What version of the openssl package is installed? This does sound like a potential issue with `openssl rehash`. Your workaround looks OK for the moment, but the problem is that the openssl devs would like to remove the deprecated `c_rehash` utility. At this point in the release cycle, it's possible c_rehash may stick around for Buster, but no guarantees from me on that one - that's up to the openssl folks.
-- Kind regards, Michael

