mirror of
git://git.yoctoproject.org/poky
synced 2026-09-27 14:16:51 +00:00
I believe the time has come to do this: openssl 1.0 upstream support stops at the end of 2019, and we do not want a situation where a supported YP release contains an unsupported version of a critical security component. Openssl 1.0 can still be utilized by depending on 'openssl10' recipe. (From OE-Core rev: 876466145f2da93757ba3f92177d0f959f5fe975) Signed-off-by: Alexander Kanavin <alexander.kanavin@linux.intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
72 lines
1.9 KiB
Diff
72 lines
1.9 KiB
Diff
From 83f318d68bbdab1ca898c94576a838cc97df4700 Mon Sep 17 00:00:00 2001
|
|
From: Ludwig Nussel <ludwig.nussel@suse.de>
|
|
Date: Wed, 21 Apr 2010 15:52:10 +0200
|
|
Subject: [PATCH] also create old hash for compatibility
|
|
|
|
Upstream-Status: Backport [debian]
|
|
|
|
Index: openssl-1.0.2n/tools/c_rehash.in
|
|
===================================================================
|
|
--- openssl-1.0.2n.orig/tools/c_rehash.in
|
|
+++ openssl-1.0.2n/tools/c_rehash.in
|
|
@@ -8,8 +8,6 @@ my $prefix;
|
|
|
|
my $openssl = $ENV{OPENSSL} || "openssl";
|
|
my $pwd;
|
|
-my $x509hash = "-subject_hash";
|
|
-my $crlhash = "-hash";
|
|
my $verbose = 0;
|
|
my $symlink_exists=eval {symlink("",""); 1};
|
|
my $removelinks = 1;
|
|
@@ -18,10 +16,7 @@ my $removelinks = 1;
|
|
while ( $ARGV[0] =~ /^-/ ) {
|
|
my $flag = shift @ARGV;
|
|
last if ( $flag eq '--');
|
|
- if ( $flag eq '-old') {
|
|
- $x509hash = "-subject_hash_old";
|
|
- $crlhash = "-hash_old";
|
|
- } elsif ( $flag eq '-h') {
|
|
+ if ( $flag eq '-h') {
|
|
help();
|
|
} elsif ( $flag eq '-n' ) {
|
|
$removelinks = 0;
|
|
@@ -113,7 +108,9 @@ sub hash_dir {
|
|
next;
|
|
}
|
|
link_hash_cert($fname) if($cert);
|
|
+ link_hash_cert_old($fname) if($cert);
|
|
link_hash_crl($fname) if($crl);
|
|
+ link_hash_crl_old($fname) if($crl);
|
|
}
|
|
}
|
|
|
|
@@ -146,6 +143,7 @@ sub check_file {
|
|
|
|
sub link_hash_cert {
|
|
my $fname = $_[0];
|
|
+ my $x509hash = $_[1] || '-subject_hash';
|
|
$fname =~ s/'/'\\''/g;
|
|
my ($hash, $fprint) = `"$openssl" x509 $x509hash -fingerprint -noout -in "$fname"`;
|
|
chomp $hash;
|
|
@@ -177,10 +175,20 @@ sub link_hash_cert {
|
|
$hashlist{$hash} = $fprint;
|
|
}
|
|
|
|
+sub link_hash_cert_old {
|
|
+ link_hash_cert($_[0], '-subject_hash_old');
|
|
+}
|
|
+
|
|
+sub link_hash_crl_old {
|
|
+ link_hash_crl($_[0], '-hash_old');
|
|
+}
|
|
+
|
|
+
|
|
# Same as above except for a CRL. CRL links are of the form <hash>.r<n>
|
|
|
|
sub link_hash_crl {
|
|
my $fname = $_[0];
|
|
+ my $crlhash = $_[1] || "-hash";
|
|
$fname =~ s/'/'\\''/g;
|
|
my ($hash, $fprint) = `"$openssl" crl $crlhash -fingerprint -noout -in '$fname'`;
|
|
chomp $hash;
|