Recommended update for libica

Announcement ID: SUSE-RU-2020:2816-2
Rating: moderate
References:
Affected Products:
  • Certifications Module 15-SP3
  • SUSE Linux Enterprise Desktop 15 SP3
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise Real Time 15 SP3
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3

An update that has three fixes can now be installed.

Description:

This update for libica fixes the following issues:

Various FIPS related fixes have been applied:

  • Fix lack of SHA3 KATs in "make check" processing (bsc#1175277)
  • Fix FIPS hmac check (bsc#1175356).
  • Update FIPS support to upstream
  • FIPS check should fail when hmac is missing
    • Create an hmac for the selftest
    • Check that selftest fails without a hmac
    • Hash libica.so.3 rather than libica.so.3.6.0
  • Fix Some internal variables used to store sensitive information (keys) were not zeroized before returning to the calling application. (bsc#1175357)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Certifications Module 15-SP3
    zypper in -t patch SUSE-SLE-Module-Certifications-15-SP3-2022-2429=1

Package List:

  • Certifications Module 15-SP3 (s390x)
    • libica-devel-static-3.6.0-5.3.1
    • libica-tools-debuginfo-3.6.0-5.3.1
    • libica-debugsource-3.6.0-5.3.1
    • libica3-3.6.0-5.3.1
    • libica-tools-3.6.0-5.3.1
    • libica-devel-3.6.0-5.3.1
    • libica3-debuginfo-3.6.0-5.3.1

References: