diff --git a/java-17-openjdk.spec b/java-17-openjdk.spec index 23a4bbc..0cb26dd 100644 --- a/java-17-openjdk.spec +++ b/java-17-openjdk.spec @@ -303,7 +303,7 @@ %global top_level_dir_name %{origin} %global top_level_dir_name_backup %{top_level_dir_name}-backup %global buildver 12 -%global rpmrelease 1 +%global rpmrelease 2 # Priority must be 8 digits in total; up to openjdk 1.8, we were using 18..... so when we moved to 11, we had to add another digit %if %is_system_jdk # Using 10 digits may overflow the int used for priority, so we combine the patch and build versions @@ -1613,7 +1613,6 @@ sed -e "s:@NSS_LIBDIR@:%{NSS_LIBDIR}:g" %{SOURCE11} > nss.cfg # Setup nss.fips.cfg sed -e "s:@NSS_LIBDIR@:%{NSS_LIBDIR}:g" %{SOURCE17} > nss.fips.cfg -sed -i -e "s:@NSS_SECMOD@:/etc/pki/nssdb:g" nss.fips.cfg %build # How many CPU's do we have? @@ -2281,6 +2280,11 @@ cjc.mainProgram(args) %endif %changelog +* Mon Nov 29 2021 Severin Gehwolf - 1:17.0.1.0.12-2 +- Use 'sql:' prefix in nss.fips.cfg as F35+ no longer ship the legacy + secmod.db file as part of nss +- Related: RHEL-45216 + * Tue Nov 16 2021 Andrew Hughes - 1:17.0.1.0.12-1 - Drop JDK-8272332 patch now included upstream. - Related: RHEL-45216 diff --git a/nss.fips.cfg.in b/nss.fips.cfg.in index ead27be..1aff153 100644 --- a/nss.fips.cfg.in +++ b/nss.fips.cfg.in @@ -1,6 +1,6 @@ name = NSS-FIPS nssLibraryDirectory = @NSS_LIBDIR@ -nssSecmodDirectory = @NSS_SECMOD@ +nssSecmodDirectory = sql:/etc/pki/nssdb nssDbMode = readOnly nssModule = fips