Hi Philipp,

On Wed, November 23, 2016 17:17, Philipp Kern wrote:
> Source: ca-certificates
> Tags: patch,d-i
> X-Debbugs-Cc: ma...@debian.org, debian-b...@lists.debian.org
>
> In an effort to make HTTPS usable in the installer (e.g. to fetch
> preseed, authorized_keys files, or packages) ca-certificates needs to
> add a udeb with the certificates. The result has to be usable by
> openssl, which requires that c_rehash has been run on the directory.
> Unfortunately c_rehash is a Perl script that requires the openssl binary
> to run, so it's not suitable to run in the installer environment.
>
> Please find attached a patch that a) adds a ca-certificates-udeb
> package, b) installs all off Mozilla's certificates into /etc/ssl/certs
> and c) runs c_rehash on the resulting directory during build. I needed
> to rename dirs, postinst and postrm. Hence there are two patch files for
> clarity: one in unified format and one in git diff format.
>
> I'd be nice to have this in Stretch. Not having the certificates
> available blocked inclusion of a HTTPS-capable wget altogether.

Thanks for the patch. This seems useful & fine to me. I'd leave it to
Michael as the primary maintainer to judge on its stretchworthiness
however.


Cheers,
Thijs

Reply via email to