What is the reason that openssl.cnf is excluded in the updater?
On 29 Jan 2019, at 13:17, ummeegge ummeegge@ipfire.org wrote:
Just as a reminder cause i havenĀ“t found it in Git, this one might be important for the OpenSSL update and IPSec.
Best,
Erik
Am Dienstag, den 08.01.2019, 20:33 +0100 schrieb Erik Kapfer:
Fixes #11943
Since the kernel RNG should do this, there is no need for this anymore.
Signed-off-by: Erik Kapfer ummeegge@ipfire.org
config/ovpn/openssl/ovpn.cnf | 2 -- config/ssl/openssl.cnf | 2 -- 2 files changed, 4 deletions(-)
diff --git a/config/ovpn/openssl/ovpn.cnf b/config/ovpn/openssl/ovpn.cnf index 40daf2a0a..96c3dcb09 100644 --- a/config/ovpn/openssl/ovpn.cnf +++ b/config/ovpn/openssl/ovpn.cnf @@ -1,5 +1,4 @@ HOME = . -RANDFILE = /var/ipfire/ovpn/ca/.rnd oid_section = new_oids
[ new_oids ] @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem serial = $dir/certs/serial crl = $dir/crl.pem private_key = $dir/ca/cakey.pem -RANDFILE = $dir/ca/.rand x509_extensions = usr_cert default_days = 999999 default_crl_days = 30 diff --git a/config/ssl/openssl.cnf b/config/ssl/openssl.cnf index 9d1e6e1ff..3b980fcd4 100644 --- a/config/ssl/openssl.cnf +++ b/config/ssl/openssl.cnf @@ -1,5 +1,4 @@ HOME = . -RANDFILE = /var/tmp/.rnd oid_section = new_oids
[ new_oids ] @@ -17,7 +16,6 @@ certificate = $dir/ca/cacert.pem serial = $dir/certs/serial crl = $dir/crls/cacrl.pem private_key = $dir/private/cakey.pem -RANDFILE = $dir/tmp/.rand x509_extensions = usr_cert default_days = 999999 default_crl_days= 30