Blame SOURCES/freeradius-bootstrap-fixed-dhparam.patch

601982
From b31f1ab9a0e1c010037d2d660e3ce4ea7eb07d6c Mon Sep 17 00:00:00 2001
601982
From: Alexander Scheel <ascheel@redhat.com>
601982
Date: Wed, 5 Aug 2020 16:10:52 -0400
601982
Subject: [PATCH] Use fixed FIPS-approved dhparam by default
601982
601982
Signed-off-by: Alexander Scheel <ascheel@redhat.com>
601982
---
601982
 raddb/certs/Makefile  | 2 +-
601982
 raddb/certs/bootstrap | 7 +++++--
601982
 2 files changed, 6 insertions(+), 3 deletions(-)
601982
601982
diff --git a/raddb/certs/Makefile b/raddb/certs/Makefile
601982
index 5cbfd46..41b7aea 100644
601982
--- a/raddb/certs/Makefile
601982
+++ b/raddb/certs/Makefile
601982
@@ -59,7 +59,7 @@ passwords.mk: server.cnf ca.cnf client.cnf inner-server.cnf
601982
 #
601982
 ######################################################################
601982
 dh:
601982
-	$(OPENSSL) dhparam -out dh -2 $(DH_KEY_SIZE)
601982
+	cp rfc3526-group-18-8192.dhparam dh
601982
 
601982
 ######################################################################
601982
 #
601982
diff --git a/raddb/certs/bootstrap b/raddb/certs/bootstrap
601982
index 9920ecf..59b3310 100755
601982
--- a/raddb/certs/bootstrap
601982
+++ b/raddb/certs/bootstrap
601982
@@ -13,6 +13,10 @@
601982
 umask 027
601982
 cd `dirname $0`
601982
 
601982
+if [ ! -e random ]; then
601982
+  ln -sf /dev/urandom random
601982
+fi
601982
+
601982
 make -h > /dev/null 2>&1
601982
 
601982
 #
601982
@@ -35,8 +39,7 @@ fi
601982
 #  re-generate these commands.
601982
 #
601982
 if [ ! -e dh ]; then
601982
-  openssl dhparam -out dh 2048 || exit 1
601982
-  ln -sf /dev/urandom random
601982
+  cp rfc3526-group-18-8192.dhparam dh
601982
 fi
601982
 
601982
 if [ ! -e server.key ]; then
601982
-- 
601982
2.26.2
601982