Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-67930

drop /etc/pki/ca-trust/extracted/openssl

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • No
    • Low
    • 1
    • rhel-security-crypto
    • ssg_security
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • Crypto25August
    • Hide

      /etc/pki/ca-trust/extracted/openssl is no longer shipped [/CoreOS/ca-certificates/Sanity/filelist already expects it not to]

      Show
      /etc/pki/ca-trust/extracted/openssl is no longer shipped [/CoreOS/ca-certificates/Sanity/filelist already expects it not to]
    • Pass
    • None
    • None

      We used to ship /etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt before RHEL-50293,
      now openssl consumes the CA roots in an exploded directory format.

      But I'm afraid we have a leftover /etc/pki/ca-trust/extracted/openssl/README which became out of date.
      We should consider removing /etc/pki/ca-trust/extracted/openssl altogether.

              fkrenzel František Krenželok
              asosedki@redhat.com Alexander Sosedkin
              František Krenželok František Krenželok
              Alexander Sosedkin Alexander Sosedkin
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: