Recommended update for ipsec-tools

Announcement ID: SUSE-RU-2015:1220-1
Rating: moderate
References:
Affected Products:
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Server for SAP Applications 12

An update that has two fixes can now be installed.

Description:

This update allows ipsec-tools racoon to operate in FIPS mode.

  • MD5 algorithm usage has been replaced by SHA1 usage in a hash table, and for a remotely driven part allowed bsc#905780

  • The minimum RSA public exponent in plainrsa-gen has been raised from 3 to 65567. bsc#928313

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server 12
    zypper in -t patch SUSE-SLE-SERVER-12-2015-309=1
  • SUSE Linux Enterprise Server for SAP Applications 12
    zypper in -t patch SUSE-SLE-SERVER-12-2015-309=1

Package List:

  • SUSE Linux Enterprise Server 12 (ppc64le s390x x86_64)
    • ipsec-tools-debugsource-0.8.0-11.2
    • ipsec-tools-debuginfo-0.8.0-11.2
    • ipsec-tools-0.8.0-11.2
  • SUSE Linux Enterprise Server for SAP Applications 12 (x86_64)
    • ipsec-tools-debugsource-0.8.0-11.2
    • ipsec-tools-debuginfo-0.8.0-11.2
    • ipsec-tools-0.8.0-11.2

References: