https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #8 from Joseph Mingrone ---
Here is Dag-Erling's review to reimplement certctl in C and generate a bundle
along with a hashed directory.
https://reviews.freebsd.org/D42320
--
You are receiving this mail because:
You are the a
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #7 from Dag-Erling Smørgrav ---
Yes, it's set in the common case (i.e. when processing individual certificates
from /usr/share/certs, but not when processing a bundle), but on a typical zfs
install it produces hard links, not sy
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #6 from Joseph Mingrone ---
I agree that it makes sense to have certctl generate a bundle and revert
8932f7ce1783. If that takes time or faces opposition, we could document that
local-unbound requires security/ca_root_nss.
FWI
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #5 from Dag-Erling Smørgrav ---
Copying the entire /etc/ssl hierarchy into the chroot should have worked,
unless of course you just copied the symlinks instead of copying the files they
point to. But a more pragmatic solution i
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #4 from Joseph Mingrone ---
Kyle and I guessed the chroot was involved (so I tried copying the system trust
store into the chroot), but I didn't realize that because it's a hashed
directory it wouldn't work with unbound. Thanks
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
Dag-Erling Smørgrav changed:
What|Removed |Added
Status|New |Open
--- Comment #3 from Dag
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
--- Comment #2 from Joseph Mingrone ---
(In reply to John Baldwin from comment #1)
It should have anything to do with security/ca_root_nss. Maybe you mean
certctl.sh.
--
You are receiving this mail because:
You are the assignee for the b
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
John Baldwin changed:
What|Removed |Added
CC||c...@freebsd.org,
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=274549
Bug ID: 274549
Summary: local-unbound not resolving unless
security/ca_root_nss installed
Product: Base System
Version: 15.0-CURRENT
Hardware: Any
OS: