Unreadable or symlinked openssl.cnf breaks bind9

Bug #1160435 reported by Ville Walveranta
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssl (Debian)
Fix Released
Unknown
openssl (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

If /etc/ssl/openssl.cnf is unreadable by bind9 process, or is symlinked from another file (regardless of whether the target is readable by bind9 or not), bind9 will not start.

This is apparently the same issue as what was discussed on the Debian side in 2010:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584911

I have several custom openssl.cnf files, and recently decided to symlink the 'default' openssl.cnf to one of them (the target is world readable). On the next reboot bind would not start. With a lot of digging, much like in the debian ticket I referred to above, I eventually clued in on the fact that somehow OpenSSL is involved even though it's not an advertised dependency.

If this can't be corrected (i.e. so that bind would start regardless of whether openssl.cnf can be accessed), perhaps a more informative error message could be added. A simple "cannot read openssl.cnf" would have saved me an hour of debug time.

--

Description: Ubuntu 12.04.2 LTS
Release: 12.04

bind9:
  Installed: 1:9.8.1.dfsg.P1-4ubuntu0.5
  Candidate: 1:9.8.1.dfsg.P1-4ubuntu0.5
  Version table:
 *** 1:9.8.1.dfsg.P1-4ubuntu0.5 0
        500 http://us.archive.ubuntu.com/ubuntu/ precise-updates/main amd64 Packages
        500 http://security.ubuntu.com/ubuntu/ precise-security/main amd64 Packages
        100 /var/lib/dpkg/status
     1:9.8.1.dfsg.P1-4 0
        500 http://us.archive.ubuntu.com/ubuntu/ precise/main amd64 Packages

Revision history for this message
Robie Basak (racb) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better.

Thanks for linking to the Debian bug. According to the discussion there, this is a bug in openssl and not in bind9. It seems likely to me that this will not get fixed in Ubuntu until it is fixed in Debian.

Changed in bind9 (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
affects: bind9 (Ubuntu) → openssl (Ubuntu)
Changed in openssl (Debian):
status: Unknown → New
Changed in openssl (Debian):
status: New → Fix Released
Revision history for this message
Adrien Nader (adrien) wrote :

Marking as Fix Released since we've imported the fixed version from Debian.

Changed in openssl (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.