Commit Graph

33 Commits

Author SHA1 Message Date
Frantisek Krenzelok
e42c2ba50a update-ca-trust: return warnings on a unsupported argument
Resolves: RHEL-54695

update-ca-trust: return warnings on a unsupported argument instead of
error
2024-08-19 15:19:23 +02:00
Frantisek Krenzelok
6c33b26707 Remove a file left behind from debuging
Related: RHEL-21094

This happens on a build system and won't affect the build process nor
the target system
2024-08-19 12:03:20 +02:00
Frantisek Krenzelok
e360c102c0 Track the directory-hash files
Related: RHEL-21094

- Temporarily generate the directory-hash files in %%install ...(next
  item)
- Add list of ghost files from directory-hash to %%files

- Fix typos in the previous changelog
2024-08-08 09:01:57 +02:00
Daiki Ueno
aecb3a3963 Populate directory-hash at %install
This generates the contents of
/etc/pki/ca-trust/extracted/pem/directory-hash at %install, only
taking into account of the generated bundle, not the one already
present on the build system.  This is done by creating a temporary
module configuration file for p11-kit-trust.so.

Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-08-07 14:40:28 +09:00
Frantisek Krenzelok
25db5ea4c1 Remove write permition from directory-hash
Related: RHEL-21094
2024-07-29 13:22:32 +02:00
Frantisek Krenzelok
093d5d9c5e Fix release number and changelog
Related: RHEL-21094
2024-07-29 12:08:11 +02:00
Frantisek Krenzelok
de8dc38885 Reduce dependency on p11-kit to only the trust subpackage
Related: RHEL-21094

Fedora MR: https://src.fedoraproject.org/rpms/ca-certificates/pull-request/9#
2024-07-26 10:11:25 +02:00
Frantisek Krenzelok
f7a6932798 Own the Directory-hash directory
Resolves: RHEL-21094
2024-07-26 10:11:19 +02:00
Frantisek Krenzelok
b0b4373888 Fix release number
Resolves: RHEL-44988
2024-07-15 15:51:06 +02:00
Frantisek Krenzelok
645309b26d Update to CKBI 2.69_v8.0.302 from NSS 3.101
Resolves: RHEL-44988
2024-07-11 09:33:06 +02:00
Frantisek Krenzelok
94fa011408 Update to CKBI 2.68_v8.0.302 from NSS 3.101
Resolves: RHEL-44988

   Removing:
    # Certificate "Verisign Class 1 Public Primary Certification Authority - G3"
    # Certificate "Verisign Class 2 Public Primary Certification Authority - G3"
    # Certificate "Security Communication Root CA"
    # Certificate "Camerfirma Chambers of Commerce Root"
    # Certificate "Hongkong Post Root CA 1"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "Symantec Class 1 Public Primary Certification Authority - G6"
    # Certificate "Symantec Class 2 Public Primary Certification Authority - G6"
    # Certificate "TrustCor RootCert CA-1"
    # Certificate "TrustCor RootCert CA-2"
    # Certificate "TrustCor ECA-1"
    # Certificate "FNMT-RCM"
   Adding:
    # Certificate "LAWtrust Root CA2 (4096)"
    # Certificate "Sectigo Public Email Protection Root E46"
    # Certificate "Sectigo Public Email Protection Root R46"
    # Certificate "Sectigo Public Server Authentication Root E46"
    # Certificate "Sectigo Public Server Authentication Root R46"
    # Certificate "SSL.com TLS RSA Root CA 2022"
    # Certificate "SSL.com TLS ECC Root CA 2022"
    # Certificate "SSL.com Client ECC Root CA 2022"
    # Certificate "SSL.com Client RSA Root CA 2022"
    # Certificate "Atos TrustedRoot Root CA ECC G2 2020"
    # Certificate "Atos TrustedRoot Root CA RSA G2 2020"
    # Certificate "Atos TrustedRoot Root CA ECC TLS 2021"
    # Certificate "Atos TrustedRoot Root CA RSA TLS 2021"
    # Certificate "TrustAsia Global Root CA G3"
    # Certificate "TrustAsia Global Root CA G4"
    # Certificate "CommScope Public Trust ECC Root-01"
    # Certificate "CommScope Public Trust ECC Root-02"
    # Certificate "CommScope Public Trust RSA Root-01"
    # Certificate "CommScope Public Trust RSA Root-02"
    # Certificate "D-Trust SBR Root CA 1 2022"
    # Certificate "D-Trust SBR Root CA 2 2022"
    # Certificate "Telekom Security SMIME ECC Root 2021"
    # Certificate "Telekom Security TLS ECC Root 2020"
    # Certificate "Telekom Security SMIME RSA Root 2023"
    # Certificate "Telekom Security TLS RSA Root 2023"
    # Certificate "FIRMAPROFESIONAL CA ROOT-A WEB"
    # Certificate "SECOM Trust.net"
    # Certificate "Chambers of Commerce Root"
    # Certificate "VeriSign Class 2 Public Primary Certification Authority - G3"
    # Certificate "SSL.com Code Signing RSA Root CA 2022"
    # Certificate "SSL.com Code Signing ECC Root CA 2022"
2024-06-28 17:34:01 +02:00
Robert Relyea
2604405935 update-ca-trust: Fix bug in update-ca-trust so we don't depened on util-unix
Related: RHEL-44988
original issue - FC-993
2024-06-28 17:34:01 +02:00
Adam Williamson
318794a69b Skip %post if getopt is missing
Related: RHEL-44988
2024-06-28 17:33:53 +02:00
Frantisek Krenzelok
81a090f89a update-ca-trust: Support --output and non-root operation
Related: RHEL-44988

original issue - FC-986

Add the --output option to update-ca-trust so that trust stores can be
written to a different output directory. This is useful to prepare trust
store directories that can be used in containers.

Additionally, fix running update-ca-trust as non-root user
(specifically, without CAP_DAC_OVERRIDE) which was previously required
to create two symbolic links.

Quote all uses of $DEST since a user-specified path could contain
spaces.
2024-06-28 17:33:51 +02:00
Robert Relyea
65fa7105d4 update License: field to SPDX
Related: RHEL-44988
2024-06-28 17:33:38 +02:00
Yaakov Selkowitz
58fa46c055 Adapt to asciidoc 10 changes
Related: RHEL-44988

asciidoc 10 includes a number of packaging changes, including the
removal of asciidoc.py aliases and the relocation of resources.
Instead of trying to manage the latter in a compatible way, use
xmlto instead for the xml-to-man conversion.
2024-06-28 17:33:05 +02:00
Robert Relyea
afc58c4ff8 Resolves: rhbz#2229003
Bump release number so we can clear gating
2023-08-29 09:42:32 -07:00
Robert Relyea
d4677a6ecf Fix gating indent 2023-08-29 09:27:30 -07:00
Robert Relyea
1147359a30 Resolves: rhbz#2229003
Update to CKBI 2.60_v7.0.306 from NSS 3.91
   Removing:
    # Certificate "Camerfirma Global Chambersign Root"
    # Certificate "Staat der Nederlanden EV Root CA"
    # Certificate "OpenTrust Root CA G1"
    # Certificate "Swedish Government Root Authority v1"
    # Certificate "DigiNotar Root CA G2"
    # Certificate "Federal Common Policy CA"
    # Certificate "TC TrustCenter Universal CA III"
    # Certificate "CCA India 2007"
    # Certificate "ipsCA Global CA Root"
    # Certificate "ipsCA Main CA Root"
    # Certificate "Macao Post eSignTrust Root Certification Authority"
    # Certificate "InfoNotary CSP Root"
    # Certificate "DigiNotar Root CA"
    # Certificate "Root CA"
    # Certificate "GPKIRootCA"
    # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
    # Certificate "TC TrustCenter Universal CA I"
    # Certificate "TC TrustCenter Universal CA II"
    # Certificate "TC TrustCenter Class 2 CA II"
    # Certificate "TC TrustCenter Class 4 CA II"
    # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "CertRSA01"
    # Certificate "KISA RootCA 3"
    # Certificate "A-CERT ADVANCED"
    # Certificate "A-Trust-Qual-01"
    # Certificate "A-Trust-nQual-01"
    # Certificate "Serasa Certificate Authority II"
    # Certificate "TDC Internet"
    # Certificate "America Online Root Certification Authority 2"
    # Certificate "RSA Security Inc"
    # Certificate "Public Notary Root"
    # Certificate "Autoridade Certificadora Raiz Brasileira"
    # Certificate "Post.Trust Root CA"
    # Certificate "Entrust.net Secure Server Certification Authority"
    # Certificate "ePKI EV SSL Certification Authority - G1"
   Adding:
    # Certificate "DigiCert TLS ECC P384 Root G5"
    # Certificate "DigiCert TLS RSA4096 Root G5"
    # Certificate "DigiCert SMIME ECC P384 Root G5"
    # Certificate "DigiCert SMIME RSA4096 Root G5"
    # Certificate "Certainly Root R1"
    # Certificate "Certainly Root E1"
    # Certificate "E-Tugra Global Root CA RSA v3"
    # Certificate "E-Tugra Global Root CA ECC v3"
    # Certificate "DIGITALSIGN GLOBAL ROOT RSA CA"
    # Certificate "DIGITALSIGN GLOBAL ROOT ECDSA CA"
    # Certificate "BJCA Global Root CA1"
    # Certificate "BJCA Global Root CA2"
    # Certificate "Symantec Enterprise Mobile Root for Microsoft"
    # Certificate "A-Trust-Root-05"
    # Certificate "ADOCA02"
    # Certificate "StartCom Certification Authority G2"
    # Certificate "ATHEX Root CA"
    # Certificate "EBG Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "GeoTrust Primary Certification Authority"
    # Certificate "thawte Primary Root CA"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5"
    # Certificate "America Online Root Certification Authority 1"
    # Certificate "Juur-SK"
    # Certificate "ComSign CA"
    # Certificate "ComSign Secured CA"
    # Certificate "ComSign Advanced Security CA"
    # Certificate "Global Chambersign Root"
    # Certificate "Sonera Class2 CA"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G3"
    # Certificate "VeriSign, Inc."
    # Certificate "GTE CyberTrust Global Root"
    # Certificate "Equifax Secure Global eBusiness CA-1"
    # Certificate "Equifax"
    # Certificate "Class 1 Primary CA"
    # Certificate "Swiss Government Root CA III"
    # Certificate "Application CA G4 Root"
    # Certificate "SSC GDL CA Root A"
    # Certificate "GlobalSign Code Signing Root E45"
    # Certificate "GlobalSign Code Signing Root R45"
    # Certificate "Entrust Code Signing Root Certification Authority - CSBR1"
2023-08-21 14:32:43 -07:00
Bob Relyea
4318c9f437 Resolves: rhbz#2099898
Add Object Signing certificates
Update to CKBI 2.54 from NSS 3.79
       Removing:
        # Certificate "GlobalSign Root CA - R2"
        # Certificate "DST Root CA X3"
        # Certificate "Explicitly Distrusted DigiNotar PKIoverheid G2"
       Adding:
