Commit fe21110
committed
Fix OpenSSL genpkey parameter formatting for SSL certificate generation
The OpenSSL genpkey command was failing with the error:
'Error setting rsa_keygen_bits: 2048 parameter'
This was caused by incorrect parameter formatting in the -pkeyopt
argument. The parameter 'rsa_keygen_bits: 2048' had a space after
the colon, but OpenSSL expects 'rsa_keygen_bits:2048' (no space).
This issue was introduced in commit 0b73535 when migrating from
genrsa to genpkey for FIPS compatibility.
Changes:
- Fixed the -pkeyopt parameter in certificate_generator.rb
- Updated the corresponding test expectation
- Added changelog entry
Testing:
Verified with OpenSSL command line:
openssl genpkey -algorithm RSA -pass stdin -aes256 \
-out /tmp/test.key -pkeyopt rsa_keygen_bits:2048
Successfully generates encrypted key with correct syntax.
Fixes: bsc#1266671
Related: bsc#1235462 (FIPS compatibility)1 parent 9acae65 commit fe21110
3 files changed
Lines changed: 3 additions & 2 deletions
File tree
- package
- spec/rmt/ssl
- src/lib/rmt/ssl
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
164 | | - | |
| 164 | + | |
165 | 165 | | |
166 | 166 | | |
167 | 167 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
99 | 99 | | |
100 | 100 | | |
101 | 101 | | |
102 | | - | |
| 102 | + | |
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
| |||
0 commit comments