Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package easy-rsa for openSUSE:Factory 
checked in at 2026-09-23 18:18:20
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/easy-rsa (Old)
 and      /work/SRC/openSUSE:Factory/.easy-rsa.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "easy-rsa"

Wed Sep 23 18:18:20 2026 rev:21 rq:1379974 version:3.2.7

Changes:
--------
--- /work/SRC/openSUSE:Factory/easy-rsa/easy-rsa.changes        2026-03-16 
15:08:19.340482553 +0100
+++ /work/SRC/openSUSE:Factory/.easy-rsa.new.383539/easy-rsa.changes    
2026-09-23 18:18:24.682676008 +0200
@@ -1,0 +2,11 @@
+Wed Sep 23 12:19:36 UTC 2026 - ecsos <[email protected]>
+
+- Update to 3.2.7
+  - Chores: Fixed a typo in easy-rsa/easyrsa3/easyrsa shell output in #1445
+  - default_vars(): If defined, set EASYRSA_SAN_CRIT to 'critical,' for use in 
#1448
+  - verify_working_env(): Do not reset '$require_pki' and '$require_ca' in 
#1450
+  - write: Load all variables before calling 'write()' in #1451
+  - Fix git bash 4win by in #1454
+  - check_serial_unique(); Do not export EASYRSA_SSL_CONF for LibreSSL in #1466
+
+-------------------------------------------------------------------

Old:
----
  EasyRSA-3.2.6.tgz
  EasyRSA-3.2.6.tgz.sig

New:
----
  EasyRSA-3.2.7.tgz
  EasyRSA-3.2.7.tgz.sig

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ easy-rsa.spec ++++++
--- /var/tmp/diff_new_pack.Pq0xRL/_old  2026-09-23 18:18:25.546711741 +0200
+++ /var/tmp/diff_new_pack.Pq0xRL/_new  2026-09-23 18:18:25.548711823 +0200
@@ -19,7 +19,7 @@
 
 %define         pname EasyRSA
 Name:           easy-rsa
-Version:        3.2.6
+Version:        3.2.7
 Release:        0
 Summary:        CLI utility to build and manage a PKI CA
 License:        GPL-2.0-or-later

++++++ EasyRSA-3.2.6.tgz -> EasyRSA-3.2.7.tgz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/EasyRSA-3.2.6/ChangeLog new/EasyRSA-3.2.7/ChangeLog
--- old/EasyRSA-3.2.6/ChangeLog 2026-03-13 22:18:45.000000000 +0100
+++ new/EasyRSA-3.2.7/ChangeLog 2026-09-19 14:53:22.000000000 +0200
@@ -1,5 +1,15 @@
 Easy-RSA 3 ChangeLog
 
+3.2.7 (2026-09-19)
+
+   * Minor changes required to support Git Bash for Windows
+     (ade5653) (dd55451) (f2591fc) (5d389e4) (cb1c437) (#1454)
+     To use Git Bash for Windows set 'EASYRSA_RAND_SN=no'
+   * write: Load all variables before calling 'write()' (3c9e340) (#1451)
+   * verify_working_env(): Do not reset '$require_pki' and '$require_ca' 
(9d34430) (#1450)
+   * Remove EASYRSA_SAN_CRIT from 'Add full --san to extra extensions' 
(19c10ab) (#1448)
+   * default_vars(): If defined, set EASYRSA_SAN_CRIT to 'critical,' (97e1020) 
(#1448)
+
 3.2.6 (2026-03-13)
 
    * Introduce command 'import-tls-key' - Import an OpenVPN TLS key (cb4735b) 
(#1429)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/EasyRSA-3.2.6/doc/EasyRSA-Contributing.md 
new/EasyRSA-3.2.7/doc/EasyRSA-Contributing.md
--- old/EasyRSA-3.2.6/doc/EasyRSA-Contributing.md       2026-03-13 
22:18:45.000000000 +0100
+++ new/EasyRSA-3.2.7/doc/EasyRSA-Contributing.md       2026-09-19 
14:53:22.000000000 +0200
@@ -129,3 +129,11 @@
 
 
     Your fork is now synchronised.
+
+### Notes:
+
+-   Use SSL for Github:
+
+    ```
+    git config --global url.ssh://[email protected]/.insteadOf 
https://github.com/
+    ```
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/EasyRSA-3.2.6/easyrsa new/EasyRSA-3.2.7/easyrsa
--- old/EasyRSA-3.2.6/easyrsa   2026-03-13 22:18:45.000000000 +0100
+++ new/EasyRSA-3.2.7/easyrsa   2026-09-19 14:53:22.000000000 +0200
@@ -1034,7 +1034,7 @@
                        else
                                # create temp-snapshot
                                
keep_tmp="$EASYRSA_TEMP_DIR/tmp/$EASYRSA_KEEP_TEMP"
-                               mkdir -p "${EASYRSA_TEMP_DIR}/tmp/${keep_tmp}" 
|| die \
+                               mkdir -p "${keep_tmp}" || die \
                                        "cleanup() - Failed to create 
'${keep_tmp}' directory."
 
                                rm -rf "$keep_tmp"
@@ -2037,6 +2037,15 @@
                                -out "$selfsign_params_file" || \
                                        die "self_sign - params-file failed"
 
+                       # OpenSSL for Windows cannot load bash style file name
+                       # as the -newkey "$newkey_params"
+                       # eg:      -newkey ec:/c/Users/me/foo.txt
+                       # becomes: -newkey ec:/Users/me/foo.txt
+                       if [ "$OS" = Windows_NT ]; then
+                               
selfsign_params_file="${selfsign_params_file#/?}"
+                               verbose "selfsign_params_file: 
$selfsign_params_file"
+                       fi
+
                        newkey_params="$EASYRSA_ALGO":"$selfsign_params_file"
                        ;;
                ed)
@@ -2089,7 +2098,7 @@
                -newkey "$newkey_params" \
                -keyout "$tmp_key_out" \
                -out "$tmp_crt_out" \
-               -subj "/CN=$file_name_base" \
+               ${EASYRSA_BATCH:+ -batch} \
                ${EASYRSA_TEXT_ON:+ -text} \
                ${EASYRSA_NO_PASS:+ "$no_password"} \
                ${EASYRSA_PASSIN:+ -passin "$EASYRSA_PASSIN"} \
@@ -2284,6 +2293,15 @@
                        ;;
                ec)
                        # Elliptic curve parameters-file
+                       # OpenSSL for Windows cannot load bash style file name
+                       # as the -newkey "$newkey_params"
+                       # eg:      -newkey ec:/c/Users/me/foo.txt
+                       # becomes: -newkey ec:/Users/me/foo.txt
+                       if [ "$OS" = Windows_NT ]; then
+                               EASYRSA_ALGO_PARAMS="${EASYRSA_ALGO_PARAMS#/?}"
+                               verbose "EASYRSA_ALGO_PARAMS: 
$EASYRSA_ALGO_PARAMS"
+                       fi
+
                        algo_opts="$EASYRSA_ALGO:$EASYRSA_ALGO_PARAMS"
                        ;;
                ed)
@@ -2796,6 +2814,11 @@
        # Check for openssl -status of serial number
        # Always errors out - Do not capture error
        check_serial="$(
+                       if [ "$EASYRSA_FORCE_SAFE_SSL" ]; then
+                               : # Use the previously exported safe 
OPENSSL_CONF
+                       else
+                               export OPENSSL_CONF="$EASYRSA_SSL_CONF"
+                       fi
                        "$EASYRSA_OPENSSL" ca -status "$1" 2>&1
                )" || :
 
@@ -3275,8 +3298,15 @@
 
                # move tmp-file to list file
                if [ -z "$pfp_error_msg" ]; then
+                       # back up the current pfp list
+                       if [ -f "$pfp_list_file" ]; then
+                               rm -f "$pfp_list_file".old
+                               mv "$pfp_list_file" "$pfp_list_file".old || \
+                                       pfp_error_msg="${pfp_error_msg}move 1 
Failed!${NL}"
+                       fi
+
                        mv "$pfp_list_tmp" "$pfp_list_file" || \
-                               pfp_error_msg="${pfp_error_msg}move 
Failed!${NL}"
+                               pfp_error_msg="${pfp_error_msg}move 2 
Failed!${NL}"
                fi
 
                # user info
@@ -5303,10 +5333,10 @@
        notice "\
 CA certificate has been successfully renewed.
 
-Your old CA cerificate has been added to the expired CA list at:
+Your old CA certificate has been added to the expired CA list at:
 * $exp_ca_cert_list
 
-Your renewed CA cerificate is at:
+Your renewed CA certificate is at:
 * $ca_cert_file"
 } # => renew_ca_cert()
 
@@ -5963,7 +5993,7 @@
        set_var EASYRSA_CRL_DAYS                180
        set_var EASYRSA_NS_SUPPORT              no
        set_var EASYRSA_NS_COMMENT              \
-               "Easy-RSA (3.2.6) Generated Certificate"
+               "Easy-RSA (3.2.7) Generated Certificate"
 
        set_var EASYRSA_TEMP_DIR                "$EASYRSA_PKI"
        set_var EASYRSA_REQ_CN                  ChangeMe
@@ -5971,6 +6001,9 @@
 
        set_var EASYRSA_MAX_TEMP                1
 
+       # configure EASYRSA_SAN_CRIT for use
+       export EASYRSA_SAN_CRIT="${EASYRSA_SAN_CRIT:+critical,}"
+
        verbose "default_vars; COMPLETED"
 } # => default_vars()
 
@@ -6096,7 +6129,6 @@
                selfsign_eku \
                internal_batch mv_temp_error \
                easyrsa_exit_with_error error_info \
-               require_pki require_ca \
                prompt_restore mktemp_counter
 
        # Protect $EASYRSA_ALIAS_DAYS from vars abuse
@@ -6893,9 +6925,9 @@
        cat <<- VERSION_TEXT
                EasyRSA Version Information
                Version:     $EASYRSA_version
-               Generated:   Fri Mar 13 16:18:45 CDT 2026
+               Generated:   Sat Sep 19 07:53:22 CDT 2026
                SSL Lib:     ${ssl_version:-undefined}
-               Git Commit:  0d746eec3f06210ae1710d17b9c8d38428058e19
+               Git Commit:  bab739d176a00f47819c79792863b13f4487b0c0
                Source Repo: https://github.com/OpenVPN/easy-rsa
                VERSION_TEXT
 } # => print_version()
@@ -6904,7 +6936,7 @@
 ########################################
 # Invocation entry point:
 
-EASYRSA_version="3.2.6"
+EASYRSA_version="3.2.7"
 NL='
 '
 
@@ -7129,7 +7161,7 @@
                        ;;
                --san-crit|--san-critical)
                        empty_ok=1
-                       export EASYRSA_SAN_CRIT='critical,'
+                       export EASYRSA_SAN_CRIT=1
                        ;;
                --bc-crit|--bc-critical)
                        empty_ok=1
@@ -7193,12 +7225,15 @@
 # Be secure with a restrictive umask
 [ "$EASYRSA_NO_UMASK" ] || umask "${EASYRSA_UMASK:=077}"
 
+# DEPRECATED behavior - This will be removed
 # option dependencies
 # Add full --san to extra extensions
+# Do not include EASYRSA_SAN_CRIT
+# If required, an externally set SAN must include 'critical,'
 if [ "$EASYRSA_SAN" ]; then
        EASYRSA_EXTRA_EXTS="\
 $EASYRSA_EXTRA_EXTS
-subjectAltName = ${EASYRSA_SAN_CRIT}${EASYRSA_SAN}"
+subjectAltName = $EASYRSA_SAN"
 fi
 
 # Set cmd now
@@ -7417,7 +7452,8 @@
                *)
                        # Only allow 'type' on command line
                        # Internally, overwrite and file-name is allowed
-                       write_legacy_file_v2 "$1" && unset -v EASYRSA_VERBOSE
+                       require_pki=""; require_ca=""; verify_working_env
+                       write_legacy_file_v2 "$1"
                esac
                ;;
        serial|check-serial)

Reply via email to