The latest OpenSSL packages moved all of the certs/keys to /etc/pki. In your postfix config, change the path to the ca-bundle to be /etc/pki/tls/certs and you should be all set.
Should we conditionally do string replacement to fix this during postfix %post?
Warren Togami wtogami@xxxxxxxxxx