I merged it. For some reason I thought this was part of the OpenSSL patchset. Best, -Michael > On 29 Jan 2019, at 13:51, Michael Tremer wrote: > > What is the reason that openssl.cnf is excluded in the updater? > >> On 29 Jan 2019, at 13:17, ummeegge wrote: >> >> Just as a reminder cause i havenĀ“t found it in Git, this one might be >> important for the OpenSSL update and IPSec. >> >> Best, >> >> Erik >> >> >> Am Dienstag, den 08.01.2019, 20:33 +0100 schrieb Erik Kapfer: >>> Fixes #11943 >>> >>> Since the kernel RNG should do this, there is no need for this >>> anymore. >>> >>> Signed-off-by: Erik Kapfer >>> --- >>> config/ovpn/openssl/ovpn.cnf | 2 -- >>> config/ssl/openssl.cnf | 2 -- >>> 2 files changed, 4 deletions(-) >>> >>> diff --git a/config/ovpn/openssl/ovpn.cnf >>> b/config/ovpn/openssl/ovpn.cnf >>> index 40daf2a0a..96c3dcb09 100644 >>> --- a/config/ovpn/openssl/ovpn.cnf >>> +++ b/config/ovpn/openssl/ovpn.cnf >>> @@ -1,5 +1,4 @@ >>> HOME = . >>> -RANDFILE = /var/ipfire/ovpn/ca/.rnd >>> oid_section = new_oids >>> >>> [ new_oids ] >>> @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem >>> serial = $dir/certs/serial >>> crl = $dir/crl.pem >>> private_key = $dir/ca/cakey.pem >>> -RANDFILE = $dir/ca/.rand >>> x509_extensions = usr_cert >>> default_days = 999999 >>> default_crl_days = 30 >>> diff --git a/config/ssl/openssl.cnf b/config/ssl/openssl.cnf >>> index 9d1e6e1ff..3b980fcd4 100644 >>> --- a/config/ssl/openssl.cnf >>> +++ b/config/ssl/openssl.cnf >>> @@ -1,5 +1,4 @@ >>> HOME = . >>> -RANDFILE = /var/tmp/.rnd >>> oid_section = new_oids >>> >>> [ new_oids ] >>> @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem >>> serial = $dir/certs/serial >>> crl = $dir/crls/cacrl.pem >>> private_key = $dir/private/cakey.pem >>> -RANDFILE = $dir/tmp/.rand >>> x509_extensions = usr_cert >>> default_days = 999999 >>> default_crl_days= 30 >> >