Update to CKBI 2.3 from NSS 3.18 with legacy modifications

This commit is contained in:
Kai Engert 2015-03-20 22:12:01 +01:00
parent ca86efd661
commit b18dd49764
4 changed files with 1506 additions and 20 deletions

View File

@ -36,7 +36,7 @@ Name: ca-certificates
# to have increasing version numbers. However, the new scheme will work,
# because all future versions will start with 2013 or larger.)
Version: 2014.2.2
Version: 2015.2.3
# for Rawhide, please always use release >= 2
# for Fedora release branches, please use release < 2 (1.0, 1.1, ...)
Release: 2%{?dist}
@ -369,6 +369,8 @@ fi
%changelog
* Fri Mar 20 2015 Kai Engert <kaie@redhat.com> - 2015.2.3-2
- Update to CKBI 2.3 from NSS 3.18 with legacy modifications
- Fixed a mistake in the legacy handling of the upstream 2.2 release:
Removed two AOL certificates from the legacy group, because
upstream didn't remove them as part of phasing out 1024-bit

File diff suppressed because it is too large Load Diff

View File

@ -1,5 +1,5 @@
--- /tmp/certdata-2.2.txt 2015-01-22 20:49:26.000000000 +0100
+++ certdata.txt 2015-03-20 21:10:31.571381076 +0100
--- certdata-2.3.txt 2015-03-17 00:03:37.000000000 +0100
+++ certdata.txt 2015-03-20 22:02:52.672993593 +0100
@@ -23,100 +23,515 @@
# CKA_SUBJECT DER+base64 (varies)
# CKA_ID byte array (varies)
@ -516,7 +516,111 @@
\164\151\146\151\143\141\164\145\040\101\165\164\150\157\162\151
\164\171\060\201\237\060\015\006\011\052\206\110\206\367\015\001
\001\001\005\000\003\201\215\000\060\201\211\002\201\201\000\301
@@ -530,100 +945,103 @@
@@ -140,100 +555,103 @@
\070\062\062\061\066\064\061\065\061\132\060\013\006\003\125\035
\017\004\004\003\002\001\006\060\037\006\003\125\035\043\004\030
\060\026\200\024\110\346\150\371\053\322\262\225\327\107\330\043
\040\020\117\063\230\220\237\324\060\035\006\003\125\035\016\004
\026\004\024\110\346\150\371\053\322\262\225\327\107\330\043\040
\020\117\063\230\220\237\324\060\014\006\003\125\035\023\004\005
\060\003\001\001\377\060\032\006\011\052\206\110\206\366\175\007
\101\000\004\015\060\013\033\005\126\063\056\060\143\003\002\006
\300\060\015\006\011\052\206\110\206\367\015\001\001\005\005\000
\003\201\201\000\130\316\051\352\374\367\336\265\316\002\271\027
\265\205\321\271\343\340\225\314\045\061\015\000\246\222\156\177
\266\222\143\236\120\225\321\232\157\344\021\336\143\205\156\230
\356\250\377\132\310\323\125\262\146\161\127\336\300\041\353\075
\052\247\043\111\001\004\206\102\173\374\356\177\242\026\122\265
\147\147\323\100\333\073\046\130\262\050\167\075\256\024\167\141
\326\372\052\146\047\240\015\372\247\163\134\352\160\361\224\041
\145\104\137\372\374\357\051\150\251\242\207\171\357\171\357\117
\254\007\167\070
END
# Trust for Certificate "Equifax Secure CA"
# Issuer: OU=Equifax Secure Certificate Authority,O=Equifax,C=US
# Serial Number: 903804111 (0x35def4cf)
# Subject: OU=Equifax Secure Certificate Authority,O=Equifax,C=US
# Not Valid Before: Sat Aug 22 16:41:51 1998
# Not Valid After : Wed Aug 22 16:41:51 2018
# Fingerprint (MD5): 67:CB:9D:C0:13:24:8A:82:9B:B2:17:1E:D1:1B:EC:D4
# Fingerprint (SHA1): D2:32:09:AD:23:D3:14:23:21:74:E4:0D:7F:9D:62:13:97:86:63:3A
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Equifax Secure CA"
CKA_CERT_SHA1_HASH MULTILINE_OCTAL
\322\062\011\255\043\323\024\043\041\164\344\015\177\235\142\023
\227\206\143\072
END
CKA_CERT_MD5_HASH MULTILINE_OCTAL
\147\313\235\300\023\044\212\202\233\262\027\036\321\033\354\324
END
CKA_ISSUER MULTILINE_OCTAL
\060\116\061\013\060\011\006\003\125\004\006\023\002\125\123\061
\020\060\016\006\003\125\004\012\023\007\105\161\165\151\146\141
\170\061\055\060\053\006\003\125\004\013\023\044\105\161\165\151
\146\141\170\040\123\145\143\165\162\145\040\103\145\162\164\151
\146\151\143\141\164\145\040\101\165\164\150\157\162\151\164\171
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\004\065\336\364\317
END
+LEGACY_CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
+LEGACY_CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
+LEGACY_CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
# Distrust "Distrust a pb.com certificate that does not comply with the baseline requirements."
# Issuer: OU=Equifax Secure Certificate Authority,O=Equifax,C=US
# Serial Number: 1407252 (0x157914)
# Subject: CN=*.pb.com,OU=Meters,O=Pitney Bowes,L=Danbury,ST=Connecticut,C=US
# Not Valid Before: Mon Feb 01 14:54:04 2010
# Not Valid After : Tue Sep 30 00:00:00 2014
# Fingerprint (MD5): 8F:46:BE:99:47:6F:93:DC:5C:01:54:50:D0:4A:BD:AC
# Fingerprint (SHA1): 30:F1:82:CA:1A:5E:4E:4F:F3:6E:D0:E6:38:18:B8:B9:41:CB:5F:8C
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Distrust a pb.com certificate that does not comply with the baseline requirements."
CKA_ISSUER MULTILINE_OCTAL
\060\116\061\013\060\011\006\003\125\004\006\023\002\125\123\061
\020\060\016\006\003\125\004\012\023\007\105\161\165\151\146\141
\170\061\055\060\053\006\003\125\004\013\023\044\105\161\165\151
\146\141\170\040\123\145\143\165\162\145\040\103\145\162\164\151
\146\151\143\141\164\145\040\101\165\164\150\157\162\151\164\171
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\003\025\171\024
END
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_NOT_TRUSTED
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_NOT_TRUSTED
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_NOT_TRUSTED
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "Digital Signature Trust Co. Global CA 1"
#
# Issuer: OU=DSTCA E1,O=Digital Signature Trust Co.,C=US
# Serial Number: 913315222 (0x36701596)
# Subject: OU=DSTCA E1,O=Digital Signature Trust Co.,C=US
# Not Valid Before: Thu Dec 10 18:10:23 1998
# Not Valid After : Mon Dec 10 18:40:23 2018
# Fingerprint (MD5): 25:7A:BA:83:2E:B6:A2:0B:DA:FE:F5:02:0F:08:D7:AD
# Fingerprint (SHA1): 81:96:8B:3A:EF:1C:DC:70:F5:FA:32:69:C2:92:A3:63:5B:D1:23:D3
CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Digital Signature Trust Co. Global CA 1"
CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
CKA_SUBJECT MULTILINE_OCTAL
@@ -530,100 +948,103 @@
\005\252\354\003\037\170\177\236\223\271\232\000\252\043\175\326
\254\205\242\143\105\307\162\047\314\364\114\306\165\161\322\071
\357\117\102\360\165\337\012\220\306\216\040\157\230\017\370\254
@ -620,7 +724,7 @@
\141\165\164\150\157\162\151\172\145\144\040\165\163\145\040\157
\156\154\171\061\037\060\035\006\003\125\004\013\023\026\126\145
\162\151\123\151\147\156\040\124\162\165\163\164\040\116\145\164
@@ -824,100 +1242,103 @@
@@ -824,100 +1245,103 @@
\005\005\000\003\201\201\000\162\056\371\177\321\361\161\373\304
\236\366\305\136\121\212\100\230\270\150\370\233\034\203\330\342
\235\275\377\355\241\346\146\352\057\011\364\312\327\352\245\053
@ -724,7 +828,7 @@
\141\165\164\150\157\162\151\172\145\144\040\165\163\145\040\157
\156\154\171\061\037\060\035\006\003\125\004\013\023\026\126\145
\162\151\123\151\147\156\040\124\162\165\163\164\040\116\145\164
@@ -971,100 +1392,103 @@
@@ -971,100 +1395,103 @@
\005\000\003\201\201\000\121\115\315\276\134\313\230\031\234\025
\262\001\071\170\056\115\017\147\160\160\231\306\020\132\224\244
\123\115\124\155\053\257\015\135\100\213\144\323\327\356\336\126
@ -828,7 +932,7 @@
\055\163\141\061\020\060\016\006\003\125\004\013\023\007\122\157
\157\164\040\103\101\061\033\060\031\006\003\125\004\003\023\022
