Thanks to excellent community feedback, this patch forces a single,
reliable list of sources for EasyRSA data-files.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
The purpose here is to force EasyRSA find the required data-files:
* 'openssl-easyrsa.cnf' MUST be found.
* 'x509-types' MUST be found.
* 'vars.example' should be found.
* 'vars'
The 'vars' file is more complicated due to user expectations.
This patch does not copy 'vars', the code is included but DISABED.
The reasons are:
* Allow running 'easyrsa' from PATH.
* Make standard packaging work correctly.
Bug fixes:
* #499 and associated issues with missing files.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
Changes made by a0dbc346bd92088ee481f5488ac53a7537b32073 result in
'ossl_major=2' and LibreSSL 2.x not being recognised.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
* Allow local copy of unit tests to persist.
* Quote file-name exapansion for Windows setup.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
github.com/ccin2p3/easy-rsa into ccin2p3-feature/custom-umask
Fix typo: 'defúlts' -> 'default'
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
When EasyRSA is installed to a path with a space in it, gen_req() fails
for EC and ED crypto. This is caused by the space in the file-name for
the parameters file $EASYRSA_CURVE.
To resolve this, '-newkey' must be removed from $algo_opts and inserted
into the OpenSSL command. And $algo_opts must be quoted. (#494)
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
Where 'if' is replaced with 'case', functionality is generaly maintained.
With the following exceptions:
* verify_curve_ed() does not need to identify the specific curve.
Error status will provide the correct result for a curve name error.
* For Edwards curve crypto, the 'case' statement is further reduced to
use the verified $EASYRSA_CURVE inside the OpenSSL command.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
Commit a0dbc346bd92088ee481f5488ac53a7537b32073 leads to bug caused
by OpenSSL 'genpkey' inconsistency. OpenSSL version 1 'genpkey' does
not support option '-config' but OpenSSL version 3 does.
(Details can be found at: https://www.openssl.org/docs/manpages.html)
To use 'genpkey' option '-config', easyrsa_openssl() needs to be aware
of the SSL Library version and only set '-config' for version 3.
This patch sets OpenSSL version 3 ONLY option '-config' for 'genpkey'.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
* (1) Move definition of $crypto_opts inside 'case' for OSSLv1 (NFC)
This defines $crypto_opts for the CA private key.
* Wrap long lines (NFC)
* (2) Expand definition of $crypto_opts to use $no_password.
This defines $crypto_opts for the CA pair.
Note: Before this change (2), the command which EasyRSA uses
does not include '-nodes' when building an unencrypted CA.
Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>