app-crypt/dehydrated: Ignore output of "openssl req"

Closes: https://bugs.gentoo.org/942637
Signed-off-by: Ulrich Müller <ulm@gentoo.org>
Closes: https://github.com/gentoo/gentoo/pull/39864
Signed-off-by: Marc Schiffbauer <mschiff@gentoo.org>
This commit is contained in:
Ulrich Müller
2024-12-27 16:34:57 +01:00
committed by Marc Schiffbauer
parent 57c187b2d7
commit 1e9bc7bf78
2 changed files with 82 additions and 0 deletions

View File

@@ -0,0 +1,63 @@
# Copyright 1999-2024 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2
EAPI="8"
VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/dehydrated.asc
inherit verify-sig
DESCRIPTION="A client for signing certificates with an ACME-server"
HOMEPAGE="https://dehydrated.io/"
SRC_URI="
https://github.com/dehydrated-io/${PN}/releases/download/v${PV}/${P}.tar.gz
verify-sig? ( https://github.com/dehydrated-io/${PN}/releases/download/v${PV}/${P}.tar.gz.asc )
"
LICENSE="MIT"
SLOT="0"
KEYWORDS="~amd64 ~arm ~arm64 ~ppc64 ~riscv ~x86"
IUSE="+cron"
BDEPEND="verify-sig? ( sec-keys/openpgp-keys-dehydrated )"
RDEPEND="acct-group/dehydrated
acct-user/dehydrated
app-shells/bash
net-misc/curl
cron? ( virtual/cron )"
PATCHES=( "${FILESDIR}"/${P}-openssl-stdout.patch )
src_configure() {
default
sed -i 's,^#CONFIG_D=.*,CONFIG_D="/etc/dehydrated/config.d",' docs/examples/config \
|| die "could not set config (CONFIG_D)"
}
src_install() {
dobin ${PN}
insinto /etc/${PN}
doins docs/examples/{config,domains.txt,hook.sh}
fperms u+x /etc/${PN}/hook.sh
dodoc docs/*.md
insinto /etc/${PN}/config.d
newins "${FILESDIR}"/00_gentoo.sh-r1 00_gentoo.sh
keepdir /etc/${PN}/domains.d
doman docs/man/dehydrated.1
if use cron ; then
insinto /etc/cron.d
newins "${FILESDIR}"/cron-r1 ${PN}
fi
}
pkg_postinst() {
if [[ -z "${REPLACING_VERSIONS}" ]] ; then
einfo "See /etc/dehydrated/config for configuration."
use cron && einfo "After finishing setup you should enable the cronjob in /etc/cron.d/dehydrated."
fi
}

View File

@@ -0,0 +1,19 @@
https://bugs.gentoo.org/942637
commit 4fd777e87e589652b1127b79ac6688ed7cb151fe
Author: Wilfried Teiken <wteiken@teiken.org>
Date: Sun Dec 3 15:07:01 2023 -0500
Ignore output of 'openssl req -verify'.
--- a/dehydrated
+++ b/dehydrated
@@ -1011,7 +1011,7 @@ signed_request() {
extract_altnames() {
csr="${1}" # the CSR itself (not a file)
- if ! <<<"${csr}" "${OPENSSL}" req -verify -noout 2>/dev/null; then
+ if ! <<<"${csr}" "${OPENSSL}" req -verify -noout >/dev/null 2>&1; then
_exiterr "Certificate signing request isn't valid"
fi