        # Certificate "TunTrust Root CA"
        # Certificate "HARICA TLS RSA Root CA 2021"
        # Certificate "HARICA TLS ECC Root CA 2021"
        # Certificate "HARICA Client RSA Root CA 2021"
        # Certificate "HARICA Client ECC Root CA 2021"
        # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
        # Certificate "vTrus ECC Root CA"
        # Certificate "vTrus Root CA"
        # Certificate "ISRG Root X2"
        # Certificate "HiPKI Root CA - G1"
        # Certificate "Telia Root CA v2"
        # Certificate "D-TRUST BR Root CA 1 2020"
        # Certificate "D-TRUST EV Root CA 1 2020"
        # Certificate "CAEDICOM Root"
        # Certificate "I.CA Root CA/RSA"
        # Certificate "MULTICERT Root Certification Authority 01"
        # Certificate "Certification Authority of WoSign G2"
        # Certificate "CA WoSign ECC Root"
        # Certificate "CCA India 2015 SPL"
        # Certificate "Swedish Government Root Authority v3"
        # Certificate "Swedish Government Root Authority v2"
        # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
        # Certificate "OpenTrust Root CA G1"
        # Certificate "OpenTrust Root CA G2"
        # Certificate "OpenTrust Root CA G3"
        # Certificate "Certplus Root CA G1"
        # Certificate "Certplus Root CA G2"
        # Certificate "Government Root Certification Authority"
        # Certificate "A-Trust-Qual-02"
        # Certificate "Thailand National Root Certification Authority - G1"
        # Certificate "TrustCor ECA-1"
        # Certificate "TrustCor RootCert CA-2"
        # Certificate "TrustCor RootCert CA-1"
        # Certificate "Certification Authority of WoSign"
        # Certificate "CA 沃通根证书"
        # Certificate "SSC GDL CA Root B"
        # Certificate "SAPO Class 2 Root CA"
        # Certificate "SAPO Class 3 Root CA"
        # Certificate "SAPO Class 4 Root CA"
        # Certificate "CA Disig Root R1"
        # Certificate "Autoridad Certificadora Raíz Nacional de Uruguay"
        # Certificate "ApplicationCA2 Root"
        # Certificate "GlobalSign"
        # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
        # Certificate "Symantec Class 3 Public Primary Certification Authority - G4"
        # Certificate "Halcom Root CA"
        # Certificate "Swisscom Root EV CA 2"
        # Certificate "CFCA GT CA"
        # Certificate "Digidentity L3 Root CA - G2"
        # Certificate "SITHS Root CA v1"
        # Certificate "Macao Post eSignTrust Root Certification Authority (G02)"
        # Certificate "Autoridade Certificadora Raiz Brasileira v2"
        # Certificate "Swisscom Root CA 2"
        # Certificate "IGC/A AC racine Etat francais"
        # Certificate "PersonalID Trustworthy RootCA 2011"
        # Certificate "Swedish Government Root Authority v1"
        # Certificate "Swiss Government Root CA II"
        # Certificate "Swiss Government Root CA I"
        # Certificate "Network Solutions Certificate Authority"
        # Certificate "COMODO Certification Authority"
        # Certificate "LuxTrust Global Root"
        # Certificate "AC1 RAIZ MTIN"
        # Certificate "Microsoft Root Certificate Authority 2011"
        # Certificate "CCA India 2011"
        # Certificate "ANCERT Certificados Notariales V2"
        # Certificate "ANCERT Certificados CGN V2"
        # Certificate "EE Certification Centre Root CA"
        # Certificate "DigiNotar Root CA G2"
        # Certificate "Federal Common Policy CA"
        # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
        # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
        # Certificate "China Internet Network Information Center EV Certificates Root"
        # Certificate "Verizon Global Root CA"
        # Certificate "SwissSign Silver Root CA - G3"
        # Certificate "SwissSign Platinum Root CA - G3"
        # Certificate "SwissSign Gold Root CA - G3"
        # Certificate "Microsec e-Szigno Root CA 2009"
        # Certificate "SITHS CA v3"
        # Certificate "Certinomis - Autorité Racine"
        # Certificate "ANF Server CA"
        # Certificate "Thawte Premium Server CA"
        # Certificate "Thawte Server CA"
        # Certificate "TC TrustCenter Universal CA III"
        # Certificate "KEYNECTIS ROOT CA"
        # Certificate "I.CA - Standard Certification Authority, 09/2009"
        # Certificate "I.CA - Qualified Certification Authority, 09/2009"
        # Certificate "VI Registru Centras RCSC (RootCA)"
        # Certificate "CCA India 2007"
        # Certificate "Autoridade Certificadora Raiz Brasileira v1"
        # Certificate "ipsCA Global CA Root"
        # Certificate "ipsCA Main CA Root"
        # Certificate "Actalis Authentication CA G1"
        # Certificate "A-Trust-Qual-03"
        # Certificate "AddTrust External CA Root"
        # Certificate "ECRaizEstado"
        # Certificate "Configuration"
        # Certificate "FNMT-RCM"
        # Certificate "StartCom Certification Authority"
        # Certificate "TWCA Root Certification Authority"
        # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
        # Certificate "thawte Primary Root CA - G2"
        # Certificate "GeoTrust Primary Certification Authority - G2"
        # Certificate "VeriSign Universal Root Certification Authority"
        # Certificate "thawte Primary Root CA - G3"
        # Certificate "GeoTrust Primary Certification Authority - G3"
        # Certificate "E-ME SSI (RCA)"
        # Certificate "ACEDICOM Root"
        # Certificate "Autoridad Certificadora Raiz de la Secretaria de Economia"
        # Certificate "Correo Uruguayo - Root CA"
        # Certificate "CNNIC ROOT"
        # Certificate "Common Policy"
        # Certificate "Macao Post eSignTrust Root Certification Authority"
        # Certificate "Staat der Nederlanden Root CA - G2"
        # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
        # Certificate "AC Raíz Certicámara S.A."
        # Certificate "Cisco Root CA 2048"
        # Certificate "CA Disig"
        # Certificate "InfoNotary CSP Root"
        # Certificate "UCA Global Root"
        # Certificate "UCA Root"
        # Certificate "DigiNotar Root CA"
        # Certificate "Starfield Services Root Certificate Authority"
        # Certificate "I.CA - Qualified root certificate"
        # Certificate "I.CA - Standard root certificate"
        # Certificate "e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
        # Certificate "Japanese Government"
        # Certificate "AdminCA-CD-T01"
        # Certificate "Admin-Root-CA"
        # Certificate "Izenpe.com"
        # Certificate "TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3"
        # Certificate "Halcom CA FO"
        # Certificate "Halcom CA PO 2"
        # Certificate "Root CA"
        # Certificate "GPKIRootCA"
        # Certificate "ACNLB"
        # Certificate "state-institutions"
        # Certificate "state-institutions"
        # Certificate "SECOM Trust Systems CO.,LTD."
        # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
        # Certificate "D-TRUST Root Class 2 CA 2007"
        # Certificate "D-TRUST Root Class 3 CA 2007"
        # Certificate "SSC Root CA A"
        # Certificate "SSC Root CA B"
        # Certificate "SSC Root CA C"
        # Certificate "Autoridad de Certificacion de la Abogacia"
        # Certificate "Root CA Generalitat Valenciana"
        # Certificate "VAS Latvijas Pasts SSI(RCA)"
        # Certificate "ANCERT Certificados CGN"
        # Certificate "ANCERT Certificados Notariales"
        # Certificate "ANCERT Corporaciones de Derecho Publico"
        # Certificate "GLOBALTRUST"
        # Certificate "Certipost E-Trust TOP Root CA"
        # Certificate "Certipost E-Trust Primary Qualified CA"
        # Certificate "Certipost E-Trust Primary Normalised CA"
        # Certificate "GlobalSign"
        # Certificate "IGC/A"
        # Certificate "S-TRUST Authentication and Encryption Root CA 2005:PN"
        # Certificate "TC TrustCenter Universal CA I"
        # Certificate "TC TrustCenter Universal CA II"
        # Certificate "TC TrustCenter Class 2 CA II"
        # Certificate "TC TrustCenter Class 4 CA II"
        # Certificate "Swisscom Root CA 1"
        # Certificate "Microsec e-Szigno Root CA"
        # Certificate "LGPKI"
        # Certificate "AC RAIZ DNIE"
        # Certificate "Common Policy"
        # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
        # Certificate "A-Trust-nQual-03"
        # Certificate "A-Trust-nQual-03"
        # Certificate "CertRSA01"
        # Certificate "KISA RootCA 1"
        # Certificate "KISA RootCA 3"
        # Certificate "NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado"
        # Certificate "A-CERT ADVANCED"
        # Certificate "A-Trust-Qual-01"
        # Certificate "A-Trust-nQual-01"
        # Certificate "A-Trust-Qual-02"
        # Certificate "Staat der Nederlanden Root CA"
        # Certificate "Serasa Certificate Authority II"
        # Certificate "TDC Internet"
        # Certificate "America Online Root Certification Authority 2"
        # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
        # Certificate "Government Root Certification Authority"
        # Certificate "RSA Security Inc"
        # Certificate "Public Notary Root"
        # Certificate "GeoTrust Global CA"
        # Certificate "GeoTrust Global CA 2"
        # Certificate "GeoTrust Universal CA"
        # Certificate "GeoTrust Universal CA 2"
        # Certificate "QuoVadis Root Certification Authority"
        # Certificate "Autoridade Certificadora Raiz Brasileira"
        # Certificate "Post.Trust Root CA"
        # Certificate "Microsoft Root Authority"
        # Certificate "Microsoft Root Certificate Authority"
        # Certificate "Microsoft Root Certificate Authority 2010"
        # Certificate "Entrust.net Secure Server Certification Authority"
        # Certificate "UTN-USERFirst-Object"
        # Certificate "BYTE Root Certification Authority 001"
        # Certificate "CISRCA1"
        # Certificate "ePKI Root Certification Authority - G2"
        # Certificate "ePKI EV SSL Certification Authority - G1"
        # Certificate "AC Raíz Certicámara S.A."
        # Certificate "SSL.com EV Root Certification Authority RSA"
        # Certificate "LuxTrust Global Root 2"
        # Certificate "ACA ROOT"
        # Certificate "Security Communication ECC RootCA1"
        # Certificate "Security Communication RootCA3"
        # Certificate "CHAMBERS OF COMMERCE ROOT - 2016"
        # Certificate "Network Solutions RSA Certificate Authority"
        # Certificate "Network Solutions ECC Certificate Authority"
        # Certificate "Australian Defence Public Root CA"
        # Certificate "SI-TRUST Root"
        # Certificate "Halcom Root Certificate Authority"
        # Certificate "Application CA G3 Root"
        # Certificate "GLOBALTRUST 2015"
        # Certificate "Microsoft ECC Product Root Certificate Authority 2018"
        # Certificate "emSign Root CA - G2"
