Commit Graph

52 Commits

Author SHA1 Message Date
Frantisek Krenzelok
b877c1467d Update to CKBI 2.69_v8.0.302 from NSS 3.101
Resolves: RHEL-46002
2024-07-11 09:35:04 +02:00
Frantisek Krenzelok
4050611f40 Update to CKBI 2.68_v8.0.302 from NSS 3.101
Resolves: RHEL-46002

   Removing:
    # Certificate "Verisign Class 1 Public Primary Certification Authority - G3"
    # Certificate "Verisign Class 2 Public Primary Certification Authority - G3"
    # Certificate "Security Communication Root CA"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "Symantec Class 1 Public Primary Certification Authority - G6"
    # Certificate "Symantec Class 2 Public Primary Certification Authority - G6"
    # Certificate "TrustCor RootCert CA-1"
    # Certificate "TrustCor RootCert CA-2"
    # Certificate "TrustCor ECA-1"
   Adding:
    # Certificate "TrustAsia Global Root CA G3"
    # Certificate "TrustAsia Global Root CA G4"
    # Certificate "CommScope Public Trust ECC Root-01"
    # Certificate "CommScope Public Trust ECC Root-02"
    # Certificate "CommScope Public Trust RSA Root-01"
    # Certificate "CommScope Public Trust RSA Root-02"
    # Certificate "D-Trust SBR Root CA 1 2022"
    # Certificate "D-Trust SBR Root CA 2 2022"
    # Certificate "Telekom Security SMIME ECC Root 2021"
    # Certificate "Telekom Security TLS ECC Root 2020"
    # Certificate "Telekom Security SMIME RSA Root 2023"
    # Certificate "Telekom Security TLS RSA Root 2023"
    # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
    # Certificate "SECOM Trust.net"
    # Certificate "VeriSign Class 2 Public Primary Certification Authority - G3"
    # Certificate "SSL.com Code Signing RSA Root CA 2022"
    # Certificate "SSL.com Code Signing ECC Root CA 2022"
2024-07-03 15:47:53 +02:00
Robert Relyea
fe9aee3d97 - Update fetch to handle merging microsoft code signing certs.
- Update fetchobjsign.sh and merge2certdata.py to their
ca-certificate-scripts equivalent.
 - Update to CKBI 2.62-v7.0.401 from NSS 3.93
   Removing:
    # Certificate "Camerfirma Chambers of Commerce Root"
    # Certificate "Hongkong Post Root CA 1"
    # Certificate "FNMT-RCM"
   Adding:
    # Certificate "LAWtrust Root CA2 (4096)"
    # Certificate "Sectigo Public Email Protection Root E46"
    # Certificate "Sectigo Public Email Protection Root R46"
    # Certificate "Sectigo Public Server Authentication Root E46"
    # Certificate "Sectigo Public Server Authentication Root R46"
    # Certificate "SSL.com TLS RSA Root CA 2022"
    # Certificate "SSL.com TLS ECC Root CA 2022"
    # Certificate "SSL.com Client ECC Root CA 2022"
    # Certificate "SSL.com Client RSA Root CA 2022"
    # Certificate "Atos TrustedRoot Root CA ECC G2 2020"
    # Certificate "Atos TrustedRoot Root CA RSA G2 2020"
    # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
    # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
    # Certificate "Chambers of Commerce Root"
2023-10-04 14:31:59 -07:00
Robert Relyea
19f1fee1e6 Update to CKBI 2.60_v7.0.306 from NSS 3.91
Removing:
    # Certificate "OpenTrust Root CA G1"
    # Certificate "Swedish Government Root Authority v1"
    # Certificate "DigiNotar Root CA G2"
    # Certificate "Federal Common Policy CA"
    # Certificate "TC TrustCenter Universal CA III"
    # Certificate "CCA India 2007"
    # Certificate "ipsCA Global CA Root"
    # Certificate "ipsCA Main CA Root"
    # Certificate "Macao Post eSignTrust Root Certification Authority"
    # Certificate "InfoNotary CSP Root"
    # Certificate "DigiNotar Root CA"
    # Certificate "Root CA"
    # Certificate "GPKIRootCA"
    # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
    # Certificate "TC TrustCenter Universal CA I"
