ovs-pki: Remove "online PKI" features and ovs-pki-cgi.
authorBen Pfaff <blp@nicira.com>
Fri, 3 Aug 2012 18:56:33 +0000 (11:56 -0700)
committerBen Pfaff <blp@nicira.com>
Mon, 6 Aug 2012 16:36:19 +0000 (09:36 -0700)
commit2562714aa5d065e26a7d03a59c01d76b27cfc1d2
treeff582ea7c53f18684478d9198364fbcebb459cf6
parent79b8c36c58f979296ce2cec1e6d899fa8321bc21
ovs-pki: Remove "online PKI" features and ovs-pki-cgi.

Debian bug #683665, Red Hat bug #845350, and CVE-2012-3449 all claim that
ovs-pki's "incoming" directory is a security vulnerability.  I do not think
that this is the case, but I do not know of any users for this feature, so
on balance I prefer to remove it and the ovs-pki-cgi program associated
with it, just to be sure.

CVE-2012-3449.
Bug-report: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683665
Bug-report: https://bugzilla.redhat.com/show_bug.cgi?id=84535
Reported-by: Andreas Beckmann <debian@abeckmann.de>
Signed-off-by: Ben Pfaff <blp@nicira.com>
NEWS
utilities/automake.mk
utilities/ovs-pki-cgi.in [deleted file]
utilities/ovs-pki.8.in
utilities/ovs-pki.in