Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 177725 - app-misc/ca-certificates-20070303-r1 creates bad symlinks
Summary: app-misc/ca-certificates-20070303-r1 creates bad symlinks
Status: RESOLVED DUPLICATE of bug 177397
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: SpanKY
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-05-08 21:25 UTC by Doug Goldstein (RETIRED)
Modified: 2007-05-09 02:55 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Doug Goldstein (RETIRED) gentoo-dev 2007-05-08 21:25:40 UTC
Basically I noticed this because cacert.org's cert files were broken into root.crt and class3.crt.

Now you run update-ca-certificates in the pkg_postinst() step, however since the file is being installed into /etc it's under CONFIG_PROTECT. So the update to the config file doesn't actually occur until the user runs etc-update or dispatch-conf. However, you've already run update-ca-certificates, which now results in the old file being used and the user sees cacert.org's certificates silently disappear for them.

Additionally the problem is even worse since --fresh isn't appended by the call so old symlinks stay around and muck up the situation even further.

The solution is to either remove ca-certificates.conf from CONFIG_PROTECT and append --fresh to the call.

Or to patch update-ca-certificates to accept a path to ca-certificates.conf and append --fresh.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-05-08 21:40:28 UTC

*** This bug has been marked as a duplicate of bug 177397 ***
Comment 2 Doug Goldstein (RETIRED) gentoo-dev 2007-05-09 02:47:06 UTC
This isn't a dup. This is an issue that the symlinks are not generated to the new certificates. A side note in this is that it leaves dangling symlinks. The fact that they symlinks aren't generated at all is what's causing breakage. The other bug report the guy says dangling symlinks are broken.
Comment 3 Doug Goldstein (RETIRED) gentoo-dev 2007-05-09 02:55:09 UTC
eh. I'll take the discussion there since it's still an issue.

*** This bug has been marked as a duplicate of bug 177397 ***