mirror of
https://git.launchpad.net/ubuntu/+source/ca-certificates
synced 2025-09-18 21:39:43 +00:00
20210119 (patches unapplied)
Imported using git-ubuntu import.
This commit is contained in:
parent
bb7135fa45
commit
47275c9bd2
Notes:
git-ubuntu importer
2021-01-19 16:44:41 +00:00
[ Julien Cristau ] * New maintainer (closes: #976406) * mozilla/{certdata.txt,nssckbi.h}: Update Mozilla certificate authority bundle to version 2.46. The following certificate authorities were added (+): + "certSIGN ROOT CA G2" + "e-Szigno Root CA 2017" + "Microsoft ECC Root Certificate Authority 2017" + "Microsoft RSA Root Certificate Authority 2017" + "NAVER Global Root Certification Authority" + "Trustwave Global Certification Authority" + "Trustwave Global ECC P256 Certification Authority" + "Trustwave Global ECC P384 Certification Authority" The following certificate authorities were removed (-): - "EE Certification Centre Root CA" - "GeoTrust Universal CA 2" - "LuxTrust Global Root 2" - "OISTE WISeKey Global Root GA CA" - "Staat der Nederlanden Root CA - G2" (closes: #962079) - "Taiwan GRCA" - "Verisign Class 3 Public Primary Certification Authority - G3" [ Michael Shuler ] * mozilla/blacklist: Revert Symantec CA blacklist (#911289). Closes: #962596 The following root certificates were added back (+): + "GeoTrust Primary Certification Authority - G2" + "VeriSign Universal Root Certification Authority" [ Gianfranco Costamagna ] * debian/{rules,control}: Merge Ubuntu patch from Matthias Klose to use Python3 during build. Closes: #942915
7 changed files with 1254 additions and 3089 deletions
38
debian/changelog
vendored
38
debian/changelog
vendored
|
@ -1,3 +1,41 @@
|
|||
ca-certificates (20210119) unstable; urgency=medium
|
||||
|
||||
[ Julien Cristau ]
|
||||
* New maintainer (closes: #976406)
|
||||
* mozilla/{certdata.txt,nssckbi.h}: Update Mozilla certificate authority
|
||||
bundle to version 2.46.
|
||||
The following certificate authorities were added (+):
|
||||
+ "certSIGN ROOT CA G2"
|
||||
+ "e-Szigno Root CA 2017"
|
||||
+ "Microsoft ECC Root Certificate Authority 2017"
|
||||
+ "Microsoft RSA Root Certificate Authority 2017"
|
||||
+ "NAVER Global Root Certification Authority"
|
||||
+ "Trustwave Global Certification Authority"
|
||||
+ "Trustwave Global ECC P256 Certification Authority"
|
||||
+ "Trustwave Global ECC P384 Certification Authority"
|
||||
The following certificate authorities were removed (-):
|
||||
- "EE Certification Centre Root CA"
|
||||
- "GeoTrust Universal CA 2"
|
||||
- "LuxTrust Global Root 2"
|
||||
- "OISTE WISeKey Global Root GA CA"
|
||||
- "Staat der Nederlanden Root CA - G2" (closes: #962079)
|
||||
- "Taiwan GRCA"
|
||||
- "Verisign Class 3 Public Primary Certification Authority - G3"
|
||||
|
||||
[ Michael Shuler ]
|
||||
* mozilla/blacklist:
|
||||
Revert Symantec CA blacklist (#911289). Closes: #962596
|
||||
The following root certificates were added back (+):
|
||||
+ "GeoTrust Primary Certification Authority - G2"
|
||||
+ "VeriSign Universal Root Certification Authority"
|
||||
|
||||
[ Gianfranco Costamagna ]
|
||||
* debian/{rules,control}:
|
||||
Merge Ubuntu patch from Matthias Klose to use Python3 during build.
|
||||
Closes: #942915
|
||||
|
||||
-- Julien Cristau <jcristau@debian.org> Tue, 19 Jan 2021 11:11:04 +0100
|
||||
|
||||
ca-certificates (20200601) unstable; urgency=medium
|
||||
|
||||
* debian/control:
|
||||
|
|
6
debian/control
vendored
6
debian/control
vendored
|
@ -1,11 +1,9 @@
|
|||
Source: ca-certificates
|
||||
Section: misc
|
||||
Priority: optional
|
||||
Maintainer: Michael Shuler <michael@pbandjelly.org>
|
||||
Uploaders: Raphael Geissert <geissert@debian.org>,
|
||||
Thijs Kinkhorst <thijs@debian.org>
|
||||
Maintainer: Julien Cristau <jcristau@debian.org>
|
||||
Build-Depends: debhelper-compat (= 13), po-debconf
|
||||
Build-Depends-Indep: python, openssl
|
||||
Build-Depends-Indep: python3, openssl
|
||||
Standards-Version: 4.5.0.2
|
||||
Vcs-Git: https://salsa.debian.org/debian/ca-certificates.git
|
||||
Vcs-Browser: https://salsa.debian.org/debian/ca-certificates
|
||||
|
|
|
@ -3,7 +3,7 @@
|
|||
#
|
||||
|
||||
all:
|
||||
python certdata2pem.py
|
||||
python3 certdata2pem.py
|
||||
|
||||
clean:
|
||||
-rm -f *.crt
|
||||
|
|
|
@ -1,39 +1,9 @@
|
|||
# One blacklist entry per line, corresponding to the label in certdata.txt.
|
||||
|
||||
# Blacklist explicitly distrusted certificates to explicitly ignore them and prevent build errors
|
||||
"Distrust: O=Egypt Trust, OU=VeriSign Trust Network (cert 1/3)"
|
||||
"Distrust: O=Egypt Trust, OU=VeriSign Trust Network (cert 2/3)"
|
||||
"Distrust: O=Egypt Trust, OU=VeriSign Trust Network (cert 3/3)"
|
||||
"Explicitly Distrust DigiNotar Root CA"
|
||||
"Explicitly Distrusted DigiNotar PKIoverheid G2"
|
||||
"MITM subCA 1 issued by Trustwave"
|
||||
"MITM subCA 2 issued by Trustwave"
|
||||
"TURKTRUST Mis-issued Intermediate CA 1"
|
||||
"TURKTRUST Mis-issued Intermediate CA 2"
|
||||
|
||||
# Distrusted Symantec Root CAs:
|
||||
"GeoTrust Global CA"
|
||||
"GeoTrust Primary Certification Authority"
|
||||
"GeoTrust Primary Certification Authority - G2"
|
||||
"GeoTrust Primary Certification Authority - G3"
|
||||
"GeoTrust Universal CA"
|
||||
"Thawte Premium Server CA"
|
||||
"thawte Primary Root CA"
|
||||
"thawte Primary Root CA - G2"
|
||||
"thawte Primary Root CA - G3"
|
||||
"Symantec Class 1 Public Primary Certification Authority - G4"
|
||||
"Symantec Class 1 Public Primary Certification Authority - G6"
|
||||
"Symantec Class 2 Public Primary Certification Authority - G4"
|
||||
"Symantec Class 2 Public Primary Certification Authority - G6"
|
||||
"Symantec Class 3 Public Primary Certification Authority - G4"
|
||||
"Symantec Class 3 Public Primary Certification Authority - G6"
|
||||
"VeriSign Class 1 Public Primary Certification Authority - G3"
|
||||
"VeriSign Class 2 Public Primary Certification Authority - G3"
|
||||
"VeriSign Class 3 Public Primary Certification Authority - G3"
|
||||
"VeriSign Class 3 Public Primary Certification Authority - G4"
|
||||
"VeriSign Class 3 Public Primary Certification Authority - G5"
|
||||
"VeriSign Universal Root Certification Authority"
|
||||
|
||||
# Blacklist expired certificate (Not After : May 30 10:48:38 2020 GMT)
|
||||
# See: https://bugs.debian.org/961907
|
||||
"AddTrust External Root"
|
||||
|
|
4261
mozilla/certdata.txt
4261
mozilla/certdata.txt
File diff suppressed because it is too large
Load diff
|
@ -1,4 +1,4 @@
|
|||
#!/usr/bin/python
|
||||
#!/usr/bin/python3
|
||||
# vim:set et sw=4:
|
||||
#
|
||||
# certdata2pem.py - splits certdata.txt into multiple files
|
||||
|
|
|
@ -46,8 +46,8 @@
|
|||
* It's recommend to switch back to 0 after having reached version 98/99.
|
||||
*/
|
||||
#define NSS_BUILTINS_LIBRARY_VERSION_MAJOR 2
|
||||
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 40
|
||||
#define NSS_BUILTINS_LIBRARY_VERSION "2.40"
|
||||
#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 46
|
||||
#define NSS_BUILTINS_LIBRARY_VERSION "2.46"
|
||||
|
||||
/* These version numbers detail the semantic changes to the ckfw engine. */
|
||||
#define NSS_BUILTINS_HARDWARE_VERSION_MAJOR 1
|
||||
|
|
Loading…
Add table
Reference in a new issue