\107\154\157\142\141\154\123\151\147\156\040\122\157\157\164\040
@@ -1240,100 +1664,520 @@
@@ -1240,100 +1667,520 @@
\333\335\161\064\032\301\124\332\106\077\340\323\052\253\155\124
\042\365\072\142\315\040\157\272\051\211\327\335\221\356\323\134
\242\076\241\133\101\365\337\345\144\103\055\351\325\071\253\322
@ -1349,7 +1453,7 @@
\002\021\000\213\133\165\126\204\124\205\013\000\317\257\070\110
\316\261\244
END
@@ -2008,100 +2852,274 @@
@@ -2008,100 +2855,274 @@
\154\273\322\036\000\260\041\355\370\101\142\202\271\330\262\304
\273\106\120\363\061\305\217\001\250\164\353\365\170\047\332\347
\367\146\103\363\236\203\076\040\252\303\065\140\221\316
@ -1624,7 +1728,111 @@
CKA_VALUE MULTILINE_OCTAL
\060\202\004\052\060\202\003\022\240\003\002\001\002\002\004\070
\143\336\370\060\015\006\011\052\206\110\206\367\015\001\001\005
@@ -2526,100 +3544,103 @@
@@ -2410,100 +3431,103 @@
\305\310\303\141\002\003\001\000\001\243\146\060\144\060\021\006
\011\140\206\110\001\206\370\102\001\001\004\004\003\002\000\007
\060\017\006\003\125\035\023\001\001\377\004\005\060\003\001\001
\377\060\037\006\003\125\035\043\004\030\060\026\200\024\276\250
\240\164\162\120\153\104\267\311\043\330\373\250\377\263\127\153
\150\154\060\035\006\003\125\035\016\004\026\004\024\276\250\240
\164\162\120\153\104\267\311\043\330\373\250\377\263\127\153\150
\154\060\015\006\011\052\206\110\206\367\015\001\001\004\005\000
\003\201\201\000\060\342\001\121\252\307\352\137\332\271\320\145
\017\060\326\076\332\015\024\111\156\221\223\047\024\061\357\304
\367\055\105\370\354\307\277\242\101\015\043\264\222\371\031\000
\147\275\001\257\315\340\161\374\132\317\144\304\340\226\230\320
\243\100\342\001\212\357\047\007\361\145\001\212\104\055\006\145
\165\122\300\206\020\040\041\137\154\153\017\154\256\011\034\257
\362\242\030\064\304\165\244\163\034\361\215\334\357\255\371\263
\166\264\222\277\334\225\020\036\276\313\310\073\132\204\140\031
\126\224\251\125
END
# Trust for Certificate "Equifax Secure Global eBusiness CA"
# Issuer: CN=Equifax Secure Global eBusiness CA-1,O=Equifax Secure Inc.,C=US
# Serial Number: 1 (0x1)
# Subject: CN=Equifax Secure Global eBusiness CA-1,O=Equifax Secure Inc.,C=US
# Not Valid Before: Mon Jun 21 04:00:00 1999
# Not Valid After : Sun Jun 21 04:00:00 2020
# Fingerprint (MD5): 8F:5D:77:06:27:C4:98:3C:5B:93:78:E7:D7:7D:9B:CC
# Fingerprint (SHA1): 7E:78:4A:10:1C:82:65:CC:2D:E1:F1:6D:47:B4:40:CA:D9:0A:19:45
CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Equifax Secure Global eBusiness CA"
CKA_CERT_SHA1_HASH MULTILINE_OCTAL
\176\170\112\020\034\202\145\314\055\341\361\155\107\264\100\312
\331\012\031\105
END
CKA_CERT_MD5_HASH MULTILINE_OCTAL
\217\135\167\006\047\304\230\074\133\223\170\347\327\175\233\314
END
CKA_ISSUER MULTILINE_OCTAL
\060\132\061\013\060\011\006\003\125\004\006\023\002\125\123\061
\034\060\032\006\003\125\004\012\023\023\105\161\165\151\146\141
\170\040\123\145\143\165\162\145\040\111\156\143\056\061\055\060
\053\006\003\125\004\003\023\044\105\161\165\151\146\141\170\040
\123\145\143\165\162\145\040\107\154\157\142\141\154\040\145\102
\165\163\151\156\145\163\163\040\103\101\055\061
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\001
END
+LEGACY_CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
+LEGACY_CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
+LEGACY_CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR
CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
