We need both individual certs and a bundle. The current scripts are in BLFS SVN 
tree, I believe in auxfiles.
-- 
Sent from my Android phone with K-9 Mail. Please excuse my brevity.

Bruce Dubbs <[email protected]> wrote:

Andrew Benton wrote:
> On Fri, 14 Oct 2011 14:21:37 -0500
> Bruce Dubbs <[email protected]> wrote:
> 
>> This is mostly for DJ.
>>
>> I think we should add information to the BLFS openssl page on how to 
>> create a ca bundle. I tried looking at some older messages, but 
>> cvs.fedoraproject.org no longer exists.
>>
>> I can find a list from debian.
>>
>> RH wants to put the files in /etc/pki.
>>
>> openssl puts them in /etc/ssl/certs.
>>
>> My questions are:
>>
>> 1. What procedure is used to generate the BLFS-ca-bundles?
> 
> The curl makefile has a make ca-bundle target. 

> 
http://linuxfromscratch.org/pipermail/blfs-support/2011-October/068687.html

I didn't remember that from your earlier message. It looks like it is 
just downloading

'http://mxr.mozilla.org/mozilla/source/security/nss/lib/ckfw/builtins/certdata.txt?raw=1'
 


and formatting it. Is that sufficient? Should we have a separate page 
in BLFS that does the same thing?

>> 2. Should we continue to put them in /etc/ssl/certs or should we 
>> consider another location?
> 
> I like /etc/ssl/certs.

I like it also, but still would like more opinions.

-- Bruce



-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-dev
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

-- 
This message has been scanned for viruses and
dangerous content, and is believed to be clean.


-- 
This message has been scanned for viruses and
dangerous content, and is believed to be clean.

-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-dev
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to