    # Certificate "TC TrustCenter Universal CA II"
    # Certificate "TC TrustCenter Class 2 CA II"
    # Certificate "TC TrustCenter Class 4 CA II"
    # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "CertRSA01"
    # Certificate "KISA RootCA 3"
    # Certificate "A-CERT ADVANCED"
    # Certificate "A-Trust-Qual-01"
    # Certificate "A-Trust-nQual-01"
    # Certificate "Serasa Certificate Authority II"
    # Certificate "TDC Internet"
    # Certificate "America Online Root Certification Authority 2"
    # Certificate "RSA Security Inc"
    # Certificate "Public Notary Root"
    # Certificate "Autoridade Certificadora Raiz Brasileira"
    # Certificate "Post.Trust Root CA"
    # Certificate "Entrust.net Secure Server Certification Authority"
    # Certificate "ePKI EV SSL Certification Authority - G1"
   Adding:
    # Certificate "BJCA Global Root CA1"
    # Certificate "BJCA Global Root CA2"
    # Certificate "Symantec Enterprise Mobile Root for Microsoft"
    # Certificate "A-Trust-Root-05"
    # Certificate "ADOCA02"
    # Certificate "StartCom Certification Authority G2"
    # Certificate "ATHEX Root CA"
    # Certificate "EBG Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "GeoTrust Primary Certification Authority"
    # Certificate "thawte Primary Root CA"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
    # Certificate "America Online Root Certification Authority 1"
    # Certificate "Juur-SK"
    # Certificate "ComSign CA"
    # Certificate "ComSign Secured CA"
    # Certificate "ComSign Advanced Security CA"
    # Certificate "Sonera Class2 CA"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G3"
    # Certificate "VeriSign, Inc."
    # Certificate "GTE CyberTrust Global Root"
    # Certificate "Equifax Secure Global eBusiness CA-1"
    # Certificate "Equifax"
    # Certificate "Class 1 Primary CA"
    # Certificate "Swiss Government Root CA III"
    # Certificate "Application CA G4 Root"
    # Certificate "SSC GDL CA Root A"
    # Certificate "GlobalSign Code Signing Root E45"
    # Certificate "GlobalSign Code Signing Root R45"
    # Certificate "Entrust Code Signing Root Certification Authority - CSBR1"
2023-08-01 10:11:53 -07:00
Frantisek Krenzelok
baa0ace302 Update to CKBI 2.60 from NSS 3.86
Removing:
    # Certificate "Camerfirma Global Chambersign Root"
    # Certificate "Staat der Nederlanden EV Root CA"
   Adding:
    # Certificate "DigiCert TLS ECC P384 Root G5"
    # Certificate "DigiCert TLS RSA4096 Root G5"
    # Certificate "DigiCert SMIME ECC P384 Root G5"
    # Certificate "DigiCert SMIME RSA4096 Root G5"
    # Certificate "Certainly Root R1"
    # Certificate "Certainly Root E1"
    # Certificate "E-Tugra Global Root CA RSA v3"
    # Certificate "E-Tugra Global Root CA ECC v3"
    # Certificate "DIGITALSIGN GLOBAL ROOT RSA CA"
    # Certificate "DIGITALSIGN GLOBAL ROOT ECDSA CA"
    # Certificate "Global Chambersign Root"
2023-01-20 20:06:00 +01:00
Bob Relyea
3e24439003 Update to CKBI 2.54 from NSS 3.79
Removing:
    # Certificate "TrustCor ECA-1"
    # Certificate "TrustCor RootCert CA-2"
    # Certificate "TrustCor RootCert CA-1"
    # Certificate "Network Solutions Certificate Authority"
    # Certificate "COMODO Certification Authority"
    # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
    # Certificate "Microsec e-Szigno Root CA 2009"
    # Certificate "TWCA Root Certification Authority"
    # Certificate "Izenpe.com"
    # Certificate "state-institutions"
    # Certificate "GlobalSign"
    # Certificate "Common Policy"
    # Certificate "A-Trust-nQual-03"
    # Certificate "A-Trust-Qual-02"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "Government Root Certification Authority"
