Bug 250299 - 11.4-p3 update removes links & files under /etc/ssl/certs/
Summary: 11.4-p3 update removes links & files under /etc/ssl/certs/
Status: New
Alias: None
Product: Base System
Classification: Unclassified
Component: misc (show other bugs)
Version: 11.4-RELEASE
Hardware: Any Any
: --- Affects Only Me
Assignee: freebsd-bugs (Nobody)
URL:
Keywords:
: 250300 (view as bug list)
Depends on:
Blocks:
 
Reported: 2020-10-12 15:52 UTC by heas
Modified: 2020-10-12 18:21 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description heas 2020-10-12 15:52:56 UTC
Installing 11.4-p3 removed files in /etc/ssl/certs.  From a zfs diff:

-       /etc/ssl/certs/apache.pem
-       /etc/ssl/certs/dovecot.pem
-       /etc/ssl/certs/postfix.pem
M       /etc/ssl/certs
-       /etc/ssl/certs/postfix.pem.old
-       /etc/ssl/certs/dovecot.pem.old
-       /etc/ssl/certs/imapd.pem.old
-       /etc/ssl/certs/nginx.key
-       /etc/ssl/certs/nginx.pem
+       /etc/ssl/blacklisted

It does not recur if the machine is rebooted, so it was not a rc script that removed it.
Comment 1 Michael Osipov 2020-10-12 18:06:04 UTC
You are incorrectly using/abusing this directory. It is solely meant to be used for hashed CA certificate links for be consumed by OpenSSL when verifying a peer. Do not put your certs into it.
Comment 2 Mark Linimon freebsd_committer freebsd_triage 2020-10-12 18:21:16 UTC
*** Bug 250300 has been marked as a duplicate of this bug. ***