Red Hat Bugzilla – Bug 1290907
ipsec initnss/checknss custom directory not recognized
Last modified: 2016-11-03 17:22:10 EDT
Copied from u/s: https://github.com/libreswan/libreswan/issues/44 "I set up Openstack with VPNaaS. During creation process of the VPN this command is executed: ip netns exec qrouter-664940e8-6139-4c36-8fcc-ee9e06bd5212 ipsec checknss /var/lib/neutron/ipsec/664940e8-6139-4c36-8fcc-ee9e06bd5212/etc The db files are always added to the directory /etc/ipsec.d Looking at the bash script "ipsec" i saw that the variable IPSEC_NSSDIR_SQL is set only at the beginning of the script. If a custom directory is specified, the variable IPSEC_NSSDIR_SQL is not changed. Adding IPSEC_NSSDIR_SQL="sql:${IPSEC_NSSDIR}" resolved the issue." We are experiencing this issue in our neutron CI system. Our current version of libreswan is 3.15. The patch has been already been merged u/s in: https://github.com/libreswan/libreswan/commit/709e2a92d768afc6c78e5a243f0076ddec744c8a
Since we need a respin for 7.1.x for FIPS, we should pull this in.
*** Bug 1288257 has been marked as a duplicate of this bug. ***
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2016-2603.html