Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package easy-rsa for openSUSE:Factory checked in at 2026-09-23 18:18:20 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/easy-rsa (Old) and /work/SRC/openSUSE:Factory/.easy-rsa.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "easy-rsa" Wed Sep 23 18:18:20 2026 rev:21 rq:1379974 version:3.2.7 Changes: -------- --- /work/SRC/openSUSE:Factory/easy-rsa/easy-rsa.changes 2026-03-16 15:08:19.340482553 +0100 +++ /work/SRC/openSUSE:Factory/.easy-rsa.new.383539/easy-rsa.changes 2026-09-23 18:18:24.682676008 +0200 @@ -1,0 +2,11 @@ +Wed Sep 23 12:19:36 UTC 2026 - ecsos <[email protected]> + +- Update to 3.2.7 + - Chores: Fixed a typo in easy-rsa/easyrsa3/easyrsa shell output in #1445 + - default_vars(): If defined, set EASYRSA_SAN_CRIT to 'critical,' for use in #1448 + - verify_working_env(): Do not reset '$require_pki' and '$require_ca' in #1450 + - write: Load all variables before calling 'write()' in #1451 + - Fix git bash 4win by in #1454 + - check_serial_unique(); Do not export EASYRSA_SSL_CONF for LibreSSL in #1466 + +------------------------------------------------------------------- Old: ---- EasyRSA-3.2.6.tgz EasyRSA-3.2.6.tgz.sig New: ---- EasyRSA-3.2.7.tgz EasyRSA-3.2.7.tgz.sig ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ easy-rsa.spec ++++++ --- /var/tmp/diff_new_pack.Pq0xRL/_old 2026-09-23 18:18:25.546711741 +0200 +++ /var/tmp/diff_new_pack.Pq0xRL/_new 2026-09-23 18:18:25.548711823 +0200 @@ -19,7 +19,7 @@ %define pname EasyRSA Name: easy-rsa -Version: 3.2.6 +Version: 3.2.7 Release: 0 Summary: CLI utility to build and manage a PKI CA License: GPL-2.0-or-later ++++++ EasyRSA-3.2.6.tgz -> EasyRSA-3.2.7.tgz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/EasyRSA-3.2.6/ChangeLog new/EasyRSA-3.2.7/ChangeLog --- old/EasyRSA-3.2.6/ChangeLog 2026-03-13 22:18:45.000000000 +0100 +++ new/EasyRSA-3.2.7/ChangeLog 2026-09-19 14:53:22.000000000 +0200 @@ -1,5 +1,15 @@ Easy-RSA 3 ChangeLog +3.2.7 (2026-09-19) + + * Minor changes required to support Git Bash for Windows + (ade5653) (dd55451) (f2591fc) (5d389e4) (cb1c437) (#1454) + To use Git Bash for Windows set 'EASYRSA_RAND_SN=no' + * write: Load all variables before calling 'write()' (3c9e340) (#1451) + * verify_working_env(): Do not reset '$require_pki' and '$require_ca' (9d34430) (#1450) + * Remove EASYRSA_SAN_CRIT from 'Add full --san to extra extensions' (19c10ab) (#1448) + * default_vars(): If defined, set EASYRSA_SAN_CRIT to 'critical,' (97e1020) (#1448) + 3.2.6 (2026-03-13) * Introduce command 'import-tls-key' - Import an OpenVPN TLS key (cb4735b) (#1429) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/EasyRSA-3.2.6/doc/EasyRSA-Contributing.md new/EasyRSA-3.2.7/doc/EasyRSA-Contributing.md --- old/EasyRSA-3.2.6/doc/EasyRSA-Contributing.md 2026-03-13 22:18:45.000000000 +0100 +++ new/EasyRSA-3.2.7/doc/EasyRSA-Contributing.md 2026-09-19 14:53:22.000000000 +0200 @@ -129,3 +129,11 @@ Your fork is now synchronised. + +### Notes: + +- Use SSL for Github: + + ``` + git config --global url.ssh://[email protected]/.insteadOf https://github.com/ + ``` diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/EasyRSA-3.2.6/easyrsa new/EasyRSA-3.2.7/easyrsa --- old/EasyRSA-3.2.6/easyrsa 2026-03-13 22:18:45.000000000 +0100 +++ new/EasyRSA-3.2.7/easyrsa 2026-09-19 14:53:22.000000000 +0200 @@ -1034,7 +1034,7 @@ else # create temp-snapshot keep_tmp="$EASYRSA_TEMP_DIR/tmp/$EASYRSA_KEEP_TEMP" - mkdir -p "${EASYRSA_TEMP_DIR}/tmp/${keep_tmp}" || die \ + mkdir -p "${keep_tmp}" || die \ "cleanup() - Failed to create '${keep_tmp}' directory." rm -rf "$keep_tmp" @@ -2037,6 +2037,15 @@ -out "$selfsign_params_file" || \ die "self_sign - params-file failed" + # OpenSSL for Windows cannot load bash style file name + # as the -newkey "$newkey_params" + # eg: -newkey ec:/c/Users/me/foo.txt + # becomes: -newkey ec:/Users/me/foo.txt + if [ "$OS" = Windows_NT ]; then + selfsign_params_file="${selfsign_params_file#/?}" + verbose "selfsign_params_file: $selfsign_params_file" + fi + newkey_params="$EASYRSA_ALGO":"$selfsign_params_file" ;; ed) @@ -2089,7 +2098,7 @@ -newkey "$newkey_params" \ -keyout "$tmp_key_out" \ -out "$tmp_crt_out" \ - -subj "/CN=$file_name_base" \ + ${EASYRSA_BATCH:+ -batch} \ ${EASYRSA_TEXT_ON:+ -text} \ ${EASYRSA_NO_PASS:+ "$no_password"} \ ${EASYRSA_PASSIN:+ -passin "$EASYRSA_PASSIN"} \ @@ -2284,6 +2293,15 @@ ;; ec) # Elliptic curve parameters-file + # OpenSSL for Windows cannot load bash style file name + # as the -newkey "$newkey_params" + # eg: -newkey ec:/c/Users/me/foo.txt + # becomes: -newkey ec:/Users/me/foo.txt + if [ "$OS" = Windows_NT ]; then + EASYRSA_ALGO_PARAMS="${EASYRSA_ALGO_PARAMS#/?}" + verbose "EASYRSA_ALGO_PARAMS: $EASYRSA_ALGO_PARAMS" + fi + algo_opts="$EASYRSA_ALGO:$EASYRSA_ALGO_PARAMS" ;; ed) @@ -2796,6 +2814,11 @@ # Check for openssl -status of serial number # Always errors out - Do not capture error check_serial="$( + if [ "$EASYRSA_FORCE_SAFE_SSL" ]; then + : # Use the previously exported safe OPENSSL_CONF + else + export OPENSSL_CONF="$EASYRSA_SSL_CONF" + fi "$EASYRSA_OPENSSL" ca -status "$1" 2>&1 )" || : @@ -3275,8 +3298,15 @@ # move tmp-file to list file if [ -z "$pfp_error_msg" ]; then + # back up the current pfp list + if [ -f "$pfp_list_file" ]; then + rm -f "$pfp_list_file".old + mv "$pfp_list_file" "$pfp_list_file".old || \ + pfp_error_msg="${pfp_error_msg}move 1 Failed!${NL}" + fi + mv "$pfp_list_tmp" "$pfp_list_file" || \ - pfp_error_msg="${pfp_error_msg}move Failed!${NL}" + pfp_error_msg="${pfp_error_msg}move 2 Failed!${NL}" fi # user info @@ -5303,10 +5333,10 @@ notice "\ CA certificate has been successfully renewed. -Your old CA cerificate has been added to the expired CA list at: +Your old CA certificate has been added to the expired CA list at: * $exp_ca_cert_list -Your renewed CA cerificate is at: +Your renewed CA certificate is at: * $ca_cert_file" } # => renew_ca_cert() @@ -5963,7 +5993,7 @@ set_var EASYRSA_CRL_DAYS 180 set_var EASYRSA_NS_SUPPORT no set_var EASYRSA_NS_COMMENT \ - "Easy-RSA (3.2.6) Generated Certificate" + "Easy-RSA (3.2.7) Generated Certificate" set_var EASYRSA_TEMP_DIR "$EASYRSA_PKI" set_var EASYRSA_REQ_CN ChangeMe @@ -5971,6 +6001,9 @@ set_var EASYRSA_MAX_TEMP 1 + # configure EASYRSA_SAN_CRIT for use + export EASYRSA_SAN_CRIT="${EASYRSA_SAN_CRIT:+critical,}" + verbose "default_vars; COMPLETED" } # => default_vars() @@ -6096,7 +6129,6 @@ selfsign_eku \ internal_batch mv_temp_error \ easyrsa_exit_with_error error_info \ - require_pki require_ca \ prompt_restore mktemp_counter # Protect $EASYRSA_ALIAS_DAYS from vars abuse @@ -6893,9 +6925,9 @@ cat <<- VERSION_TEXT EasyRSA Version Information Version: $EASYRSA_version - Generated: Fri Mar 13 16:18:45 CDT 2026 + Generated: Sat Sep 19 07:53:22 CDT 2026 SSL Lib: ${ssl_version:-undefined} - Git Commit: 0d746eec3f06210ae1710d17b9c8d38428058e19 + Git Commit: bab739d176a00f47819c79792863b13f4487b0c0 Source Repo: https://github.com/OpenVPN/easy-rsa VERSION_TEXT } # => print_version() @@ -6904,7 +6936,7 @@ ######################################## # Invocation entry point: -EASYRSA_version="3.2.6" +EASYRSA_version="3.2.7" NL=' ' @@ -7129,7 +7161,7 @@ ;; --san-crit|--san-critical) empty_ok=1 - export EASYRSA_SAN_CRIT='critical,' + export EASYRSA_SAN_CRIT=1 ;; --bc-crit|--bc-critical) empty_ok=1 @@ -7193,12 +7225,15 @@ # Be secure with a restrictive umask [ "$EASYRSA_NO_UMASK" ] || umask "${EASYRSA_UMASK:=077}" +# DEPRECATED behavior - This will be removed # option dependencies # Add full --san to extra extensions +# Do not include EASYRSA_SAN_CRIT +# If required, an externally set SAN must include 'critical,' if [ "$EASYRSA_SAN" ]; then EASYRSA_EXTRA_EXTS="\ $EASYRSA_EXTRA_EXTS -subjectAltName = ${EASYRSA_SAN_CRIT}${EASYRSA_SAN}" +subjectAltName = $EASYRSA_SAN" fi # Set cmd now @@ -7417,7 +7452,8 @@ *) # Only allow 'type' on command line # Internally, overwrite and file-name is allowed - write_legacy_file_v2 "$1" && unset -v EASYRSA_VERBOSE + require_pki=""; require_ca=""; verify_working_env + write_legacy_file_v2 "$1" esac ;; serial|check-serial)
