Update to CKBI 2.41 from NSS 3.53.0

Removing:
    # Certificate "AddTrust Low-Value Services Root"
    # Certificate "AddTrust External Root"
    # Certificate "Staat der Nederlanden Root CA - G2"

-Updates several certificates with CKA_SERVER_DISTRUST_AFTER with a data
-Fix circular dependency issue by moving ca-legacy and upcate-ca-trust to
 %posttrans
This commit is contained in:
Bob Relyea 2020-06-10 12:45:49 -07:00
parent 00da4d0e2a
commit 9a68b05c60
3 changed files with 90 additions and 489 deletions

View File

@ -35,10 +35,10 @@ Name: ca-certificates
# to have increasing version numbers. However, the new scheme will work,
# because all future versions will start with 2013 or larger.)
Version: 2020.2.40
Version: 2020.2.41
# for Rawhide, please always use release >= 2
# for Fedora release branches, please use release < 2 (1.0, 1.1, ...)
Release: 3%{?dist}
Release: 2%{?dist}
License: Public Domain
URL: https://fedoraproject.org/wiki/CA-Certificates
@ -306,9 +306,28 @@ fi
#if [ $1 -gt 1 ] ; then
# # when upgrading or downgrading
#fi
# if ln is available, go ahead and run the ca-legacy and update
# scripts. If not, what until %posttrans.
if [ -x %{-bindir}/ln ]; then
%{_bindir}/ca-legacy install
%{_bindir}/update-ca-trust
%define caupdatecomplete 1
fi
%posttrans
# When coreutils is installing with ca-certificates
# we need to wait until coreutils install to
# run our update since update requires ln to complete.
# There is a circular dependency here where
# ca-certificates depends on coreutils
# coreutils depends on openssl
# openssl depends on ca-certificates
# in that case, we want to complete the install in
# %posttrans when ln is available
%if ! %{caupdatecomplete}
%{_bindir}/ca-legacy install
%{_bindir}/update-ca-trust
fi
%files
%dir %{_sysconfdir}/ssl
@ -369,6 +388,13 @@ fi
%changelog
*Wed Jun 10 2020 Bob Relyea <rrelyea@redhat.com> - 2020.2.41-2
- Update to CKBI 2.41 from NSS 3.53.0
- Removing:
- # Certificate "AddTrust Low-Value Services Root"
- # Certificate "AddTrust External Root"
- # Certificate "Staat der Nederlanden Root CA - G2"
* Tue Jan 28 2020 Daiki Ueno <dueno@redhat.com> - 2020.2.40-3
- Update versioned dependency on p11-kit

View File

@ -1250,305 +1250,6 @@ CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "AddTrust Low-Value Services Root"
#
# Issuer: CN=AddTrust Class 1 CA Root,OU=AddTrust TTP Network,O=AddTrust AB,C=SE
# Serial Number: 1 (0x1)
# Subject: CN=AddTrust Class 1 CA Root,OU=AddTrust TTP Network,O=AddTrust AB,C=SE
# Not Valid Before: Tue May 30 10:38:31 2000
# Not Valid After : Sat May 30 10:38:31 2020
# Fingerprint (MD5): 1E:42:95:02:33:92:6B:B9:5F:C0:7F:DA:D6:B2:4B:FC
# Fingerprint (SHA1): CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D
CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "AddTrust Low-Value Services Root"
CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
CKA_SUBJECT MULTILINE_OCTAL
\060\145\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\035\060\033\006\003\125\004\013\023\024
\101\144\144\124\162\165\163\164\040\124\124\120\040\116\145\164
\167\157\162\153\061\041\060\037\006\003\125\004\003\023\030\101
\144\144\124\162\165\163\164\040\103\154\141\163\163\040\061\040
\103\101\040\122\157\157\164
END
CKA_ID UTF8 "0"
CKA_ISSUER MULTILINE_OCTAL
\060\145\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\035\060\033\006\003\125\004\013\023\024
\101\144\144\124\162\165\163\164\040\124\124\120\040\116\145\164
\167\157\162\153\061\041\060\037\006\003\125\004\003\023\030\101
\144\144\124\162\165\163\164\040\103\154\141\163\163\040\061\040
\103\101\040\122\157\157\164
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\001
END
CKA_VALUE MULTILINE_OCTAL
