From 712c78984c891e6357e1b1dc414431fb6c226c49 Mon Sep 17 00:00:00 2001 From: Philippe Normand Date: Mon, 3 Jun 2019 09:20:31 +0100 Subject: gnutls: Use ca-certificates as default trust store file Since version 2.58 the glib-networking TLS database relies on GnuTLS's system trust store, so not enabling it leads to TLS errors in applications depending on glib-networking. The raised runtime warning is: process:500): GLib-Net-WARNING **: 09:14:09.321: Failed to load TLS database: Failed to load system trust store: GnuTLS was not configured with a system trust (app:490): ... TLS Error: TLS certificate has unknown CA. (From OE-Core rev: 1d147be584d2f016853edbe9751247d7daa0b5d0) Signed-off-by: Richard Purdie Signed-off-by: Armin Kuster --- meta/recipes-support/gnutls/gnutls_3.6.7.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-support/gnutls/gnutls_3.6.7.bb b/meta/recipes-support/gnutls/gnutls_3.6.7.bb index e05dc2b57d..01dd23c961 100644 --- a/meta/recipes-support/gnutls/gnutls_3.6.7.bb +++ b/meta/recipes-support/gnutls/gnutls_3.6.7.bb @@ -44,6 +44,7 @@ EXTRA_OECONF = " \ --enable-local-libopts \ --enable-openssl-compatibility \ --with-libpthread-prefix=${STAGING_DIR_HOST}${prefix} \ + --with-default-trust-store-file=/etc/ssl/certs/ca-certificates.crt \ " LDFLAGS_append_libc-musl = " -largp" -- cgit 1.2.3-korg