Skip to content

Commit fe21110

Browse files
committed
Fix OpenSSL genpkey parameter formatting for SSL certificate generation
The OpenSSL genpkey command was failing with the error: 'Error setting rsa_keygen_bits: 2048 parameter' This was caused by incorrect parameter formatting in the -pkeyopt argument. The parameter 'rsa_keygen_bits: 2048' had a space after the colon, but OpenSSL expects 'rsa_keygen_bits:2048' (no space). This issue was introduced in commit 0b73535 when migrating from genrsa to genpkey for FIPS compatibility. Changes: - Fixed the -pkeyopt parameter in certificate_generator.rb - Updated the corresponding test expectation - Added changelog entry Testing: Verified with OpenSSL command line: openssl genpkey -algorithm RSA -pass stdin -aes256 \ -out /tmp/test.key -pkeyopt rsa_keygen_bits:2048 Successfully generates encrypted key with correct syntax. Fixes: bsc#1266671 Related: bsc#1235462 (FIPS compatibility)
1 parent 9acae65 commit fe21110

3 files changed

Lines changed: 3 additions & 2 deletions

File tree

‎package/yast2-rmt.changes‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
-------------------------------------------------------------------
22
Mon Sep 1 10:06:04 UTC 2025 - Natnael Getahun <natnael.getahun@suse.com>
33

4+
- Fix OpenSSL genpkey parameter formatting for SSL certificate generation (bsc#1266671)
45
- Ensure compatibility with FIPS mode (bsc#1235462)
56
- Remove 'Forward systems to SCC' checkbox (scc-262)
67
- Fix ERB initialization for older Ruby versions (bsc#1146403)

‎spec/rmt/ssl/certificate_generator_spec.rb‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -161,7 +161,7 @@
161161
expect_any_instance_of(Cheetah::DefaultRecorder).not_to receive(:record_stdin)
162162
expect(RMT::Execute).to receive(:on_target!).with(
163163
'openssl', 'genpkey', '-algorithm', 'RSA', '-pass', 'stdin', '-aes256',
164-
'-out', ssl_files[:ca_private_key], '-pkeyopt', "rsa_keygen_bits: #{described_class::OPENSSL_KEY_BITS}",
164+
'-out', ssl_files[:ca_private_key], '-pkeyopt', "rsa_keygen_bits:#{described_class::OPENSSL_KEY_BITS}",
165165
stdin: ca_password,
166166
logger: nil
167167
)

‎src/lib/rmt/ssl/certificate_generator.rb‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -99,7 +99,7 @@ def generate(common_name, alt_names, ca_password)
9999

100100
RMT::Execute.on_target!(
101101
'openssl', 'genpkey', '-algorithm', 'RSA', '-pass', 'stdin', '-aes256',
102-
'-out', @ssl_paths[:ca_private_key], '-pkeyopt', "rsa_keygen_bits: #{OPENSSL_KEY_BITS}",
102+
'-out', @ssl_paths[:ca_private_key], '-pkeyopt', "rsa_keygen_bits:#{OPENSSL_KEY_BITS}",
103103
stdin: ca_password,
104104
logger: nil # do not log in order to securely pass password
105105
)

0 commit comments

Comments
 (0)