        # Certificate "emSign Root CA - C2"
        # Certificate "Microsoft ECC TS Root Certificate Authority 2018"
        # Certificate "DigiCert CS ECC P384 Root G5"
        # Certificate "DigiCert CS RSA4096 Root G5"
        # Certificate "DigiCert RSA4096 Root G5"
        # Certificate "DigiCert ECC P384 Root G5"
        # Certificate "HARICA Code Signing RSA Root CA 2021"
        # Certificate "HARICA Code Signing ECC Root CA 2021"
        # Certificate "Microsoft Identity Verification Root Certificate Authority 2020"
2022-08-25 09:35:32 -07:00
Bob Relyea
3780497d60 Resolves: rhbz#2099898
Update to CKBI 2.54 from NSS 3.79
   Removing:
    # Certificate "GlobalSign Root CA - R2"
    # Certificate "DST Root CA X3"
    # Certificate "Explicitly Distrusted DigiNotar PKIoverheid G2"
   Adding:
    # Certificate "TunTrust Root CA"
    # Certificate "HARICA TLS RSA Root CA 2021"
    # Certificate "HARICA TLS ECC Root CA 2021"
    # Certificate "HARICA Client RSA Root CA 2021"
    # Certificate "HARICA Client ECC Root CA 2021"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "vTrus ECC Root CA"
    # Certificate "vTrus Root CA"
    # Certificate "ISRG Root X2"
    # Certificate "HiPKI Root CA - G1"
    # Certificate "Telia Root CA v2"
    # Certificate "D-TRUST BR Root CA 1 2020"
    # Certificate "D-TRUST EV Root CA 1 2020"
    # Certificate "CAEDICOM Root"
    # Certificate "I.CA Root CA/RSA"
    # Certificate "MULTICERT Root Certification Authority 01"
    # Certificate "Certification Authority of WoSign G2"
    # Certificate "CA WoSign ECC Root"
    # Certificate "CCA India 2015 SPL"
    # Certificate "Swedish Government Root Authority v3"
    # Certificate "Swedish Government Root Authority v2"
    # Certificate "Tunisian Root Certificate Authority - TunRootCA2"
    # Certificate "OpenTrust Root CA G1"
    # Certificate "OpenTrust Root CA G2"
    # Certificate "OpenTrust Root CA G3"
    # Certificate "Certplus Root CA G1"
    # Certificate "Certplus Root CA G2"
    # Certificate "Government Root Certification Authority"
    # Certificate "A-Trust-Qual-02"
    # Certificate "Thailand National Root Certification Authority - G1"
    # Certificate "TrustCor ECA-1"
    # Certificate "TrustCor RootCert CA-2"
    # Certificate "TrustCor RootCert CA-1"
    # Certificate "Certification Authority of WoSign"
    # Certificate "CA 沃通根证书"
    # Certificate "SSC GDL CA Root B"
    # Certificate "SAPO Class 2 Root CA"
    # Certificate "SAPO Class 3 Root CA"
    # Certificate "SAPO Class 4 Root CA"
    # Certificate "CA Disig Root R1"
    # Certificate "Autoridad Certificadora Raíz Nacional de Uruguay"
    # Certificate "ApplicationCA2 Root"
    # Certificate "GlobalSign"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G6"
    # Certificate "Symantec Class 3 Public Primary Certification Authority - G4"
    # Certificate "Halcom Root CA"
    # Certificate "Swisscom Root EV CA 2"
    # Certificate "CFCA GT CA"
    # Certificate "Digidentity L3 Root CA - G2"
    # Certificate "SITHS Root CA v1"
    # Certificate "Macao Post eSignTrust Root Certification Authority (G02)"
    # Certificate "Autoridade Certificadora Raiz Brasileira v2"
    # Certificate "Swisscom Root CA 2"
    # Certificate "IGC/A AC racine Etat francais"
    # Certificate "PersonalID Trustworthy RootCA 2011"
    # Certificate "Swedish Government Root Authority v1"
    # Certificate "Swiss Government Root CA II"
    # Certificate "Swiss Government Root CA I"
    # Certificate "Network Solutions Certificate Authority"
    # Certificate "COMODO Certification Authority"
    # Certificate "LuxTrust Global Root"
    # Certificate "AC1 RAIZ MTIN"
    # Certificate "Microsoft Root Certificate Authority 2011"
    # Certificate "CCA India 2011"
    # Certificate "ANCERT Certificados Notariales V2"
    # Certificate "ANCERT Certificados CGN V2"
    # Certificate "EE Certification Centre Root CA"
    # Certificate "DigiNotar Root CA G2"
    # Certificate "Federal Common Policy CA"
    # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
    # Certificate "Autoridad de Certificacion Raiz del Estado Venezolano"
    # Certificate "China Internet Network Information Center EV Certificates Root"
    # Certificate "Verizon Global Root CA"
    # Certificate "SwissSign Silver Root CA - G3"
    # Certificate "SwissSign Platinum Root CA - G3"
    # Certificate "SwissSign Gold Root CA - G3"
    # Certificate "Microsec e-Szigno Root CA 2009"
    # Certificate "SITHS CA v3"
    # Certificate "Certinomis - Autorité Racine"
    # Certificate "ANF Server CA"
    # Certificate "Thawte Premium Server CA"
    # Certificate "Thawte Server CA"
    # Certificate "TC TrustCenter Universal CA III"
    # Certificate "KEYNECTIS ROOT CA"
    # Certificate "I.CA - Standard Certification Authority, 09/2009"
    # Certificate "I.CA - Qualified Certification Authority, 09/2009"
    # Certificate "VI Registru Centras RCSC (RootCA)"
    # Certificate "CCA India 2007"
    # Certificate "Autoridade Certificadora Raiz Brasileira v1"
    # Certificate "ipsCA Global CA Root"
    # Certificate "ipsCA Main CA Root"
    # Certificate "Actalis Authentication CA G1"
    # Certificate "A-Trust-Qual-03"
    # Certificate "AddTrust External CA Root"
    # Certificate "ECRaizEstado"
    # Certificate "Configuration"
    # Certificate "FNMT-RCM"
    # Certificate "StartCom Certification Authority"
    # Certificate "TWCA Root Certification Authority"
    # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4"
