Bug 11296 - openssl.cnf not in expected location for openssl-native
Summary: openssl.cnf not in expected location for openssl-native
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: connectivity (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 2.3 M4
Assignee: Jussi Kukkonen
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2017-04-04 23:39 UTC by California Sullivan
Modified: 2017-04-19 12:51 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description California Sullivan 2017-04-04 23:39:06 UTC
I'm working on a recipe that uses openssl's key generation, and get the following error:

| WARNING: can't open config file: <snip>/recipe-sysroot-native/usr/bin/../../usr/lib/ssl/openssl.cnf
| Unable to load config info from <snip>/recipe-sysroot-native/usr/bin/../../usr/lib/ssl/openssl.cnf

[clsulliv@clsulliv 1.00-r0]$ ls recipe-sysroot-native/usr/bin/../../usr/lib/ssl/
certs  engines  misc  private

The symlink to openssl.cnf doesn't exist anymore.

It seems to be caused by patch  991620f3 "openssl: Fix symlink creation".

I was able to fix it locally by adding an openssl bbappend that does the following, but I doubt its the right solution:

do_install_append_class-native() {
        ln -sf ${sysconfdir}/ssl/openssl.cnf ${D}${libdir}/ssl/openssl.cnf
}

pkg_postinst_openssl-conf_class-native () {

}
Comment 1 Jussi Kukkonen 2017-04-18 10:10:19 UTC
I've sent a revert of 991620f3962a to list.
Comment 2 Jussi Kukkonen 2017-04-19 12:51:18 UTC
commit 7fe30a5df4ad25275492f241a69553693af1fd3f
Author: Jussi Kukkonen <jussi.kukkonen@intel.com>
Date:   Tue Apr 18 13:08:43 2017 +0300

    Revert "openssl: Fix symlink creation"
    
    This reverts commit 991620f3962a9917fa99abb5582f4b72ebd42a3d.
    
    The commit breaks openssl-native (you can no longer generate keys
    because it can't find the configuration file). Also the idea that we
    would install configuration files normally but then add the symlinks
    pointing to them in a postinstall feels wrong.
    
    Fixes [YOCTO #11296]. The bug contains an alternative fix but I'm
    sending a revert as I cannot fully understand the motive of the
    original patch. See also discussion in
    http://lists.openembedded.org/pipermail/openembedded-core/2017-April/135176.html
    
    (From OE-Core rev: b192daef5d1e7f3501c533b92dc75e2d996afc13)
    
    Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com>
    Signed-off-by: Ross Burton <ross.burton@intel.com>
    Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>