ad-password arrow-down-ring arrow-left arrow-right auto-select cog customer-id excel-statistics external-link featured github icn-admin icn-developer icn-evaluierung icn-installation icn-keyuser icn-konzeptionierung icn-master icn-performance icn-review last-contact linkedin map-person messages multi-upload no-eye out-of-office password-guidlines pending-time phone plus proxy-support quick-close search service-catalog setting-search shield sugarcrm-integration tag-cloud ticket-create twitter watch-arrow watchlist xing

ZSA-2020-10

Problems distinguishing downloaded certificate files

Problem

Downloaded PGP or S/MIME certificate files will have the same name for the public and private key. This might lead to accidentally disclosing the private key.

Solution

Upgrade to the latest available OTRS patch level (https://ftp.otrs.org/pub/otrs/).

Workaround

As a workaround, you can replace the affected files (see below for download).
Note on OTRS 5: There is no official OTRS release for this fix but you can use the OTRS 5 patch download below.

ATTENTION: Please check if any of these files have been changed in your OTRS installation by additional add-ons. In that case you MUST NOT simply overwrite the files with the ones provided below. Please contact us instead.

Download

References