    # Certificate "thawte Primary Root CA - G2"
    # Certificate "GeoTrust Primary Certification Authority - G2"
    # Certificate "VeriSign Universal Root Certification Authority"
    # Certificate "thawte Primary Root CA - G3"
    # Certificate "GeoTrust Primary Certification Authority - G3"
    # Certificate "E-ME SSI (RCA)"
    # Certificate "ACEDICOM Root"
    # Certificate "Autoridad Certificadora Raiz de la Secretaria de Economia"
    # Certificate "Correo Uruguayo - Root CA"
    # Certificate "CNNIC ROOT"
    # Certificate "Common Policy"
    # Certificate "Macao Post eSignTrust Root Certification Authority"
    # Certificate "Staat der Nederlanden Root CA - G2"
    # Certificate "NetLock Platina (Class Platinum) Főtanúsítvány"
    # Certificate "AC Raíz Certicámara S.A."
    # Certificate "Cisco Root CA 2048"
    # Certificate "CA Disig"
    # Certificate "InfoNotary CSP Root"
    # Certificate "UCA Global Root"
    # Certificate "UCA Root"
    # Certificate "DigiNotar Root CA"
    # Certificate "Starfield Services Root Certificate Authority"
    # Certificate "I.CA - Qualified root certificate"
    # Certificate "I.CA - Standard root certificate"
    # Certificate "e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
    # Certificate "Japanese Government"
    # Certificate "AdminCA-CD-T01"
    # Certificate "Admin-Root-CA"
    # Certificate "Izenpe.com"
    # Certificate "TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3"
    # Certificate "Halcom CA FO"
    # Certificate "Halcom CA PO 2"
    # Certificate "Root CA"
    # Certificate "GPKIRootCA"
    # Certificate "ACNLB"
    # Certificate "state-institutions"
    # Certificate "state-institutions"
    # Certificate "SECOM Trust Systems CO.,LTD."
    # Certificate "D-TRUST Qualified Root CA 1 2007:PN"
    # Certificate "D-TRUST Root Class 2 CA 2007"
    # Certificate "D-TRUST Root Class 3 CA 2007"
    # Certificate "SSC Root CA A"
    # Certificate "SSC Root CA B"
    # Certificate "SSC Root CA C"
    # Certificate "Autoridad de Certificacion de la Abogacia"
    # Certificate "Root CA Generalitat Valenciana"
    # Certificate "VAS Latvijas Pasts SSI(RCA)"
    # Certificate "ANCERT Certificados CGN"
    # Certificate "ANCERT Certificados Notariales"
    # Certificate "ANCERT Corporaciones de Derecho Publico"
    # Certificate "GLOBALTRUST"
    # Certificate "Certipost E-Trust TOP Root CA"
    # Certificate "Certipost E-Trust Primary Qualified CA"
    # Certificate "Certipost E-Trust Primary Normalised CA"
    # Certificate "GlobalSign"
    # Certificate "IGC/A"
    # Certificate "S-TRUST Authentication and Encryption Root CA 2005:PN"
    # Certificate "TC TrustCenter Universal CA I"
    # Certificate "TC TrustCenter Universal CA II"
    # Certificate "TC TrustCenter Class 2 CA II"
    # Certificate "TC TrustCenter Class 4 CA II"
    # Certificate "Swisscom Root CA 1"
    # Certificate "Microsec e-Szigno Root CA"
    # Certificate "LGPKI"
    # Certificate "AC RAIZ DNIE"
    # Certificate "Common Policy"
    # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı"
    # Certificate "A-Trust-nQual-03"
    # Certificate "A-Trust-nQual-03"
    # Certificate "CertRSA01"
    # Certificate "KISA RootCA 1"
    # Certificate "KISA RootCA 3"
    # Certificate "NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado"
    # Certificate "A-CERT ADVANCED"
    # Certificate "A-Trust-Qual-01"
    # Certificate "A-Trust-nQual-01"
    # Certificate "A-Trust-Qual-02"
    # Certificate "Staat der Nederlanden Root CA"
    # Certificate "Serasa Certificate Authority II"
    # Certificate "TDC Internet"
    # Certificate "America Online Root Certification Authority 2"
    # Certificate "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    # Certificate "Government Root Certification Authority"