\060\202\004\030\060\202\003\000\240\003\002\001\002\002\001\001
\060\015\006\011\052\206\110\206\367\015\001\001\005\005\000\060
\145\061\013\060\011\006\003\125\004\006\023\002\123\105\061\024
\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165\163
\164\040\101\102\061\035\060\033\006\003\125\004\013\023\024\101
\144\144\124\162\165\163\164\040\124\124\120\040\116\145\164\167
\157\162\153\061\041\060\037\006\003\125\004\003\023\030\101\144
\144\124\162\165\163\164\040\103\154\141\163\163\040\061\040\103
\101\040\122\157\157\164\060\036\027\015\060\060\060\065\063\060
\061\060\063\070\063\061\132\027\015\062\060\060\065\063\060\061
\060\063\070\063\061\132\060\145\061\013\060\011\006\003\125\004
\006\023\002\123\105\061\024\060\022\006\003\125\004\012\023\013
\101\144\144\124\162\165\163\164\040\101\102\061\035\060\033\006
\003\125\004\013\023\024\101\144\144\124\162\165\163\164\040\124
\124\120\040\116\145\164\167\157\162\153\061\041\060\037\006\003
\125\004\003\023\030\101\144\144\124\162\165\163\164\040\103\154
\141\163\163\040\061\040\103\101\040\122\157\157\164\060\202\001
\042\060\015\006\011\052\206\110\206\367\015\001\001\001\005\000
\003\202\001\017\000\060\202\001\012\002\202\001\001\000\226\226
\324\041\111\140\342\153\350\101\007\014\336\304\340\334\023\043
\315\301\065\307\373\326\116\021\012\147\136\365\006\133\153\245
\010\073\133\051\026\072\347\207\262\064\006\305\274\005\245\003
\174\202\313\051\020\256\341\210\201\275\326\236\323\376\055\126
\301\025\316\343\046\235\025\056\020\373\006\217\060\004\336\247
\264\143\264\377\261\234\256\074\257\167\266\126\305\265\253\242
\351\151\072\075\016\063\171\062\077\160\202\222\231\141\155\215
\060\010\217\161\077\246\110\127\031\370\045\334\113\146\134\245
\164\217\230\256\310\371\300\006\042\347\254\163\337\245\056\373
\122\334\261\025\145\040\372\065\146\151\336\337\054\361\156\274
\060\333\054\044\022\333\353\065\065\150\220\313\000\260\227\041
\075\164\041\043\145\064\053\273\170\131\243\326\341\166\071\232
\244\111\216\214\164\257\156\244\232\243\331\233\322\070\134\233
\242\030\314\165\043\204\276\353\342\115\063\161\216\032\360\302
\370\307\035\242\255\003\227\054\370\317\045\306\366\270\044\061
\261\143\135\222\177\143\360\045\311\123\056\037\277\115\002\003
\001\000\001\243\201\322\060\201\317\060\035\006\003\125\035\016
\004\026\004\024\225\261\264\360\224\266\275\307\332\321\021\011
\041\276\301\257\111\375\020\173\060\013\006\003\125\035\017\004
\004\003\002\001\006\060\017\006\003\125\035\023\001\001\377\004
\005\060\003\001\001\377\060\201\217\006\003\125\035\043\004\201
\207\060\201\204\200\024\225\261\264\360\224\266\275\307\332\321
\021\011\041\276\301\257\111\375\020\173\241\151\244\147\060\145
\061\013\060\011\006\003\125\004\006\023\002\123\105\061\024\060
\022\006\003\125\004\012\023\013\101\144\144\124\162\165\163\164
\040\101\102\061\035\060\033\006\003\125\004\013\023\024\101\144
\144\124\162\165\163\164\040\124\124\120\040\116\145\164\167\157
\162\153\061\041\060\037\006\003\125\004\003\023\030\101\144\144
\124\162\165\163\164\040\103\154\141\163\163\040\061\040\103\101
\040\122\157\157\164\202\001\001\060\015\006\011\052\206\110\206
\367\015\001\001\005\005\000\003\202\001\001\000\054\155\144\033
\037\315\015\335\271\001\372\226\143\064\062\110\107\231\256\227
\355\375\162\026\246\163\107\132\364\353\335\351\365\326\373\105
\314\051\211\104\135\277\106\071\075\350\356\274\115\124\206\036
\035\154\343\027\047\103\341\211\126\053\251\157\162\116\111\063
\343\162\174\052\043\232\274\076\377\050\052\355\243\377\034\043
\272\103\127\011\147\115\113\142\006\055\370\377\154\235\140\036
\330\034\113\175\265\061\057\331\320\174\135\370\336\153\203\030
\170\067\127\057\350\063\007\147\337\036\307\153\052\225\166\256
