

PKI debug log rotation not working (BZ2332976)

Admin certificate (ca_admin_cert.p12) not updated correctly in multiple CA installations (BZ2341931)

Legacy endpoint '/ca/ug' is not available [RHCS 10.8] (BZ2342330)

Pkidestroy should remove all susbsystems and "pkiserver instance-find" should show no susbsystems left (BZ2342383)

Cert fix operation fails with - ERROR: 'Namespace' object has no attribute 'ldap_socket' (BZ2343298)

pkiconsole has incorrect sizing of buttons and missing button text (BZ2350123)

java-17-openjdk is not installed as a dependency for redhat-pki-console (BZ2350212)

Typos in user messages related to serial management V2 (BZ2350218)

EST: matching client auth cert with CSR (BZ2350630)

TPS subsystem cert unable to unwrap shared secret and TPS install fails with pki_import_shared_secret=True config (BZ2351094)

Users of Red Hat Certificate System are advised to upgrade to these updated
packages.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Certificate System 10.8 x86_64

Fixes

  • BZ - 2127190 - pki pkcs12-key-del operation converting the hex key to decimal in output result
  • BZ - 2177616 - module install redhat-pki fetching resteasy from RHEL Appstream instead of RHCS repo
  • BZ - 2178816 - Unable to use the TPS UI "Token Filter" to filter a list of tokens [RHCS 10.8]
  • BZ - 2196889 - Implement ServerSide KeyGen Password Complexity Checks for pkcs12
  • BZ - 2327302 - Cloned CA not adhering to NextRange for serial numbers
  • BZ - 2350630 - EST: matching client auth cert with CSR

CVEs

(none)

References

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Certificate System 10.8

SRPM
apache-commons-logging-1.2-33.module+el8pki+22719+1e38f097.src.rpm SHA-256: b977889bc090c113357be44fdf72dce49515a651d027a42a9d40fd2798db108b
jss-5.6.0-2.module+el8pki+22942+ec484924.src.rpm SHA-256: 1a1eecf74d57b139999447eb76befdc8a1df1ec234c74cb79942d3768dea4bbd
ldapjdk-5.6.0-2.module+el8pki+22942+ec484924.src.rpm SHA-256: edce584631391ff6db3ca64d43d6bd92b7e4c971e9aae8512354dea7b224bd0e
redhat-pki-11.6.1-2.module+el8pki+22942+ec484924.src.rpm SHA-256: aa1263a98a62ffc6cbd15cc3183c1df404cbaca46d89395f58259c900d2c60f9
x86_64
apache-commons-logging-1.2-33.module+el8pki+22719+1e38f097.noarch.rpm SHA-256: a217adf346de4a8cb52f11c6b42906bd05440af98cb359d5e900e10c385687ed
apache-commons-logging-javadoc-1.2-33.module+el8pki+22719+1e38f097.noarch.rpm SHA-256: 7720a7126bc9d1c93fdda97bbef1075eadb1abc99b4b3821aa14c47d2db328b8
jss-debuginfo-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: 8481dbcc0ba09957800e68940bc161158b04b637baa3ca4037ebabf1abea8da6
jss-debugsource-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: 6f5021627ddfabec14a43ca711547ceeb1dedb4deb91936d70dc53632826ee49
python3-redhat-pki-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: a8cb3c571ecb1050a80376dd6aca624e87c9aa87093026a300292ba6b2efc3b1
redhat-jss-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: a326f70b5c51249bbb454370e0bee74a731a19737f1f60ec5ed4184473f74b4d
redhat-jss-debuginfo-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: acdb6457a226e9baf9b3d0fb29e99f3fbed9d683f7222cdfd3bc3b76ced7d247
redhat-jss-javadoc-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: bba22bc5b2f62f12b52214da82baa128ec466e49d1993723d3ff74def76a01f0
redhat-jss-tomcat-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: c07819fc43839720e462b7b4491ddd137302dd21726e023d7efee6ff873099e9
redhat-jss-tools-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: f24c5ed15ebcfb2dd10a82022a1b1b3b8abfb1c0c3a7f3cb70765577811a1db5
redhat-jss-tools-debuginfo-5.6.0-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: 417198487cd119ff39abf399ea1683f2f5b666c93a6a1467ff9d8099747f19d8
redhat-ldapjdk-5.6.0-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 9e2b277f7521e6b01e6568735a2eb4395b2341c41083207078aa0d0143b5e28a
redhat-ldapjdk-javadoc-5.6.0-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: eee38613212186a416f4850d8a4ebe660f2143ab89dcde4ff91345b4fd0d5b95
redhat-pki-11.6.1-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: dc34c419f5de8d5ad43530acf3d602288e4402f2dd480eafbace83c2a4add458
redhat-pki-acme-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 9e566ed8988e01d7e2856f4541ae3a6f8f2d0ad70eff46c09d4b031b00effb97
redhat-pki-base-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 83ec25b5bd2b52a8273541d5e125daa34dfbae2523116b2db309f681327299a8
redhat-pki-ca-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 2300d8676bf7dfdb3115ab5002612e26fefd233e92ab4e2c9f7ab5a0a15480a8
redhat-pki-console-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 2d6956c279ca438aa81ef579d9a8127be8e672008ec61a22d6b5e80f5e382c6b
redhat-pki-console-theme-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 7fbe74e33ac4807b0c208a76ecb176f571908424eb4bf29b05658f09c845c05a
redhat-pki-debugsource-11.6.1-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: 4817720557e120effdd2d85fbcc16b56d01edfc6b3034373c37262fa5835aed9
redhat-pki-est-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 2def7302c0a02f2a7a7fccc86bfadbe3495aa88ba97d16d778d6976aecb29d77
redhat-pki-java-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 28c4f1a42065da5d6214d1611f98eab562229f6db3d124e4027766e4339c1acc
redhat-pki-javadoc-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: c019cebbfa9c84acf8e17edae93f6706298b68c7148231eb76eacf2e78e95f57
redhat-pki-kra-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 7b7daff6e89b585636e5c66dfef0de7347706500fb2747e00b096fadca5a2e3c
redhat-pki-ocsp-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: d49be4110379a4c755e8fbe05e495205b4e073b27eb660a195c64d6f9cc60f89
redhat-pki-server-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 866c06b69e2eb0b3c131cdff90382e9f9fe2e6a6e8f4c84970ff270ea77c2602
redhat-pki-theme-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 5fe221c05fd8b15cbde06a5e31e9bbab3db8a5a4a90f9e070cade7bbf3cee163
redhat-pki-tks-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: 2a73fa168bf728f85b4a1238d2db50b26318446652036274ac231d45267001af
redhat-pki-tools-11.6.1-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: 1266a42775693ef04dbf5335c738fbeaadf8746deacd5bdc96ea4a5df582a660
redhat-pki-tools-debuginfo-11.6.1-2.module+el8pki+22942+ec484924.x86_64.rpm SHA-256: ea3f7641d328d46635356de7f9a1e42aa87e59bcbe67f159b89099c0866ae7bf
redhat-pki-tps-11.6.1-2.module+el8pki+22942+ec484924.noarch.rpm SHA-256: d7bc6f6bd12913717e117269c0cde8ddc617d9881c205b0da392ec57f1e85c4a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility