]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
apache: Drop RSA key and certificate generation
authorPeter Müller <peter.mueller@ipfire.org>
Fri, 20 Sep 2024 14:20:19 +0000 (14:20 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Sun, 22 Sep 2024 14:42:41 +0000 (14:42 +0000)
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
src/initscripts/system/apache

index e7a62097e1b1832d910e4307f4b285d1438326c3..ba7ede6702e95c48c12554de4e387ca3db332663 100644 (file)
@@ -2,7 +2,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2022  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2024  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
 PIDFILE="/var/run/httpd.pid"
 
 generate_certificates() {
-       if [ ! -f "/etc/httpd/server.key" ]; then
-               boot_mesg "Generating HTTPS RSA server key (this will take a moment)..."
-               openssl genrsa -out /etc/httpd/server.key 4096 &>/dev/null
-               chmod 600 /etc/httpd/server.key
-               evaluate_retval
-       fi
-
        if [ ! -f "/etc/httpd/server-ecdsa.key" ]; then
                boot_mesg "Generating HTTPS ECDSA server key..."
                openssl ecparam -genkey -name secp384r1 -noout \
@@ -40,29 +33,12 @@ generate_certificates() {
                evaluate_retval
        fi
 
-       # Generate RSA CSR
-       if [ ! -f "/etc/httpd/server.csr" ]; then
-               sed "s/HOSTNAME/`hostname -f`/" < /etc/certparams | \
-                       openssl req -new -key /etc/httpd/server.key \
-                               -out /etc/httpd/server.csr &>/dev/null
-       fi
-
-       # Generate ECDSA CSR
        if [ ! -f "/etc/httpd/server-ecdsa.csr" ]; then
                sed "s/HOSTNAME/`hostname -f`/" < /etc/certparams | \
                        openssl req -new -key /etc/httpd/server-ecdsa.key \
                        -out /etc/httpd/server-ecdsa.csr &>/dev/null
        fi
 
-       if [ ! -f "/etc/httpd/server.crt" ]; then
-               boot_mesg "Signing RSA certificate..."
-               openssl x509 -req -days 999999 -sha256 \
-                       -in /etc/httpd/server.csr \
-                       -signkey /etc/httpd/server.key \
-                       -out /etc/httpd/server.crt &>/dev/null
-               evaluate_retval
-       fi
-
        if [ ! -f "/etc/httpd/server-ecdsa.crt" ]; then
                boot_mesg "Signing ECDSA certificate..."
                openssl x509 -req -days 999999 -sha256 \