\217\127\243\360\364\122\264\251\123\010\317\340\117\323\172\123
\213\375\273\034\126\066\362\376\262\266\345\166\273\325\042\145
\247\077\376\321\146\255\013\274\153\231\206\357\077\175\363\030
\062\312\173\306\343\253\144\106\225\370\046\151\331\125\203\173
\054\226\007\377\131\054\104\243\306\345\351\251\334\241\143\200
\132\041\136\041\317\123\124\360\272\157\211\333\250\252\225\317
\213\343\161\314\036\033\040\104\010\300\172\266\100\375\304\344
\065\341\035\026\034\320\274\053\216\326\161\331
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "AddTrust Low-Value Services Root"
# Issuer: CN=AddTrust Class 1 CA Root,OU=AddTrust TTP Network,O=AddTrust AB,C=SE
# Serial Number: 1 (0x1)
# Subject: CN=AddTrust Class 1 CA Root,OU=AddTrust TTP Network,O=AddTrust AB,C=SE
# Not Valid Before: Tue May 30 10:38:31 2000
# Not Valid After : Sat May 30 10:38:31 2020
# Fingerprint (MD5): 1E:42:95:02:33:92:6B:B9:5F:C0:7F:DA:D6:B2:4B:FC
# Fingerprint (SHA1): CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "AddTrust Low-Value Services Root"
CKA_CERT_SHA1_HASH MULTILINE_OCTAL
\314\253\016\240\114\043\001\326\151\173\335\067\237\315\022\353
\044\343\224\235
END
CKA_CERT_MD5_HASH MULTILINE_OCTAL
\036\102\225\002\063\222\153\271\137\300\177\332\326\262\113\374
END
CKA_ISSUER MULTILINE_OCTAL
\060\145\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\035\060\033\006\003\125\004\013\023\024
\101\144\144\124\162\165\163\164\040\124\124\120\040\116\145\164
\167\157\162\153\061\041\060\037\006\003\125\004\003\023\030\101
\144\144\124\162\165\163\164\040\103\154\141\163\163\040\061\040
\103\101\040\122\157\157\164
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\001
END
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "AddTrust External Root"
#
# Issuer: CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
# Serial Number: 1 (0x1)
# Subject: CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
# Not Valid Before: Tue May 30 10:48:38 2000
# Not Valid After : Sat May 30 10:48:38 2020
# Fingerprint (MD5): 1D:35:54:04:85:78:B0:3F:42:42:4D:BF:20:73:0A:3F
# Fingerprint (SHA1): 02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68
CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "AddTrust External Root"
CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
CKA_SUBJECT MULTILINE_OCTAL
\060\157\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\046\060\044\006\003\125\004\013\023\035
\101\144\144\124\162\165\163\164\040\105\170\164\145\162\156\141
\154\040\124\124\120\040\116\145\164\167\157\162\153\061\042\060
\040\006\003\125\004\003\023\031\101\144\144\124\162\165\163\164
\040\105\170\164\145\162\156\141\154\040\103\101\040\122\157\157
\164
END
CKA_ID UTF8 "0"
CKA_ISSUER MULTILINE_OCTAL
\060\157\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\046\060\044\006\003\125\004\013\023\035
\101\144\144\124\162\165\163\164\040\105\170\164\145\162\156\141
\154\040\124\124\120\040\116\145\164\167\157\162\153\061\042\060
\040\006\003\125\004\003\023\031\101\144\144\124\162\165\163\164
\040\105\170\164\145\162\156\141\154\040\103\101\040\122\157\157
\164
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\001
END
CKA_VALUE MULTILINE_OCTAL
\060\202\004\066\060\202\003\036\240\003\002\001\002\002\001\001
\060\015\006\011\052\206\110\206\367\015\001\001\005\005\000\060
\157\061\013\060\011\006\003\125\004\006\023\002\123\105\061\024
\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165\163
\164\040\101\102\061\046\060\044\006\003\125\004\013\023\035\101
\144\144\124\162\165\163\164\040\105\170\164\145\162\156\141\154
\040\124\124\120\040\116\145\164\167\157\162\153\061\042\060\040
\006\003\125\004\003\023\031\101\144\144\124\162\165\163\164\040
\105\170\164\145\162\156\141\154\040\103\101\040\122\157\157\164
\060\036\027\015\060\060\060\065\063\060\061\060\064\070\063\070
\132\027\015\062\060\060\065\063\060\061\060\064\070\063\070\132
\060\157\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\046\060\044\006\003\125\004\013\023\035
\101\144\144\124\162\165\163\164\040\105\170\164\145\162\156\141
\154\040\124\124\120\040\116\145\164\167\157\162\153\061\042\060
\040\006\003\125\004\003\023\031\101\144\144\124\162\165\163\164
\040\105\170\164\145\162\156\141\154\040\103\101\040\122\157\157
\164\060\202\001\042\060\015\006\011\052\206\110\206\367\015\001
\001\001\005\000\003\202\001\017\000\060\202\001\012\002\202\001
\001\000\267\367\032\063\346\362\000\004\055\071\340\116\133\355
\037\274\154\017\315\265\372\043\266\316\336\233\021\063\227\244
\051\114\175\223\237\275\112\274\223\355\003\032\343\217\317\345
\155\120\132\326\227\051\224\132\200\260\111\172\333\056\225\375
\270\312\277\067\070\055\036\076\221\101\255\160\126\307\360\117
\077\350\062\236\164\312\310\220\124\351\306\137\017\170\235\232
\100\074\016\254\141\252\136\024\217\236\207\241\152\120\334\327
\232\116\257\005\263\246\161\224\234\161\263\120\140\012\307\023
\235\070\007\206\002\250\351\250\151\046\030\220\253\114\260\117
\043\253\072\117\204\330\337\316\237\341\151\157\273\327\102\327
\153\104\344\307\255\356\155\101\137\162\132\161\010\067\263\171
\145\244\131\240\224\067\367\000\057\015\302\222\162\332\320\070
\162\333\024\250\105\304\135\052\175\267\264\326\304\356\254\315
\023\104\267\311\053\335\103\000\045\372\141\271\151\152\130\043
\021\267\247\063\217\126\165\131\365\315\051\327\106\267\012\053
\145\266\323\102\157\025\262\270\173\373\357\351\135\123\325\064
\132\047\002\003\001\000\001\243\201\334\060\201\331\060\035\006
\003\125\035\016\004\026\004\024\255\275\230\172\064\264\046\367
\372\304\046\124\357\003\275\340\044\313\124\032\060\013\006\003
\125\035\017\004\004\003\002\001\006\060\017\006\003\125\035\023
\001\001\377\004\005\060\003\001\001\377\060\201\231\006\003\125
\035\043\004\201\221\060\201\216\200\024\255\275\230\172\064\264
\046\367\372\304\046\124\357\003\275\340\044\313\124\032\241\163
\244\161\060\157\061\013\060\011\006\003\125\004\006\023\002\123
\105\061\024\060\022\006\003\125\004\012\023\013\101\144\144\124
\162\165\163\164\040\101\102\061\046\060\044\006\003\125\004\013
\023\035\101\144\144\124\162\165\163\164\040\105\170\164\145\162
\156\141\154\040\124\124\120\040\116\145\164\167\157\162\153\061
\042\060\040\006\003\125\004\003\023\031\101\144\144\124\162\165
\163\164\040\105\170\164\145\162\156\141\154\040\103\101\040\122
\157\157\164\202\001\001\060\015\006\011\052\206\110\206\367\015
\001\001\005\005\000\003\202\001\001\000\260\233\340\205\045\302
\326\043\342\017\226\006\222\235\101\230\234\331\204\171\201\331
\036\133\024\007\043\066\145\217\260\330\167\273\254\101\154\107
\140\203\121\260\371\062\075\347\374\366\046\023\307\200\026\245
\277\132\374\207\317\170\171\211\041\232\342\114\007\012\206\065
\274\362\336\121\304\322\226\267\334\176\116\356\160\375\034\071
\353\014\002\121\024\055\216\275\026\340\301\337\106\165\347\044
\255\354\364\102\264\205\223\160\020\147\272\235\006\065\112\030
\323\053\172\314\121\102\241\172\143\321\346\273\241\305\053\302
\066\276\023\015\346\275\143\176\171\173\247\011\015\100\253\152
\335\217\212\303\366\366\214\032\102\005\121\324\105\365\237\247
\142\041\150\025\040\103\074\231\347\174\275\044\330\251\221\027
\163\210\077\126\033\061\070\030\264\161\017\232\315\310\016\236
\216\056\033\341\214\230\203\313\037\061\361\104\114\306\004\163
\111\166\140\017\307\370\275\027\200\153\056\351\314\114\016\132
