stunnel/stunnel-5-sample.patch
Avesh Agarwal 2b02b2d361 rhbz#1108818: New upstream realease 5.02
- Updated local patches
- The rhbz#530950 is tested and seems to work. STRLEN has
  been no longer allocated statically since 4.36 version.
  So it is possible that this bz might have got fixed
  around 4.36 release.
- Fixes rpmlint errors
2014-07-14 14:39:31 -04:00

40 lines
1.6 KiB
Diff

diff -urNp stunnel-5.02-patched/tools/stunnel.conf-sample.in stunnel-5.02-current/tools/stunnel.conf-sample.in
--- stunnel-5.02-patched/tools/stunnel.conf-sample.in 2014-07-14 13:12:23.093008573 -0400
+++ stunnel-5.02-current/tools/stunnel.conf-sample.in 2014-07-14 13:22:38.431698073 -0400
@@ -9,7 +9,7 @@
; A copy of some devices and system files is needed within the chroot jail
; Chroot conflicts with configuration file reload and many other features
-;chroot = @prefix@/var/lib/stunnel/
+;chroot = @localstatedir@/run/stunnel/
; Chroot jail can be escaped if setuid option is not used
setuid = nobody
setgid = @DEFAULT_GROUP@
@@ -26,8 +26,8 @@ setgid = @DEFAULT_GROUP@
; **************************************************************************
; Certificate/key is needed in server mode and optional in client mode
-cert = @prefix@/etc/stunnel/mail.pem
-;key = @prefix@/etc/stunnel/mail.pem
+cert = @sysconfdir@/stunnel/mail.pem
+;key = @sysconfdir@/stunnel/mail.pem
; Authentication stuff needs to be configured to prevent MITM attacks
; It is not enabled by default!
@@ -36,12 +36,13 @@ cert = @prefix@/etc/stunnel/mail.pem
; CApath is located inside chroot jail
;CApath = /certs
; It's often easier to use CAfile
-;CAfile = @prefix@/etc/stunnel/certs.pem
+;CAfile = @sysconfdir@/stunnel/certs.pem
+;CAfile = @sysconfdir@/pki/tls/certs/ca-bundle.crt
; Don't forget to c_rehash CRLpath
; CRLpath is located inside chroot jail
;CRLpath = /crls
; Alternatively CRLfile can be used
-;CRLfile = @prefix@/etc/stunnel/crls.pem
+;CRLfile = @sysconfdir@/stunnel/crls.pem
; Disable support for insecure SSLv2 protocol
options = NO_SSLv2