    # Certificate "RSA Security Inc"
    # Certificate "Public Notary Root"
    # Certificate "GeoTrust Global CA"
    # Certificate "GeoTrust Global CA 2"
    # Certificate "GeoTrust Universal CA"
    # Certificate "GeoTrust Universal CA 2"
    # Certificate "QuoVadis Root Certification Authority"
    # Certificate "Autoridade Certificadora Raiz Brasileira"
    # Certificate "Post.Trust Root CA"
    # Certificate "Microsoft Root Authority"
    # Certificate "Microsoft Root Certificate Authority"
    # Certificate "Microsoft Root Certificate Authority 2010"
    # Certificate "Entrust.net Secure Server Certification Authority"
    # Certificate "UTN-USERFirst-Object"
    # Certificate "BYTE Root Certification Authority 001"
    # Certificate "CISRCA1"
    # Certificate "ePKI Root Certification Authority - G2"
    # Certificate "ePKI EV SSL Certification Authority - G1"
    # Certificate "AC Raíz Certicámara S.A."
    # Certificate "SSL.com EV Root Certification Authority RSA"
    # Certificate "LuxTrust Global Root 2"
    # Certificate "ACA ROOT"
    # Certificate "Security Communication ECC RootCA1"
    # Certificate "Security Communication RootCA3"
    # Certificate "CHAMBERS OF COMMERCE ROOT - 2016"
    # Certificate "Network Solutions RSA Certificate Authority"
    # Certificate "Network Solutions ECC Certificate Authority"
    # Certificate "Australian Defence Public Root CA"
    # Certificate "SI-TRUST Root"
    # Certificate "Halcom Root Certificate Authority"
    # Certificate "Application CA G3 Root"
    # Certificate "GLOBALTRUST 2015"
    # Certificate "Microsoft ECC Product Root Certificate Authority 2018"
    # Certificate "emSign Root CA - G2"
    # Certificate "emSign Root CA - C2"
    # Certificate "Microsoft ECC TS Root Certificate Authority 2018"
    # Certificate "DigiCert CS ECC P384 Root G5"
    # Certificate "DigiCert CS RSA4096 Root G5"
    # Certificate "DigiCert RSA4096 Root G5"
    # Certificate "DigiCert ECC P384 Root G5"
    # Certificate "HARICA Code Signing RSA Root CA 2021"
    # Certificate "HARICA Code Signing ECC Root CA 2021"
    # Certificate "Microsoft Identity Verification Root Certificate Authority 2020"
2022-07-19 09:39:07 -07:00
Bob Relyea
ba5317bf16 Turn on manual gating to prevent 9.1 builds from passing gating and releasing 2022-07-18 15:21:15 -07:00
Bob Relyea
09eff8709a Resolves: rhbz#2021362
Remove blacklist directory from release and documentation. Add requires
for the version of p11_kit that uses the blocklist directory.
2021-11-16 08:59:37 -08:00
Mohan Boddu
7ce59a8b26 Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-08-09 19:33:34 +00:00
Stanislav Zidek
b19ede64b0 add gating configuration 2021-07-23 18:44:21 +02:00
Mohan Boddu
293bea7647 Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-06-22 18:36:01 +00:00
Bob Relyea
18c64aec9f Resolves: rhbz#1972921
Update to CKBI 2.50 from NSS 3.67
       Removing:
        # Certificate "QuoVadis Root CA"
        # Certificate "Sonera Class 2 Root CA"
        # Certificate "Trustis FPS Root CA"
       Adding:
        # Certificate "GLOBALTRUST 2020"
        # Certificate "ANF Secure Server Root CA"
        # Certificate "Certum EC-384 CA"
        # Certificate "Certum Trusted Root CA"
2021-06-17 08:05:39 -07:00
Mohan Boddu
6835eac039 - Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-04-15 22:48:37 +00:00
DistroBaker
f5f0f5fd95 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/ca-certificates.git#0fa62ae95f260387a3a91d6c73387b27abbf7163
2021-02-03 11:56:36 +01:00
DistroBaker
a6a84258da Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/ca-certificates.git#05fc0ccfd2bc9d55ffa21f34de17cc6618fb9b16
2021-01-12 22:08:18 +00:00
DistroBaker
8eeccfe166 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/ca-certificates.git#9bd23da27ffac43abfb42ae5c982d2320d6cd8fd
2020-12-10 01:08:56 +01:00
Petr Šabata
cbe6d70855 RHEL 9.0.0 Alpha bootstrap
The content of this branch was automatically imported from Fedora ELN
with the following as its source:
https://src.fedoraproject.org/rpms/ca-certificates#5221e001cb29e491c529e5d5e8c1d26c84f4d9b4
2020-10-14 22:35:13 +02:00
Release Configuration Management
8f161f5cb6 New branch setup 2020-10-08 11:11:01 +00:00