Welcome To openEuler Community
Hey @liu_yangmei , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.
Contact Guide
If you have any questions, please contact the SIG: sig-security-facility ,
and any of the maintainers: @mailofzxf, @robertosassu, @zhujianwei001 ,
and any of the committers: @gcw_n2PeTU3z, @zcfsite .


以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:
| 指令 | 指令说明 | 使用权限 |
|---|---|---|
| /check-issue | 触发defect-manager校验 | 不限 |
| /reason xxx | /reason +挂起或取消条件 | 不限 |
影响性分析说明:
缺陷严重等级:(Critical/High/Moderate/Low)
缺陷根因说明:
受影响版本排查(受影响/不受影响):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP3:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP2:
abi变化(是/否):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP3:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP2:
缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue


初步分析非问题
openEuler-24.03 系列分支版本: 3.94.0
openEuler-26.09 系列分支版本: 3.120.1
3.94.0 certutil -M 修改证书信任标志被归类为非敏感的元数据更新,允许在未提供有效主密码文件时静默执行;
3.120.1 满足现代 FIPS 审计及防止无鉴权篡改的安全要求,nss统一收紧了受保护数据库,若命令未显式附加鉴权凭证(-f pwfile)则会交互式密码回显
保持兼容性测试 建议均使用显示方案
certutil -M -d . -n ca-self -t Cu,Cu,Cu -f pwfile // 将会进行无交互模式



@gcw_n2PeTU3z 未对受影响版本排查/abi变化进行分析


@gcw_n2PeTU3z 未对受影响版本排查/abi变化进行分析


@gcw_n2PeTU3z 未对受影响版本排查/abi变化进行分析


【缺陷描述】:请补充详细的缺陷问题现象描述
执行certutil -M参数回显变更,请确认
一、缺陷信息
执行certutil -M参数回显变更
【缺陷所属的os版本】
【内核版本】
6.6.0-163.0.0.1.oe2609
【缺陷所属软件及版本号】
nss-3.120.1-3.oe2609
【环境信息】
无
【问题复现步骤】
yum install -y gnutls-utils
echo "cn = test" > ca.tmpl
echo "expiration_days = 365" >> ca.tmpl
echo "ca" >> ca.tmpl
echo "signing_key" >> ca.tmpl
echo "cert_signing_key" >> ca.tmpl
echo "crl_signing_key" >> ca.tmpl
echo "cn = test.example.org" >> server.tmpl
echo "expiration_days = 365" >> server.tmpl
echo "tls_www_server" >> server.tmpl
echo "encryption_key" >> server.tmpl
echo "signing_key" >> server.tmpl
echo "email_protection_key" >> server.tmpl
echo "dns_name = localhost" >> server.tmpl
echo "123456" > pwfile
dd if=/dev/urandom bs=512 count=1 of=noise
certutil -N -d . -f pwfile
ls | grep db
certtool --generate-privkey --outfile ca-key.pem
certtool --generate-self-signed --load-privkey ca-key.pem --template ca.tmpl --outfile ca-cert.pem
certutil -A -n ca -t "C,C,C" -i ca-cert.pem -d . -f pwfile
certutil -L -d . | grep "ca"
certtool --generate-privkey --outfile server-key.pem
certtool --generate-certificate --load-privkey server-key.pem --load-ca-certificate ca-cert.pem --load-ca-privkey ca-key.pem --template server.tmpl --outfile server-cert.pem
certutil -E -n server -t "C,C,C" -i server-cert.pem -d . -f pwfile
certutil -L -d . | grep "server"
certutil -R -s 'CN=Test, C=US' -d . -f pwfile -a -o req.pem -z noise
cat req.pem | grep "BEGIN NEW CERTIFICATE REQUEST"
certutil -C -z noise -d . -n server-cert -s 'CN=Test, C=US' -t C,C,C -x -i req.pem -a -f pwfile -a -o server.pem
cat server.pem | grep "BEGIN CERTIFICATE"
certutil -S -z noise -d . -n ca-self -s 'CN=TestCA, C=US' -t C,C,C -x -f pwfile
certutil -L -d . | grep "ca-self"
certutil -M -d . -n ca-self -t Cu,Cu,Cu
【实际结果】
执行命令certutil -M -d . -n ca-self -t Cu,Cu,Cu时提示输入密码或证书的PIN

【期望结果】
无密码输入提示或确认变更是否合理
【其他相关附件信息】
【缺陷详情及分析指导参考链接】
二、缺陷分析结构反馈
影响性分析说明:
缺陷严重等级:(Critical/High/Moderate/Low)
缺陷根因说明:
受影响版本排查(受影响/不受影响):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2
修复是否涉及abi变化(是/否):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2