\232\171\017\040\012\056\325\236\143\046\036\125\222\224\330\202
\027\132\173\320\274\307\217\116\206\004
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "AddTrust External Root"
# Issuer: CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
# Serial Number: 1 (0x1)
# Subject: CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
# Not Valid Before: Tue May 30 10:48:38 2000
# Not Valid After : Sat May 30 10:48:38 2020
# Fingerprint (MD5): 1D:35:54:04:85:78:B0:3F:42:42:4D:BF:20:73:0A:3F
# Fingerprint (SHA1): 02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "AddTrust External Root"
CKA_CERT_SHA1_HASH MULTILINE_OCTAL
\002\372\363\342\221\103\124\150\140\170\127\151\115\365\344\133
\150\205\030\150
END
CKA_CERT_MD5_HASH MULTILINE_OCTAL
\035\065\124\004\205\170\260\077\102\102\115\277\040\163\012\077
END
CKA_ISSUER MULTILINE_OCTAL
\060\157\061\013\060\011\006\003\125\004\006\023\002\123\105\061
\024\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165
\163\164\040\101\102\061\046\060\044\006\003\125\004\013\023\035
\101\144\144\124\162\165\163\164\040\105\170\164\145\162\156\141
\154\040\124\124\120\040\116\145\164\167\157\162\153\061\042\060
\040\006\003\125\004\003\023\031\101\144\144\124\162\165\163\164
\040\105\170\164\145\162\156\141\154\040\103\101\040\122\157\157
\164
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\001
END
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "Entrust Root Certification Authority"
#
@ -1810,7 +1511,10 @@ CKA_VALUE MULTILINE_OCTAL
\302\005\146\200\241\313\346\063
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Wed Jan 01 00:00:00 2020
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\062\060\060\061\060\061\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Global CA"
@ -1972,7 +1676,10 @@ CKA_VALUE MULTILINE_OCTAL
\244\346\216\330\371\051\110\212\316\163\376\054
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Sun Sep 30 00:00:00 2018
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\070\060\071\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Universal CA"
@ -2134,7 +1841,10 @@ CKA_VALUE MULTILINE_OCTAL
\362\034\054\176\256\002\026\322\126\320\057\127\123\107\350\222
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Wed Jan 01 00:00:00 2020
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\062\060\060\061\060\061\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Universal CA 2"
@ -4131,7 +3841,10 @@ CKA_VALUE MULTILINE_OCTAL
\245\206\054\174\364\022
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Thu Sep 19 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\071\061\071\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "Taiwan GRCA"
@ -5329,7 +5042,10 @@ CKA_VALUE MULTILINE_OCTAL
\253\022\350\263\336\132\345\240\174\350\017\042\035\132\351\131
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Primary Certification Authority"
@ -5486,7 +5202,10 @@ CKA_VALUE MULTILINE_OCTAL
\215\126\214\150
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "thawte Primary Root CA"
@ -5663,7 +5382,10 @@ CKA_VALUE MULTILINE_OCTAL
\254\021\326\250\355\143\152
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
@ -7240,7 +6962,10 @@ CKA_VALUE MULTILINE_OCTAL
\021\055
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Primary Certification Authority - G3"
@ -7371,7 +7096,10 @@ CKA_VALUE MULTILINE_OCTAL
\367\130\077\056\162\002\127\243\217\241\024\056
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Sun Sep 30 00:00:00 2018
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\070\060\071\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "thawte Primary Root CA - G2"
@ -7533,7 +7261,10 @@ CKA_VALUE MULTILINE_OCTAL
\061\324\100\032\142\064\066\077\065\001\256\254\143\240
