Hi Philipp, On Wed, November 23, 2016 17:17, Philipp Kern wrote: > Source: ca-certificates > Tags: patch,d-i > X-Debbugs-Cc: ma...@debian.org, debian-b...@lists.debian.org > > In an effort to make HTTPS usable in the installer (e.g. to fetch > preseed, authorized_keys files, or packages) ca-certificates needs to > add a udeb with the certificates. The result has to be usable by > openssl, which requires that c_rehash has been run on the directory. > Unfortunately c_rehash is a Perl script that requires the openssl binary > to run, so it's not suitable to run in the installer environment. > > Please find attached a patch that a) adds a ca-certificates-udeb > package, b) installs all off Mozilla's certificates into /etc/ssl/certs > and c) runs c_rehash on the resulting directory during build. I needed > to rename dirs, postinst and postrm. Hence there are two patch files for > clarity: one in unified format and one in git diff format. > > I'd be nice to have this in Stretch. Not having the certificates > available blocked inclusion of a HTTPS-capable wget altogether.
Thanks for the patch. This seems useful & fine to me. I'd leave it to Michael as the primary maintainer to judge on its stretchworthiness however. Cheers, Thijs