-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
rhel-10.0
-
None
-
No
-
Low
-
rhel-sst-security-crypto
-
ssg_security
-
0.1
-
False
-
-
None
-
None
-
None
-
None
-
None
We used to ship /etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt before RHEL-50293,
now openssl consumes the CA roots in an exploded directory format.
But I'm afraid we have a leftover /etc/pki/ca-trust/extracted/openssl/README which became out of date.
We should consider removing /etc/pki/ca-trust/extracted/openssl altogether.