Commit Graph

113 Commits

Author SHA1 Message Date
Kai Engert
201f66b36b Stop using sln in ca-legacy script. 2018-01-19 13:07:06 +01:00
Kai Engert
078e3f0b9b Use ln -s, because sln was removed from glibc. rhbz#1536349 2018-01-19 12:57:53 +01:00
Kai Engert
e3a2f67722 Update to CKBI 2.20 from NSS 3.34.1 2017-11-27 21:37:37 +01:00
Bruno Goncalves
5fae916208 Add CI tests using the standard test interface 2017-09-25 11:03:21 +02:00
Kai Engert
6b317cb305 Merge branch 'master' of ssh://pkgs.fedoraproject.org/rpms/ca-certificates 2017-08-15 15:41:33 +02:00
Kai Engert
7a69d0d22f - Set P11_KIT_NO_USER_CONFIG=1 to prevent p11-kit from reading user configuration files (rhbz#1478172). 2017-08-15 15:39:45 +02:00
Fedora Release Engineering
c735381906 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild 2017-07-26 04:24:01 +00:00
Kai Engert
7accaab619 Update to (yet unreleased) CKBI 2.16 which is planned for NSS 3.32. Mozilla removed all trust bits for code signing. 2017-07-19 11:40:38 +02:00
Petr Písař
a2a1b6c64d perl dependency renamed to perl-interpreter <https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules> 2017-07-12 14:05:20 +02:00
Kai Engert
6cea01c4b1 Update to CKBI 2.14 from NSS 3.30.2 2017-04-26 14:37:22 +02:00
Kai Engert
c1c275770a For CAs trusted by Mozilla, set attribute nss-mozilla-ca-policy: true
Set attribute modifiable: false
Require p11-kit 0.23.4
2017-02-23 19:39:46 +01:00
Kai Engert
f0b0be2c1f - Changed the packaged bundle to use the flexible p11-kit-object-v1 file format,
as a preparation to fix bugs in the interaction between p11-kit-trust and
  Mozilla applications, such as Firefox, Thunderbird etc.
- Changed update-ca-trust to add comments to extracted PEM format files.
- Added an utility to help with comparing output of the trust dump command.
2017-02-13 21:04:08 +01:00
Fedora Release Engineering
b1bece42f2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild 2017-02-10 07:11:28 +00:00
Kai Engert
1926916bb3 Update to CKBI 2.11 from NSS 3.28.1 2017-01-11 14:16:31 +01:00
Kai Engert
00af3f958b Update to CKBI 2.10 from NSS 3.27 2016-10-04 19:54:47 +02:00
Kai Engert
552fa4a6d3 Revert to the unmodified upstream CA list, changing the legacy trust to an empty list. Keeping the ca-legacy tool and existing config, however, the configuration has no effect after this change. 2016-08-18 14:11:51 +02:00
Kai Engert
02204a071d Update to CKBI 2.9 from NSS 3.26 with legacy modifications 2016-08-16 18:51:35 +02:00
Kai Engert
54fae46d1e Update to CKBI 2.8 from NSS 3.25 with legacy modifications 2016-07-15 13:44:08 +02:00
Kai Engert
8867a18ec0 Only create backup files if there is an original file (bug 999017). 2016-05-10 20:28:23 +02:00
Kai Engert
5300aa7f75 Use sln, not ln, to avoid the dependency on coreutils. 2016-05-10 18:48:44 +02:00
Kai Engert
de9cf5de04 Fix typos in a manual page and in a README file. 2016-04-25 18:58:31 +02:00
Kai Engert
53674928a5 Update to CKBI 2.7 from NSS 3.23 with legacy modifications 2016-03-16 18:25:23 +01:00
Dennis Gilmore
199d06cb4e - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild 2016-02-03 17:20:38 +00:00
Kai Engert
da979a1a44 Update to CKBI 2.6 from NSS 3.21 with legacy modifications 2015-11-23 17:51:07 +01:00
Kai Engert
87f92384d1 Update the spec file to version 2.5 2015-08-13 22:49:30 +02:00
Kai Engert
6df1740e0f Update to CKBI 2.5 from NSS 3.19.3 with legacy modifications
This update adjusts the diff-from-upstream patch (which is a patch purely provided for documentation purposes).
