Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
Set RANDFILE=/dev/null for ipa-server-configure-first.service
OpenSSL requires at least one of HOME or RANDFILE environment
variables to be set for it to work.

Without this fix, the external CA setup crashes because OpenSSL
is unable to write its random state anywhere when it tries to
generate a CSR for the external CA to sign.
  • Loading branch information
stlaz committed Jan 12, 2018
1 parent 4f45c77 commit bd3a33a
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions ipa-server-configure-first.service
Expand Up @@ -3,6 +3,7 @@ Description=Configure IPA server upon the first start

[Service]
Type=oneshot
Environment="RANDFILE=/dev/null"
ExecStart=/usr/sbin/ipa-server-configure-first
ExecStartPost=/usr/sbin/ipa-server-status-check
FailureAction=poweroff
Expand Down

0 comments on commit bd3a33a

Please sign in to comment.