    # Certificate "AC Raíz Certicámara S.A."
2022-07-28 12:10:46 -07:00
Bob Relyea
d4451d31cd Update to CKBI 2.54 from NSS 3.79 2022-07-27 16:05:04 -07:00
Bob Relyea
f6b8f45e83 Update to CKBI 2.54 from NSS 3.79
Removing:
    # Certificate "GlobalSign Root CA - R2"
    # Certificate "DST Root CA X3"
    # Certificate "Explicitly Distrusted DigiNotar PKIoverheid G2"
   Adding:
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "vTrus ECC Root CA"
    # Certificate "vTrus Root CA"
    # Certificate "ISRG Root X2"
    # Certificate "HiPKI Root CA - G1"
    # Certificate "Telia Root CA v2"
    # Certificate "D-TRUST BR Root CA 1 2020"
    # Certificate "D-TRUST EV Root CA 1 2020"
    # Certificate "CAEDICOM Root"
    # Certificate "I.CA Root CA/RSA"
    # Certificate "MULTICERT Root Certification Authority 01"
    # Certificate "Certification Authority of WoSign G2"
    # Certificate "CA WoSign ECC Root"
    # Certificate "CCA India 2015 SPL"
    # Certificate "Swedish Government Root Authority v3"
    # Certificate "Swedish Government Root Authority v2"
    # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
    # Certificate "OpenTrust Root CA G1"
    # Certificate "OpenTrust Root CA G2"
    # Certificate "OpenTrust Root CA G3"
    # Certificate "Certplus Root CA G1"
    # Certificate "Certplus Root CA G2"
    # Certificate "Government Root Certification Authority"
    # Certificate "A-Trust-Qual-02"
    # Certificate "Thailand National Root Certification Authority - G1"
    # Certificate "TrustCor ECA-1"
    # Certificate "TrustCor RootCert CA-2"
    # Certificate "TrustCor RootCert CA-1"
    # Certificate "Certification Authority of WoSign"
    # Certificate "CA 沃通根证书"
    # Certificate "SSC GDL CA Root B"
    # Certificate "SAPO Class 2 Root CA"
    # Certificate "SAPO Class 3 Root CA"
    # Certificate "SAPO Class 4 Root CA"
    # Certificate "CA Disig Root R1"
    # Certificate "Autoridad Certificadora Raíz Nacional de Uruguay"
    # Certificate "ApplicationCA2 Root"
    # Certificate "GlobalSign"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G4"
    # Certificate "Halcom Root CA"
    # Certificate "Swisscom Root EV CA 2"
    # Certificate "CFCA GT CA"
    # Certificate "Digidentity L3 Root CA - G2"
    # Certificate "SITHS Root CA v1"
    # Certificate "Macao Post eSignTrust Root Certification Authority (G02)"
    # Certificate "Autoridade Certificadora Raiz Brasileira v2"
    # Certificate "Swisscom Root CA 2"
    # Certificate "IGC/A AC racine Etat francais"
    # Certificate "PersonalID Trustworthy RootCA 2011"
    # Certificate "Swedish Government Root Authority v1"
    # Certificate "Swiss Government Root CA II"
    # Certificate "Swiss Government Root CA I"
    # Certificate "Network Solutions Certificate Authority"
    # Certificate "COMODO Certification Authority"
    # Certificate "LuxTrust Global Root"
    # Certificate "AC1 RAIZ MTIN"
    # Certificate "Microsoft Root Certificate Authority 2011"
    # Certificate "CCA India 2011"
    # Certificate "ANCERT Certificados Notariales V2"
    # Certificate "ANCERT Certificados CGN V2"
    # Certificate "EE Certification Centre Root CA"
    # Certificate "DigiNotar Root CA G2"
    # Certificate "Federal Common Policy CA"
    # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
    # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
    # Certificate "China Internet Network Information Center EV Certificates Root"
    # Certificate "Verizon Global Root CA"
    # Certificate "SwissSign Silver Root CA - G3"
    # Certificate "SwissSign Platinum Root CA - G3"
    # Certificate "SwissSign Gold Root CA - G3"
    # Certificate "Microsec e-Szigno Root CA 2009"
    # Certificate "SITHS CA v3"
    # Certificate "Certinomis - Autorité Racine"
    # Certificate "ANF Server CA"
    # Certificate "Thawte Premium Server CA"
    # Certificate "Thawte Server CA"
    # Certificate "TC TrustCenter Universal CA III"
