However, I don’t have access to it and I can’t even figure out how to enrol as a RH customer to get (paid) access. After clicking around on their website for almost an hour I’m totally frustrated and beginning to believe they don’t need money.
If someone here has access to the KB could you please send me that article and/or let me know how to enrol as a RH customer?
you need to get your org admin to create you an account tied to your company. that will let you open tickets and stuff as you have actual entitlements.
Their account system is pretty … odd. User accounts belong to the customer account and can’t be independent. I recommend having 2 accounts, one tied to the employer and a personal one that you can use to manage any potential certifications.
Also, don’t so what a co-worker did and create your personal account with your work email address, so you have 2 accounts tied to the same email. They frequently log in with their personal account and freak out when they can’t open tickets.
Apply the latest cumulative patch for JBoss EAP 7.4. The fix for this issue has been incorporated in JBoss EAP 7.4.10+ (CP10)
Apply the latest cumulative patch for RH-SSO 7.6. The fix for this issue has been incorporated in RH-SSO 7.6.4+ by RHSA-2023:3892
Downgrade Java to 1.8.0_351 / 11.0.17 / 17.0.5 or earlier as a workaround until updating to the versions that include the fix.
Root Cause
CVE-2023-1108 / Bugzilla 2174246
Java 1.8.0_361+, 11.0.18+ and 17.0.6+ changes increases the possibility of SSLEngineResult.writeRecord returning a CLOSED/NEED_WRAP state for a client abruptly terminating an SSL handshake:
JDK-8273553
Undertow does not currently handle this state and falls into a busy loop:
Also, make sure you set a calendar reminder for a year after you created the free developer account. They don’t send you a reminder that your account is expiring, and it can be a real hassle when it expires and you need it. Unfortunately, you can’t renew early (that I can tell), so you have to do it the day it expires. I could be wrong, but last time, I tried to renew my developer account early and it didn’t work. If there’s a way, feel free to correct me.
Until you lose access in a year and have start a new subscription and you have to wait for whatever to happen on backend to acknowledge the new subscription. I recently lost access for like 24 hrs.