From 52d608c4cba64fadba556e4ff36cdaadafbb1b71 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 7 Oct 2025 12:07:26 +0200 Subject: [PATCH] Update OpenSSL certificates set up Resolves: RHEL-118293 --- sblim-sfcb-1.4.9-ssl-certs-gen-changes.patch | 71 ++++++++++++++++++++ sblim-sfcb.spec | 6 ++ 2 files changed, 77 insertions(+) create mode 100644 sblim-sfcb-1.4.9-ssl-certs-gen-changes.patch diff --git a/sblim-sfcb-1.4.9-ssl-certs-gen-changes.patch b/sblim-sfcb-1.4.9-ssl-certs-gen-changes.patch new file mode 100644 index 0000000..b8e7653 --- /dev/null +++ b/sblim-sfcb-1.4.9-ssl-certs-gen-changes.patch @@ -0,0 +1,71 @@ +diff -up sblim-sfcb-1.4.9/genSslCert.sh.orig sblim-sfcb-1.4.9/genSslCert.sh +--- sblim-sfcb-1.4.9/genSslCert.sh.orig 2014-11-25 02:43:10.000000000 +0100 ++++ sblim-sfcb-1.4.9/genSslCert.sh 2025-10-07 11:23:59.201504832 +0200 +@@ -4,6 +4,44 @@ HOSTNAME=`uname -n` + DO_SERVER=yes + DO_CLIENT=yes + DIR=`mktemp -d /var/tmp/sfcb.XXXXXX` || exit 1 ++DAYS=365 ++# Get minimum RSA key length at current security level ++# This workarounds openssl not enforcing min. key length enforced by current security level ++KEYSIZE=`grep min_rsa_size /etc/crypto-policies/state/CURRENT.pol 2>/dev/null | cut -d ' ' -f 3` ++if [ -z "$KEYSIZE" ]; then ++ KEYSIZE=2048 # fallback to safe default ++fi ++ ++function create_ssl_cnf() ++{ ++cat > $DIR/ssl.cnf < $DIR/ssl.cnf <sblim-sfcb.sysusers.conf < - 1.4.9-26 +- Update OpenSSL certificates set up + Resolves: RHEL-118293 - Eliminate use of obsolete %patchN syntax Related: RHEL-91101 - Add sysusers.d config file to allow rpm to create users/groups automatically