    # Certificate "KEYNECTIS ROOT CA"
    # Certificate "I.CA - Standard Certification Authority, 09/2009"
    # Certificate "I.CA - Qualified Certification Authority, 09/2009"
    # Certificate "VI Registru Centras RCSC (RootCA)"
    # Certificate "CCA India 2007"
    # Certificate "Autoridade Certificadora Raiz Brasileira v1"
    # Certificate "ipsCA Global CA Root"
    # Certificate "ipsCA Main CA Root"
    # Certificate "Actalis Authentication CA G1"
    # Certificate "A-Trust-Qual-03"
    # Certificate "AddTrust External CA Root"
    # Certificate "ECRaizEstado"
    # Certificate "Configuration"
    # Certificate "FNMT-RCM"
    # Certificate "StartCom Certification Authority"
    # Certificate "TWCA Root Certification Authority"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
    # Certificate "thawte Primary Root CA - G2"
    # Certificate "GeoTrust Primary Certification Authority - G2"
    # Certificate "VeriSign Universal Root Certification Authority"
    # Certificate "thawte Primary Root CA - G3"
    # Certificate "GeoTrust Primary Certification Authority - G3"
    # Certificate "E-ME SSI (RCA)"
    # Certificate "ACEDICOM Root"
    # Certificate "Autoridad Certificadora Raiz de la Secretaria de Economia"
    # Certificate "Correo Uruguayo - Root CA"
    # Certificate "CNNIC ROOT"
    # Certificate "Common Policy"
    # Certificate "Macao Post eSignTrust Root Certification Authority"
    # Certificate "Staat der Nederlanden Root CA - G2"
    # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
    # Certificate "AC Raíz Certicámara S.A."
    # Certificate "Cisco Root CA 2048"
    # Certificate "CA Disig"
    # Certificate "InfoNotary CSP Root"
    # Certificate "UCA Global Root"
    # Certificate "UCA Root"
    # Certificate "DigiNotar Root CA"
    # Certificate "Starfield Services Root Certificate Authority"
    # Certificate "I.CA - Qualified root certificate"
    # Certificate "I.CA - Standard root certificate"
    # Certificate "e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
    # Certificate "Japanese Government"
    # Certificate "AdminCA-CD-T01"
    # Certificate "Admin-Root-CA"
    # Certificate "Izenpe.com"
    # Certificate "TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3"
    # Certificate "Halcom CA FO"
    # Certificate "Halcom CA PO 2"
    # Certificate "Root CA"
    # Certificate "GPKIRootCA"
    # Certificate "ACNLB"
    # Certificate "state-institutions"
    # Certificate "state-institutions"
    # Certificate "SECOM Trust Systems CO.,LTD."
    # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
    # Certificate "D-TRUST Root Class 2 CA 2007"
    # Certificate "D-TRUST Root Class 3 CA 2007"
    # Certificate "SSC Root CA A"
    # Certificate "SSC Root CA B"
    # Certificate "SSC Root CA C"
    # Certificate "Autoridad de Certificacion de la Abogacia"
    # Certificate "Root CA Generalitat Valenciana"
    # Certificate "VAS Latvijas Pasts SSI(RCA)"
    # Certificate "ANCERT Certificados CGN"
    # Certificate "ANCERT Certificados Notariales"
    # Certificate "ANCERT Corporaciones de Derecho Publico"
    # Certificate "GLOBALTRUST"
    # Certificate "Certipost E-Trust TOP Root CA"
    # Certificate "Certipost E-Trust Primary Qualified CA"
    # Certificate "Certipost E-Trust Primary Normalised CA"
    # Certificate "GlobalSign"
    # Certificate "IGC/A"
    # Certificate "S-TRUST Authentication and Encryption Root CA 2005:PN"
    # Certificate "TC TrustCenter Universal CA I"
    # Certificate "TC TrustCenter Universal CA II"
    # Certificate "TC TrustCenter Class 2 CA II"
    # Certificate "TC TrustCenter Class 4 CA II"
    # Certificate "Swisscom Root CA 1"
    # Certificate "Microsec e-Szigno Root CA"
    # Certificate "LGPKI"
    # Certificate "AC RAIZ DNIE"
    # Certificate "Common Policy"
    # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "A-Trust-nQual-03"
    # Certificate "A-Trust-nQual-03"
    # Certificate "CertRSA01"
    # Certificate "KISA RootCA 1"
    # Certificate "KISA RootCA 3"
    # Certificate "NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado"
    # Certificate "A-CERT ADVANCED"
    # Certificate "A-Trust-Qual-01"
    # Certificate "A-Trust-nQual-01"
    # Certificate "A-Trust-Qual-02"
    # Certificate "Staat der Nederlanden Root CA"
    # Certificate "Serasa Certificate Authority II"
    # Certificate "TDC Internet"
    # Certificate "America Online Root Certification Authority 2"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "Government Root Certification Authority"
    # Certificate "RSA Security Inc"
    # Certificate "Public Notary Root"
    # Certificate "GeoTrust Global CA"
    # Certificate "GeoTrust Global CA 2"
    # Certificate "GeoTrust Universal CA"
    # Certificate "GeoTrust Universal CA 2"
    # Certificate "QuoVadis Root Certification Authority"
    # Certificate "Autoridade Certificadora Raiz Brasileira"
    # Certificate "Post.Trust Root CA"
    # Certificate "Microsoft Root Authority"
    # Certificate "Microsoft Root Certificate Authority"
    # Certificate "Microsoft Root Certificate Authority 2010"
    # Certificate "Entrust.net Secure Server Certification Authority"
    # Certificate "UTN-USERFirst-Object"
    # Certificate "BYTE Root Certification Authority 001"
    # Certificate "CISRCA1"
    # Certificate "ePKI Root Certification Authority - G2"
    # Certificate "ePKI EV SSL Certification Authority - G1"
    # Certificate "AC Raíz Certicámara S.A."
    # Certificate "SSL.com EV Root Certification Authority RSA"
    # Certificate "LuxTrust Global Root 2"
    # Certificate "ACA ROOT"
    # Certificate "Security Communication ECC RootCA1"
    # Certificate "Security Communication RootCA3"
    # Certificate "CHAMBERS OF COMMERCE ROOT - 2016"
    # Certificate "Network Solutions RSA Certificate Authority"
    # Certificate "Network Solutions ECC Certificate Authority"
    # Certificate "Australian Defence Public Root CA"
    # Certificate "SI-TRUST Root"
    # Certificate "Halcom Root Certificate Authority"
    # Certificate "Application CA G3 Root"
    # Certificate "GLOBALTRUST 2015"
    # Certificate "Microsoft ECC Product Root Certificate Authority 2018"
    # Certificate "emSign Root CA - G2"
    # Certificate "emSign Root CA - C2"
    # Certificate "Microsoft ECC TS Root Certificate Authority 2018"
    # Certificate "DigiCert CS ECC P384 Root G5"
    # Certificate "DigiCert CS RSA4096 Root G5"
    # Certificate "DigiCert RSA4096 Root G5"
    # Certificate "DigiCert ECC P384 Root G5"
    # Certificate "HARICA Code Signing RSA Root CA 2021"
    # Certificate "HARICA Code Signing ECC Root CA 2021"
    # Certificate "Microsoft Identity Verification Root Certificate Authority 2020"
2022-07-15 10:08:43 -07:00
Bob Relyea
662998d9d7 Update to CKBI 2.52 from NSS 3.72
Adding:
    # Certificate "TunTrust Root CA"
    # Certificate "HARICA TLS RSA Root CA 2021"
    # Certificate "HARICA TLS ECC Root CA 2021"
    # Certificate "HARICA Client RSA Root CA 2021"
    # Certificate "HARICA Client ECC Root CA 2021"
2021-12-13 09:07:38 -08:00
Bob Relyea
6d222498e8 Update to CKBI 2.50 from NSS 3.67
Removing:
    # Certificate "Trustis FPS Root CA"
    # Certificate "GlobalSign Code Signing Root R45"
    # Certificate "GlobalSign Code Signing Root E45"
    # Certificate "Halcom Root Certificate Authority"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
    # Certificate "GLOBALTRUST"
    # Certificate "MULTICERT Root Certification Authority 01"
    # Certificate "Verizon Global Root CA"
    # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
    # Certificate "CAEDICOM Root"
    # Certificate "COMODO Certification Authority"
    # Certificate "Security Communication ECC RootCA1"
    # Certificate "Security Communication RootCA3"
    # Certificate "AC RAIZ DNIE"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G3"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
    # Certificate "VeriSign Universal Root Certification Authority"
    # Certificate "GeoTrust Global CA"
    # Certificate "GeoTrust Primary Certification Authority"
    # Certificate "thawte Primary Root CA"
    # Certificate "thawte Primary Root CA - G2"
    # Certificate "thawte Primary Root CA - G3"
    # Certificate "GeoTrust Primary Certification Authority - G3"
    # Certificate "GeoTrust Primary Certification Authority - G2"
    # Certificate "GeoTrust Universal CA"
    # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
    # Certificate "GLOBALTRUST 2015"
    # Certificate "emSign Root CA - G2"
    # Certificate "emSign Root CA - C2"
   Adding:
    # Certificate "GLOBALTRUST 2020"
    # Certificate "ANF Secure Server Root CA"
2021-06-16 13:32:35 -07:00
Bob Relyea
c4c1a32e95 Add code to pull in object signing certs from Common CA Database (ccadb.org).
Fix the updated merge scripts to handle this.
Prune Expired certificates from certdata.txt and the object signing cert list

Update to CKBI 2.48 from NSS 3.64

   Removing:
    # Certificate "Verisign Class 3 Public Primary Certification Authority - G3"
    # Certificate "GeoTrust Universal CA 2"
    # Certificate "QuoVadis Root CA"
    # Certificate "Sonera Class 2 Root CA"
    # Certificate "Taiwan GRCA"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
    # Certificate "EE Certification Centre Root CA"
    # Certificate "LuxTrust Global Root 2"
    # Certificate "Symantec Class 1 Public Primary Certification Authority - G4"
    # Certificate "Symantec Class 2 Public Primary Certification Authority - G4"
   Adding:
    # Certificate "Microsoft ECC Root Certificate Authority 2017"
    # Certificate "Microsoft RSA Root Certificate Authority 2017"
    # Certificate "e-Szigno Root CA 2017"
    # Certificate "certSIGN Root CA G2"
    # Certificate "Trustwave Global Certification Authority"
    # Certificate "Trustwave Global ECC P256 Certification Authority"
    # Certificate "Trustwave Global ECC P384 Certification Authority"
    # Certificate "NAVER Global Root Certification Authority"
    # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
    # Certificate "GlobalSign Secure Mail Root R45"
    # Certificate "GlobalSign Secure Mail Root E45"
    # Certificate "GlobalSign Root R46"
    # Certificate "GlobalSign Root E46"
    # Certificate "Certum EC-384 CA"
    # Certificate "Certum Trusted Root CA"
    # Certificate "GlobalSign Code Signing Root R45"
    # Certificate "GlobalSign Code Signing Root E45"
    # Certificate "Halcom Root Certificate Authority"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
    # Certificate "GLOBALTRUST"
    # Certificate "MULTICERT Root Certification Authority 01"
    # Certificate "Verizon Global Root CA"
    # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
    # Certificate "CAEDICOM Root"
    # Certificate "COMODO Certification Authority"
    # Certificate "Security Communication ECC RootCA1"
    # Certificate "Security Communication RootCA3"
    # Certificate "AC RAIZ DNIE"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G3"
    # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
    # Certificate "GLOBALTRUST 2015"
    # Certificate "emSign Root CA - G2"
    # Certificate "emSign Root CA - C2"
2021-05-25 16:48:57 -07:00
Bob Relyea
9a68b05c60 Update to CKBI 2.41 from NSS 3.53.0
Removing:
    # Certificate "AddTrust Low-Value Services Root"
    # Certificate "AddTrust External Root"
    # Certificate "Staat der Nederlanden Root CA - G2"

-Updates several certificates with CKA_SERVER_DISTRUST_AFTER with a data
-Fix circular dependency issue by moving ca-legacy and upcate-ca-trust to
 %posttrans
2020-06-10 12:45:49 -07:00
Daiki Ueno
eaf3ef8b6b Update to CKBI 2.40 from NSS 3.48 2020-01-22 10:56:12 +01:00
Bob Relyea
605570b71e Resolves: rhbz#1722213
- Update to CKBI 2.32 from NSS 3.44
   Removing:
    # Certificate "Visa eCommerce Root"
    # Certificate "AC Raiz Certicamara S.A."
    # Certificate "Certplus Root CA G1"
    # Certificate "Certplus Root CA G2"
    # Certificate "OpenTrust Root CA G1"
    # Certificate "OpenTrust Root CA G2"
    # Certificate "OpenTrust Root CA G3"
   Adding:
    # Certificate "GTS Root R1"
    # Certificate "GTS Root R2"
    # Certificate "GTS Root R3"
    # Certificate "GTS Root R4"
    # Certificate "UCA Global G2 Root"
    # Certificate "UCA Extended Validation Root"
    # Certificate "Certigna Root CA"
    # Certificate "emSign Root CA - G1"
    # Certificate "emSign ECC Root CA - G3"
    # Certificate "emSign Root CA - C1"
    # Certificate "emSign ECC Root CA - C3"
    # Certificate "Hongkong Post Root CA 3"
2019-06-19 10:17:16 -07:00
Robert Relyea
439a513c7a Update ca-certficates to 2.26 from NSS 3.39 2018-09-24 17:18:53 -07:00
Kai Engert
342574ec95 Update to CKBI 2.24 from NSS 3.37 2018-05-18 13:05:43 +02:00
Kai Engert
a77bc273de Update to CKBI 2.22 from NSS 3.35 2018-02-06 14:42:09 +01:00
Kai Engert
e3a2f67722 Update to CKBI 2.20 from NSS 3.34.1 2017-11-27 21:37:37 +01:00
Kai Engert
7accaab619 Update to (yet unreleased) CKBI 2.16 which is planned for NSS 3.32. Mozilla removed all trust bits for code signing. 2017-07-19 11:40:38 +02:00
Kai Engert
6cea01c4b1 Update to CKBI 2.14 from NSS 3.30.2 2017-04-26 14:37:22 +02:00
Kai Engert
1926916bb3 Update to CKBI 2.11 from NSS 3.28.1 2017-01-11 14:16:31 +01:00
Kai Engert
00af3f958b Update to CKBI 2.10 from NSS 3.27 2016-10-04 19:54:47 +02:00
Kai Engert
552fa4a6d3 Revert to the unmodified upstream CA list, changing the legacy trust to an empty list. Keeping the ca-legacy tool and existing config, however, the configuration has no effect after this change. 2016-08-18 14:11:51 +02:00
Kai Engert
02204a071d Update to CKBI 2.9 from NSS 3.26 with legacy modifications 2016-08-16 18:51:35 +02:00
Kai Engert
54fae46d1e Update to CKBI 2.8 from NSS 3.25 with legacy modifications 2016-07-15 13:44:08 +02:00
Kai Engert
53674928a5 Update to CKBI 2.7 from NSS 3.23 with legacy modifications 2016-03-16 18:25:23 +01:00
Kai Engert
da979a1a44 Update to CKBI 2.6 from NSS 3.21 with legacy modifications 2015-11-23 17:51:07 +01:00
Kai Engert
6df1740e0f Update to CKBI 2.5 from NSS 3.19.3 with legacy modifications
This update adjusts the diff-from-upstream patch (which is a patch purely provided for documentation purposes).