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "thawte Primary Root CA - G3"
@ -7671,7 +7402,10 @@ CKA_VALUE MULTILINE_OCTAL
\017\212
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Wed Jan 01 00:00:00 2020
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\062\060\060\061\060\061\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "GeoTrust Primary Certification Authority - G2"
@ -7843,7 +7577,10 @@ CKA_VALUE MULTILINE_OCTAL
\354\315\202\141\361\070\346\117\227\230\052\132\215
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Tue Apr 30 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\064\063\060\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "VeriSign Universal Root Certification Authority"
@ -8000,7 +7737,10 @@ CKA_VALUE MULTILINE_OCTAL
\055\247\330\206\052\335\056\020
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Thu Jan 31 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\060\061\063\061\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
@ -8206,177 +7946,6 @@ CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "Staat der Nederlanden Root CA - G2"
#
# Issuer: CN=Staat der Nederlanden Root CA - G2,O=Staat der Nederlanden,C=NL
# Serial Number: 10000012 (0x98968c)
# Subject: CN=Staat der Nederlanden Root CA - G2,O=Staat der Nederlanden,C=NL
# Not Valid Before: Wed Mar 26 11:18:17 2008
# Not Valid After : Wed Mar 25 11:03:10 2020
# Fingerprint (MD5): 7C:A5:0F:F8:5B:9A:7D:6D:30:AE:54:5A:E3:42:A2:8A
# Fingerprint (SHA1): 59:AF:82:79:91:86:C7:B4:75:07:CB:CF:03:57:46:EB:04:DD:B7:16
CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Staat der Nederlanden Root CA - G2"
CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
CKA_SUBJECT MULTILINE_OCTAL
\060\132\061\013\060\011\006\003\125\004\006\023\002\116\114\061
\036\060\034\006\003\125\004\012\014\025\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\061
\053\060\051\006\003\125\004\003\014\042\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\040
\122\157\157\164\040\103\101\040\055\040\107\062
END
CKA_ID UTF8 "0"
CKA_ISSUER MULTILINE_OCTAL
\060\132\061\013\060\011\006\003\125\004\006\023\002\116\114\061
\036\060\034\006\003\125\004\012\014\025\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\061
\053\060\051\006\003\125\004\003\014\042\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\040
\122\157\157\164\040\103\101\040\055\040\107\062
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\004\000\230\226\214
END
CKA_VALUE MULTILINE_OCTAL
\060\202\005\312\060\202\003\262\240\003\002\001\002\002\004\000
\230\226\214\060\015\006\011\052\206\110\206\367\015\001\001\013
\005\000\060\132\061\013\060\011\006\003\125\004\006\023\002\116
\114\061\036\060\034\006\003\125\004\012\014\025\123\164\141\141
\164\040\144\145\162\040\116\145\144\145\162\154\141\156\144\145
\156\061\053\060\051\006\003\125\004\003\014\042\123\164\141\141
\164\040\144\145\162\040\116\145\144\145\162\154\141\156\144\145
\156\040\122\157\157\164\040\103\101\040\055\040\107\062\060\036
\027\015\060\070\060\063\062\066\061\061\061\070\061\067\132\027
\015\062\060\060\063\062\065\061\061\060\063\061\060\132\060\132
\061\013\060\011\006\003\125\004\006\023\002\116\114\061\036\060
\034\006\003\125\004\012\014\025\123\164\141\141\164\040\144\145
\162\040\116\145\144\145\162\154\141\156\144\145\156\061\053\060
\051\006\003\125\004\003\014\042\123\164\141\141\164\040\144\145
\162\040\116\145\144\145\162\154\141\156\144\145\156\040\122\157
\157\164\040\103\101\040\055\040\107\062\060\202\002\042\060\015
\006\011\052\206\110\206\367\015\001\001\001\005\000\003\202\002
\017\000\060\202\002\012\002\202\002\001\000\305\131\347\157\165
\252\076\113\234\265\270\254\236\013\344\371\331\312\253\135\217
