Bug 72300 - removing the ssl cert rpm leaves apache in a broken state.
removing the ssl cert rpm leaves apache in a broken state.
Status: CLOSED CURRENTRELEASE
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Server (Show other bugs)
unspecified
i386 Linux
high Severity medium
: ---
: ---
Assigned To: Mihai Ibanescu
Fanny Augustin
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2002-08-22 16:17 EDT by Todd Warner
Modified: 2007-07-31 15:24 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2002-08-26 14:35:06 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Todd Warner 2002-08-22 16:17:40 EDT
rpm -e rhns-ssl-cert.rpm (or whatever it is called) on a satellite (or proxy)

Apache will no longer restart because 
/etc/http/conf/ssl.{crt,key}/server.{crt,key} were nuked.

We probably need to backup and restore their original server.{crt,key} files upon
installation and removal of this package.
Comment 1 Greg DeKoenigsberg 2002-08-22 16:46:44 EDT
Yeah.  In fact, we should probably consider making proper sslCACert
configuration a function of both install and removal.

On installation of a custom cert package, %post should alter
/etc/sysconfig/rhn/up2date and /etc/sysconfig/rhn/rhn_register, adding the new
sslCACert line to each: 

sslCACert=/usr/share/rhn/RHNS-CORP-CA-CERT

On removal of the custom cert package, %post should return the default setting.
Comment 2 Mihai Ibanescu 2002-08-22 19:00:41 EDT
Todd was actually referring to the server-side (i.e. proxy/satellite) apache
config. I do agree that it would be nice to modify stuff in the post section,
but I don't think it's the right time to do it.
Comment 3 Mihai Ibanescu 2002-08-22 19:10:12 EDT
I do agree that it would be nice to modify stuff in the post section FOR THE
CLIENT, but I don't think it's the right time to do it.

This is what I actually meant
Comment 4 Josef Komenda 2002-08-23 16:06:18 EDT
Bumping to high priority.
Comment 5 Mihai Ibanescu 2002-08-23 19:06:59 EDT
Fixed. rhns-certs-tools 1.3.0-4 should fix this.
Added a postun scriptlet (stolen from mod_ssl) to recreate the dummy certs.
Comment 6 Josef Komenda 2002-08-26 16:14:13 EDT
confirmed good - closing.

Note You need to log in before you can comment on or make changes to this bug.