#
# Certificate "Equifax Secure eBusiness CA 1"
#
# Issuer: CN=Equifax Secure eBusiness CA-1,O=Equifax Secure Inc.,C=US
# Serial Number: 4 (0x4)
# Subject: CN=Equifax Secure eBusiness CA-1,O=Equifax Secure Inc.,C=US
# Not Valid Before: Mon Jun 21 04:00:00 1999
# Not Valid After : Sun Jun 21 04:00:00 2020
# Fingerprint (MD5): 64:9C:EF:2E:44:FC:C6:8F:52:07:D0:51:73:8F:CB:3D
# Fingerprint (SHA1): DA:40:18:8B:91:89:A3:ED:EE:AE:DA:97:FE:2F:9D:F5:B7:D1:8A:41
CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
CKA_TOKEN CK_BBOOL CK_TRUE
CKA_PRIVATE CK_BBOOL CK_FALSE
CKA_MODIFIABLE CK_BBOOL CK_FALSE
CKA_LABEL UTF8 "Equifax Secure eBusiness CA 1"
CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
CKA_SUBJECT MULTILINE_OCTAL
\060\123\061\013\060\011\006\003\125\004\006\023\002\125\123\061
\034\060\032\006\003\125\004\012\023\023\105\161\165\151\146\141
\170\040\123\145\143\165\162\145\040\111\156\143\056\061\046\060
\044\006\003\125\004\003\023\035\105\161\165\151\146\141\170\040
\123\145\143\165\162\145\040\145\102\165\163\151\156\145\163\163
\040\103\101\055\061
END
CKA_ID UTF8 "0"
CKA_ISSUER MULTILINE_OCTAL
\060\123\061\013\060\011\006\003\125\004\006\023\002\125\123\061
\034\060\032\006\003\125\004\012\023\023\105\161\165\151\146\141
\170\040\123\145\143\165\162\145\040\111\156\143\056\061\046\060
\044\006\003\125\004\003\023\035\105\161\165\151\146\141\170\040
\123\145\143\165\162\145\040\145\102\165\163\151\156\145\163\163
\040\103\101\055\061
END
CKA_SERIAL_NUMBER MULTILINE_OCTAL
\002\001\004
END
CKA_VALUE MULTILINE_OCTAL
\060\202\002\202\060\202\001\353\240\003\002\001\002\002\001\004
\060\015\006\011\052\206\110\206\367\015\001\001\004\005\000\060
\123\061\013\060\011\006\003\125\004\006\023\002\125\123\061\034
\060\032\006\003\125\004\012\023\023\105\161\165\151\146\141\170
\040\123\145\143\165\162\145\040\111\156\143\056\061\046\060\044
\006\003\125\004\003\023\035\105\161\165\151\146\141\170\040\123
\145\143\165\162\145\040\145\102\165\163\151\156\145\163\163\040
\103\101\055\061\060\036\027\015\071\071\060\066\062\061\060\064
@@ -2526,100 +3550,103 @@
\022\173\376\217\246\003\002\003\001\000\001\243\146\060\144\060
\021\006\011\140\206\110\001\206\370\102\001\001\004\004\003\002
\000\007\060\017\006\003\125\035\023\001\001\377\004\005\060\003
@ -1728,7 +1936,7 @@
\060\022\006\003\125\004\012\023\013\101\144\144\124\162\165\163
\164\040\101\102\061\035\060\033\006\003\125\004\013\023\024\101
\144\144\124\162\165\163\164\040\124\124\120\040\116\145\164\167
@@ -7415,100 +8436,103 @@
@@ -7415,100 +8442,103 @@
\164\164\160\163\072\057\057\167\167\167\056\156\145\164\154\157
\143\153\056\156\145\164\057\144\157\143\163\040\157\162\040\142
\171\040\145\055\155\141\151\154\040\141\164\040\143\160\163\100
@ -1832,7 +2040,7 @@
\002\001\150
END
CKA_VALUE MULTILINE_OCTAL
@@ -7588,100 +8612,103 @@
@@ -7588,100 +8618,103 @@
\145\164\154\157\143\153\056\156\145\164\057\144\157\143\163\040
\157\162\040\142\171\040\145\055\155\141\151\154\040\141\164\040
\143\160\163\100\156\145\164\154\157\143\153\056\156\145\164\056
@ -1936,7 +2144,7 @@
END
CKA_VALUE MULTILINE_OCTAL
\060\202\004\060\060\202\003\030\240\003\002\001\002\002\020\120
@@ -17139,100 +18166,103 @@
@@ -17139,100 +18172,103 @@
\005\252\354\003\037\170\177\236\223\271\232\000\252\043\175\326
\254\205\242\143\105\307\162\047\314\364\114\306\165\161\322\071
\357\117\102\360\165\337\012\220\306\216\040\157\230\017\370\254

View File

@ -45,8 +45,8 @@
* of the comment in the CK_VERSION type definition.
*/
#define NSS_BUILTINS_LIBRARY_VERSION_MAJOR 2
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 2
#define NSS_BUILTINS_LIBRARY_VERSION "2.2"
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 3
#define NSS_BUILTINS_LIBRARY_VERSION "2.3"
/* These version numbers detail the semantic changes to the ckfw engine. */
#define NSS_BUILTINS_HARDWARE_VERSION_MAJOR 1