\265\071\020\202\327\257\121\340\073\341\000\110\152\317\332\341
\006\103\021\231\252\024\045\022\255\042\350\000\155\103\304\251
\270\345\037\211\113\147\275\141\110\357\375\322\340\140\210\345
\271\030\140\050\303\167\053\255\260\067\252\067\336\144\131\052
\106\127\344\113\271\370\067\174\325\066\347\200\301\266\363\324
\147\233\226\350\316\327\306\012\123\320\153\111\226\363\243\013
\005\167\110\367\045\345\160\254\060\024\040\045\343\177\165\132
\345\110\370\116\173\003\007\004\372\202\141\207\156\360\073\304
\244\307\320\365\164\076\245\135\032\010\362\233\045\322\366\254
\004\046\076\125\072\142\050\245\173\262\060\257\370\067\302\321
\272\326\070\375\364\357\111\060\067\231\046\041\110\205\001\251
\345\026\347\334\220\125\337\017\350\070\315\231\067\041\117\135
\365\042\157\152\305\022\026\140\027\125\362\145\146\246\247\060
\221\070\301\070\035\206\004\204\272\032\045\170\136\235\257\314
\120\140\326\023\207\122\355\143\037\155\145\175\302\025\030\164
\312\341\176\144\051\214\162\330\026\023\175\013\111\112\361\050
\033\040\164\153\305\075\335\260\252\110\011\075\056\202\224\315
\032\145\331\053\210\232\231\274\030\176\237\356\175\146\174\076
\275\224\270\201\316\315\230\060\170\301\157\147\320\276\137\340
\150\355\336\342\261\311\054\131\170\222\252\337\053\140\143\362
\345\136\271\343\312\372\177\120\206\076\242\064\030\014\011\150
\050\021\034\344\341\271\134\076\107\272\062\077\030\314\133\204
\365\363\153\164\304\162\164\341\343\213\240\112\275\215\146\057
\352\255\065\332\040\323\210\202\141\360\022\042\266\274\320\325
\244\354\257\124\210\045\044\074\247\155\261\162\051\077\076\127
\246\177\125\257\156\046\306\376\347\314\100\134\121\104\201\012
\170\336\112\316\125\277\035\325\331\267\126\357\360\166\377\013
\171\265\257\275\373\251\151\221\106\227\150\200\024\066\035\263
\177\273\051\230\066\245\040\372\202\140\142\063\244\354\326\272
\007\247\156\305\317\024\246\347\326\222\064\330\201\365\374\035
\135\252\134\036\366\243\115\073\270\367\071\002\003\001\000\001
\243\201\227\060\201\224\060\017\006\003\125\035\023\001\001\377
\004\005\060\003\001\001\377\060\122\006\003\125\035\040\004\113
\060\111\060\107\006\004\125\035\040\000\060\077\060\075\006\010
\053\006\001\005\005\007\002\001\026\061\150\164\164\160\072\057
\057\167\167\167\056\160\153\151\157\166\145\162\150\145\151\144
\056\156\154\057\160\157\154\151\143\151\145\163\057\162\157\157
\164\055\160\157\154\151\143\171\055\107\062\060\016\006\003\125
\035\017\001\001\377\004\004\003\002\001\006\060\035\006\003\125
\035\016\004\026\004\024\221\150\062\207\025\035\211\342\265\361
\254\066\050\064\215\013\174\142\210\353\060\015\006\011\052\206
\110\206\367\015\001\001\013\005\000\003\202\002\001\000\250\101
\112\147\052\222\201\202\120\156\341\327\330\263\071\073\363\002
\025\011\120\121\357\055\275\044\173\210\206\073\371\264\274\222
\011\226\271\366\300\253\043\140\006\171\214\021\116\121\322\171
\200\063\373\235\110\276\354\101\103\201\037\176\107\100\034\345
\172\010\312\252\213\165\255\024\304\302\350\146\074\202\007\247
\346\047\202\133\030\346\017\156\331\120\076\212\102\030\051\306
\264\126\374\126\020\240\005\027\275\014\043\177\364\223\355\234
\032\121\276\335\105\101\277\221\044\264\037\214\351\137\317\173
\041\231\237\225\237\071\072\106\034\154\371\315\173\234\220\315
\050\251\307\251\125\273\254\142\064\142\065\023\113\024\072\125
\203\271\206\215\222\246\306\364\007\045\124\314\026\127\022\112
\202\170\310\024\331\027\202\046\055\135\040\037\171\256\376\324
\160\026\026\225\203\330\065\071\377\122\135\165\034\026\305\023
\125\317\107\314\165\145\122\112\336\360\260\247\344\012\226\013
\373\255\302\342\045\204\262\335\344\275\176\131\154\233\360\360