It shows a modification that was made as part of the 2.4 update (which in fact removed legacy treatment for one certificate, because upstream had reverted it to an earlier trusted state, as documented on the package wiki page).
No changes to the legacy treatment were made in this 2.5 update.
2015-08-13 22:43:25 +02:00
Kai Engert
b2076a019e Update to CKBI 2.4 from NSS 3.18.1 with legacy modifications 2015-05-05 20:18:08 +02:00
Kai Engert
b18dd49764 Update to CKBI 2.3 from NSS 3.18 with legacy modifications 2015-03-20 22:12:01 +01:00
Kai Engert
b1d00ef388 Fix mistakes in the legacy handling of the upstream 2.1 and 2.2 releases 2015-03-20 21:23:05 +01:00
Kai Engert
053dde8a2f - Update to CKBI 2.2 from NSS 3.17.3 with legacy modifications 2014-12-16 22:09:03 +01:00
Kai Engert
e24bfeb6b0 - Introduce the ca-legacy utility and a ca-legacy.conf configuration file.
By default, legacy roots required for OpenSSL/GnuTLS compatibility
  are kept enabled. Using the ca-legacy utility, the legacy roots can be
  disabled. If disabled, the system will use the trust set as provided
  by the upstream Mozilla CA list. (See also: rhbz#1158197)
2014-10-28 20:54:15 +01:00
Kai Engert
f81c301d27 - Temporarily re-enable several legacy root CA certificates because of
compatibility issues with software based on OpenSSL/GnuTLS,
  see rhbz#1144808
2014-09-21 10:33:16 +02:00
Kai Engert
18eedda612 - Update to CKBI 2.1 from NSS 3.16.4
- Fix rhbz#1130226
2014-08-14 17:06:04 +02:00
Kai Engert
f176bca921 Update to CKBI 1.97 from NSS 3.16 2014-03-19 11:30:07 +01:00
Kai Engert
5df4185c4d * Thu Jan 09 2014 Kai Engert <kaie@redhat.com> - 2013.1.96-1
- Update to CKBI 1.96 from NSS 3.15.4
2014-01-09 17:38:04 +01:00
Kai Engert
9a4d41a78e * Tue Dec 17 2013 Kai Engert <kaie@redhat.com> - 2013.1.95-1
- Update to CKBI 1.95 from NSS 3.15.3.1
2013-12-17 18:51:16 +01:00
Kai Engert
2dc4526741 - update to version 1.94 provided by NSS 3.15 (beta) 2013-05-27 14:57:04 +02:00
Paul Wouters
73800e131b * Fri Jan 04 2013 Paul Wouters <pwouters@redhat.com> - 2012.87-1
- Updated to r1.87 to blacklist mis-issued turktrust CA certs
2013-01-04 12:50:54 -05:00
Paul Wouters
b65d8a87f1 * Tue Oct 23 2012 Paul Wouters <pwouters@redhat.com> - 2012.86-1
- update to r1.86
2012-10-23 16:04:09 -04:00
Joe Orton
df639e3f3e update to r1.85 2012-07-23 11:50:51 +01:00
Joe Orton
229976ab38 update to r1.81 2012-02-13 10:20:14 +00:00
Joe Orton
596824452e update to r1.80
fix handling of certs with dublicate Subject names (#733032)
2011-11-09 14:36:15 -08:00
Joe Orton
f098063f3d update to r1.78, removing trust from DigiNotar root (#734679) 2011-09-01 14:36:45 +01:00
Joe Orton
fbef64556c update to r1.75 2011-08-03 11:40:12 +01:00
Joe Orton
37d25f7154 update to r1.74 2011-04-20 10:12:55 +01:00
Joe Orton
bf4a1f1789 - update to r1.70 2011-01-12 13:51:15 +00:00
Joe Orton
96465e81bb - update to r1.65 2010-11-09 08:24:29 +00:00
jorton
b62ba6e474 - update to certdata.txt r1.63
- use upstream RCS version in Version
2010-04-07 09:40:17 +00:00