It shows a modification that was made as part of the 2.4 update (which in fact removed legacy treatment for one certificate, because upstream had reverted it to an earlier trusted state, as documented on the package wiki page).
No changes to the legacy treatment were made in this 2.5 update.
2015-08-13 22:43:25 +02:00
Dennis Gilmore
298b40723b - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild 2015-06-17 02:13:52 +00:00
Kai Engert
b2076a019e Update to CKBI 2.4 from NSS 3.18.1 with legacy modifications 2015-05-05 20:18:08 +02:00
Kai Engert
41111200ad Fixed a typo in the ca-legacy manual page. 2015-05-05 17:27:27 +02:00
Kai Engert
40d3667f3c rename legacy=enable to legacy=default and related changes; add ca-legacy man page; handle absent configuration in ca-legacy 2015-03-31 23:02:57 +02:00
Kai Engert
b18dd49764 Update to CKBI 2.3 from NSS 3.18 with legacy modifications 2015-03-20 22:12:01 +01:00
Kai Engert
ca86efd661 Update the documented differences from upstream 2.2 2015-03-20 21:49:48 +01:00
Kai Engert
b1d00ef388 Fix mistakes in the legacy handling of the upstream 2.1 and 2.2 releases 2015-03-20 21:23:05 +01:00
Kai Engert
053dde8a2f - Update to CKBI 2.2 from NSS 3.17.3 with legacy modifications 2014-12-16 22:09:03 +01:00
Kai Engert
3837ff2e4e Add a patch to document the changes from upstream version 2.1 2014-12-16 19:42:43 +01:00
Kai Engert
a1c2aece67 update project URL 2014-11-21 16:29:39 +01:00
Kai Engert
99c1a4b448 remove the obsolete blacklist.txt file 2014-11-20 17:24:17 +01:00
Kai Engert
f9355b7943 remove the unnecessary entry in trust-fixes, because we no longer ship the old entrust root (it got replaced with one that contains the basic constraints extension) 2014-11-20 17:22:39 +01:00
Peter Lemenkov
0c19add667 Restore Requires: coreutils
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
2014-11-15 08:11:39 +03:00
Peter Lemenkov
d8e353c1d2 A proper fix for #1158343
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
2014-11-14 18:33:00 +03:00
Kai Engert
d7defefea7 add Requires: coreutils (rhbz#1158343) 2014-10-29 12:14:57 +01:00
Kai Engert
e24bfeb6b0 - Introduce the ca-legacy utility and a ca-legacy.conf configuration file.
By default, legacy roots required for OpenSSL/GnuTLS compatibility
  are kept enabled. Using the ca-legacy utility, the legacy roots can be
  disabled. If disabled, the system will use the trust set as provided
  by the upstream Mozilla CA list. (See also: rhbz#1158197)
2014-10-28 20:54:15 +01:00
Kai Engert
f81c301d27 - Temporarily re-enable several legacy root CA certificates because of
compatibility issues with software based on OpenSSL/GnuTLS,
  see rhbz#1144808
2014-09-21 10:33:16 +02:00
Kai Engert
18eedda612 - Update to CKBI 2.1 from NSS 3.16.4
- Fix rhbz#1130226
2014-08-14 17:06:04 +02:00
Dennis Gilmore
b0943c5cc0 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild 2014-06-06 22:50:54 -05:00
Kai Engert
f176bca921 Update to CKBI 1.97 from NSS 3.16 2014-03-19 11:30:07 +01:00
Kai Engert
4a1396fc65 Merge branch 'master' of ssh://pkgs.fedoraproject.org/ca-certificates
Conflicts:
	ca-certificates.spec
2014-02-10 20:15:14 +01:00
Kai Engert
278ac24070 remove openjdk build requirement 2014-02-10 20:13:22 +01:00
Ville Skyttä
a14dcb43a0 Own the %{_datadir}/pki dir. 2014-01-25 20:39:23 +02:00
Kai Engert
5df4185c4d * Thu Jan 09 2014 Kai Engert <kaie@redhat.com> - 2013.1.96-1
- Update to CKBI 1.96 from NSS 3.15.4
2014-01-09 17:38:04 +01:00