\330\347\312\362\351\227\070\176\211\276\314\373\071\027\141\077
\162\333\072\221\330\145\001\031\035\255\120\244\127\012\174\113
\274\234\161\163\052\105\121\031\205\314\216\375\107\247\164\225
\035\250\321\257\116\027\261\151\046\302\252\170\127\133\305\115
\247\345\236\005\027\224\312\262\137\240\111\030\215\064\351\046
\154\110\036\252\150\222\005\341\202\163\132\233\334\007\133\010
\155\175\235\327\215\041\331\374\024\040\252\302\105\337\077\347
\000\262\121\344\302\370\005\271\171\032\214\064\363\236\133\344
\067\133\153\112\337\054\127\212\100\132\066\272\335\165\104\010
\067\102\160\014\376\334\136\041\240\243\212\300\220\234\150\332
\120\346\105\020\107\170\266\116\322\145\311\303\067\337\341\102
\143\260\127\067\105\055\173\212\234\277\005\352\145\125\063\367
\071\020\305\050\052\041\172\033\212\304\044\371\077\025\310\232
\025\040\365\125\142\226\355\155\223\120\274\344\252\170\255\331
\313\012\145\207\246\146\301\304\201\243\167\072\130\036\013\356
\203\213\235\036\322\122\244\314\035\157\260\230\155\224\061\265
\370\161\012\334\271\374\175\062\140\346\353\257\212\001
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "Staat der Nederlanden Root CA - G2"
# Issuer: CN=Staat der Nederlanden Root CA - G2,O=Staat der Nederlanden,C=NL
# Serial Number: 10000012 (0x98968c)
# Subject: CN=Staat der Nederlanden Root CA - G2,O=Staat der Nederlanden,C=NL
# Not Valid Before: Wed Mar 26 11:18:17 2008
# Not Valid After : Wed Mar 25 11:03:10 2020
# Fingerprint (MD5): 7C:A5:0F:F8:5B:9A:7D:6D:30:AE:54:5A:E3:42:A2:8A
# Fingerprint (SHA1): 59:AF:82:79:91:86:C7:B4:75:07:CB:CF:03:57:46:EB:04:DD:B7:16
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Staat der Nederlanden Root CA - G2"
CKA_CERT_SHA1_HASH MULTILINE_OCTAL
\131\257\202\171\221\206\307\264\165\007\313\317\003\127\106\353
\004\335\267\026
END
CKA_CERT_MD5_HASH MULTILINE_OCTAL
\174\245\017\370\133\232\175\155\060\256\124\132\343\102\242\212
END
CKA_ISSUER MULTILINE_OCTAL
\060\132\061\013\060\011\006\003\125\004\006\023\002\116\114\061
\036\060\034\006\003\125\004\012\014\025\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\061
\053\060\051\006\003\125\004\003\014\042\123\164\141\141\164\040
\144\145\162\040\116\145\144\145\162\154\141\156\144\145\156\040
\122\157\157\164\040\103\101\040\055\040\107\062
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\004\000\230\226\214
END
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "Hongkong Post Root CA 1"
#
@ -11580,7 +11149,10 @@ CKA_VALUE MULTILINE_OCTAL
\371\210\075\176\270\157\156\003\344\102
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Sat Dec 28 00:00:00 2019
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\071\061\062\062\070\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for Certificate "EC-ACC"
@ -12734,7 +12306,10 @@ CKA_VALUE MULTILINE_OCTAL
\307\314\165\301\226\305\235
END
CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE
CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE
# For Server Distrust After: Fri Sep 01 00:00:00 2017
CKA_NSS_SERVER_DISTRUST_AFTER MULTILINE_OCTAL
\061\067\060\071\060\061\060\060\060\060\060\060\132
END
CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE
# Trust for "EE Certification Centre Root CA"

View File

@ -46,8 +46,8 @@
* It's recommend to switch back to 0 after having reached version 98/99.
*/
#define NSS_BUILTINS_LIBRARY_VERSION_MAJOR 2
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 40
#define NSS_BUILTINS_LIBRARY_VERSION "2.40"
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 41
#define NSS_BUILTINS_LIBRARY_VERSION "2.41"
/* These version numbers detail the semantic changes to the ckfw engine. */
#define NSS_BUILTINS_HARDWARE_VERSION_MAJOR 1