From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: [PATCH] del_rand: Deletion of RAND file in openssl config Date: Tue, 29 Jan 2019 13:51:20 +0000 Message-ID: <7F378D72-5CB1-4911-ABA9-008F72ECF87C@ipfire.org> In-Reply-To: <46ec14e20a50fac15924ef1f2dc624882f0d7fbe.camel@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1597746044924128776==" List-Id: --===============1597746044924128776== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit What is the reason that openssl.cnf is excluded in the updater? > On 29 Jan 2019, at 13:17, ummeegge wrote: > > Just as a reminder cause i havenĀ“t found it in Git, this one might be > important for the OpenSSL update and IPSec. > > Best, > > Erik > > > Am Dienstag, den 08.01.2019, 20:33 +0100 schrieb Erik Kapfer: >> Fixes #11943 >> >> Since the kernel RNG should do this, there is no need for this >> anymore. >> >> Signed-off-by: Erik Kapfer >> --- >> config/ovpn/openssl/ovpn.cnf | 2 -- >> config/ssl/openssl.cnf | 2 -- >> 2 files changed, 4 deletions(-) >> >> diff --git a/config/ovpn/openssl/ovpn.cnf >> b/config/ovpn/openssl/ovpn.cnf >> index 40daf2a0a..96c3dcb09 100644 >> --- a/config/ovpn/openssl/ovpn.cnf >> +++ b/config/ovpn/openssl/ovpn.cnf >> @@ -1,5 +1,4 @@ >> HOME = . >> -RANDFILE = /var/ipfire/ovpn/ca/.rnd >> oid_section = new_oids >> >> [ new_oids ] >> @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem >> serial = $dir/certs/serial >> crl = $dir/crl.pem >> private_key = $dir/ca/cakey.pem >> -RANDFILE = $dir/ca/.rand >> x509_extensions = usr_cert >> default_days = 999999 >> default_crl_days = 30 >> diff --git a/config/ssl/openssl.cnf b/config/ssl/openssl.cnf >> index 9d1e6e1ff..3b980fcd4 100644 >> --- a/config/ssl/openssl.cnf >> +++ b/config/ssl/openssl.cnf >> @@ -1,5 +1,4 @@ >> HOME = . >> -RANDFILE = /var/tmp/.rnd >> oid_section = new_oids >> >> [ new_oids ] >> @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem >> serial = $dir/certs/serial >> crl = $dir/crls/cacrl.pem >> private_key = $dir/private/cakey.pem >> -RANDFILE = $dir/tmp/.rand >> x509_extensions = usr_cert >> default_days = 999999 >> default_crl_days= 30 > --===============1597746044924128776==--