ssl-cert.eclass: Set default key length to 4096 bit and allow to specify message...
authorThomas Deutschmann <whissi@gentoo.org>
Wed, 24 May 2017 11:16:00 +0000 (13:16 +0200)
committerThomas Deutschmann <whissi@gentoo.org>
Wed, 24 May 2017 11:16:00 +0000 (13:16 +0200)
eclass/ssl-cert.eclass

index 6bec347234d42d85e8b9370dd0ad0766bbfe7b38..bfe5291314c02e885c5481a4b1ef575f6c768ee8 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2014 Gentoo Foundation
+# Copyright 1999-2017 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 # @ECLASS: ssl-cert.eclass
@@ -66,7 +66,8 @@ gen_cnf() {
 
        # These can be overridden in the ebuild
        SSL_DAYS="${SSL_DAYS:-730}"
-       SSL_BITS="${SSL_BITS:-1024}"
+       SSL_BITS="${SSL_BITS:-4096}"
+       SSL_MD="${SSL_MD:-sha256}"
        SSL_COUNTRY="${SSL_COUNTRY:-US}"
        SSL_STATE="${SSL_STATE:-California}"
        SSL_LOCALITY="${SSL_LOCALITY:-Santa Barbara}"
@@ -166,6 +167,7 @@ gen_crt() {
        if [ "${1}" ] ; then
                ebegin "Generating self-signed X.509 Certificate for CA"
                openssl x509 -extfile "${SSL_CONF}" \
+                       -${SSL_MD} \
                        -days ${SSL_DAYS} -req -signkey "${base}.key" \
                        -in "${base}.csr" -out "${base}.crt" &>/dev/null
        else
@@ -173,7 +175,7 @@ gen_crt() {
                ebegin "Generating authority-signed X.509 Certificate"
                openssl x509 -extfile "${SSL_CONF}" \
                        -days ${SSL_DAYS} -req -CAserial "${SSL_SERIAL}" \
-                       -CAkey "${ca}.key" -CA "${ca}.crt" \
+                       -CAkey "${ca}.key" -CA "${ca}.crt" -${SSL_MD} \
                        -in "${base}.csr" -out "${base}.crt" &>/dev/null
        fi
        eend $?