f2d6e7213b
- diff-from-upstream-2.7.patch: restore some important legacy CAs, otherwise Pidgin fails to talk to Google Talk for instance.
Marcus Meissner2016-04-06 14:54:24 +00:00
bc2a7e821f
- diff-from-upstream-2.7.patch: restore some important legacy CAs, otherwise Pidgin fails to talk to Google Talk for instance.
Marcus Meissner2016-04-06 14:54:24 +00:00
be731fb915
- Updated to 2.7. - diff-from-upstream-2.2.patch: removed as openssl 1.0.2 can do immediate root CAs. - Removed server trust from: AC Raíz Certicámara S.A. ComSign Secured CA NetLock Uzleti (Class B) Tanusitvanykiado NetLock Business (Class B) Root NetLock Expressz (Class C) Tanusitvanykiado TC TrustCenter Class 3 CA II TURKTRUST Certificate Services Provider Root 1 TURKTRUST Certificate Services Provider Root 2 Equifax Secure Global eBusiness CA-1 Verisign Class 4 Public Primary Certification Authority G3 - enable server trust Actalis Authentication Root CA - Deleted CAs: A Trust nQual 03 Buypass Class 3 CA 1 CA Disig Digital Signature Trust Co Global CA 1 Digital Signature Trust Co Global CA 3 E Guven Kok Elektronik Sertifika Hizmet Saglayicisi NetLock Expressz (Class C) Tanusitvanykiado NetLock Kozjegyzoi (Class A) Tanusitvanykiado NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado NetLock Uzleti (Class B) Tanusitvanykiado SG TRUST SERVICES RACINE Staat der Nederlanden Root CA TC TrustCenter Class 2 CA II
Marcus Meissner2016-03-31 13:08:43 +00:00
bda0de663c
- Updated to 2.7. - diff-from-upstream-2.2.patch: removed as openssl 1.0.2 can do immediate root CAs. - Removed server trust from: AC Raíz Certicámara S.A. ComSign Secured CA NetLock Uzleti (Class B) Tanusitvanykiado NetLock Business (Class B) Root NetLock Expressz (Class C) Tanusitvanykiado TC TrustCenter Class 3 CA II TURKTRUST Certificate Services Provider Root 1 TURKTRUST Certificate Services Provider Root 2 Equifax Secure Global eBusiness CA-1 Verisign Class 4 Public Primary Certification Authority G3 - enable server trust Actalis Authentication Root CA - Deleted CAs: A Trust nQual 03 Buypass Class 3 CA 1 CA Disig Digital Signature Trust Co Global CA 1 Digital Signature Trust Co Global CA 3 E Guven Kok Elektronik Sertifika Hizmet Saglayicisi NetLock Expressz (Class C) Tanusitvanykiado NetLock Kozjegyzoi (Class A) Tanusitvanykiado NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado NetLock Uzleti (Class B) Tanusitvanykiado SG TRUST SERVICES RACINE Staat der Nederlanden Root CA TC TrustCenter Class 2 CA II
Marcus Meissner2016-03-31 13:08:43 +00:00
ba558922b3
- diff-from-upstream-2.2.patch: Temporary reenable some root ca trusts, as openssl/gnutls have trouble using intermediates as root CA. - GTE CyberTrust Global Root - Thawte Server CA - Thawte Premium Server CA - ValiCert Class 1 VA - ValiCert Class 2 VA - RSA Root Certificate 1 - Entrust.net Secure Server CA - America Online Root Certification Authority 1 - America Online Root Certification Authority 2
Marcus Meissner2015-01-14 09:43:56 +00:00
d3e3a94129
- diff-from-upstream-2.2.patch: Temporary reenable some root ca trusts, as openssl/gnutls have trouble using intermediates as root CA. - GTE CyberTrust Global Root - Thawte Server CA - Thawte Premium Server CA - ValiCert Class 1 VA - ValiCert Class 2 VA - RSA Root Certificate 1 - Entrust.net Secure Server CA - America Online Root Certification Authority 1 - America Online Root Certification Authority 2
Marcus Meissner2015-01-14 09:43:56 +00:00
7e390f6a84
- Updated to 2.2 (bnc#888534) - The following CAs were removed: + America_Online_Root_Certification_Authority_1 + America_Online_Root_Certification_Authority_2 + GTE_CyberTrust_Global_Root + Thawte_Premium_Server_CA + Thawte_Server_CA - The following CAs were added: + COMODO_RSA_Certification_Authority codeSigning emailProtection serverAuth + GlobalSign_ECC_Root_CA_-_R4 codeSigning emailProtection serverAuth + GlobalSign_ECC_Root_CA_-_R5 codeSigning emailProtection serverAuth + USERTrust_ECC_Certification_Authority codeSigning emailProtection serverAuth + USERTrust_RSA_Certification_Authority codeSigning emailProtection serverAuth + VeriSign-C3SSA-G2-temporary-intermediate-after-1024bit-removal - The following CAs were changed: + Equifax_Secure_eBusiness_CA_1 remote code signing and https trust, leave email trust + Verisign_Class_3_Public_Primary_Certification_Authority_-_G2 only trust emailProtection
Marcus Meissner2015-01-12 16:50:43 +00:00
2cfeb8d007
- Updated to 2.2 (bnc#888534) - The following CAs were removed: + America_Online_Root_Certification_Authority_1 + America_Online_Root_Certification_Authority_2 + GTE_CyberTrust_Global_Root + Thawte_Premium_Server_CA + Thawte_Server_CA - The following CAs were added: + COMODO_RSA_Certification_Authority codeSigning emailProtection serverAuth + GlobalSign_ECC_Root_CA_-_R4 codeSigning emailProtection serverAuth + GlobalSign_ECC_Root_CA_-_R5 codeSigning emailProtection serverAuth + USERTrust_ECC_Certification_Authority codeSigning emailProtection serverAuth + USERTrust_RSA_Certification_Authority codeSigning emailProtection serverAuth + VeriSign-C3SSA-G2-temporary-intermediate-after-1024bit-removal - The following CAs were changed: + Equifax_Secure_eBusiness_CA_1 remote code signing and https trust, leave email trust + Verisign_Class_3_Public_Primary_Certification_Authority_-_G2 only trust emailProtection
Marcus Meissner2015-01-12 16:50:43 +00:00
d006589b99
- certdata-temporary-1024.patch: restore some certificates removed from NSS as these are still used for some major sites. openssl is not as clever as NSS in selecting the new ones in the chain correctly.
Marcus Meissner2015-01-12 15:58:35 +00:00
b4c0f97a4b
- certdata-temporary-1024.patch: restore some certificates removed from NSS as these are still used for some major sites. openssl is not as clever as NSS in selecting the new ones in the chain correctly.
Marcus Meissner2015-01-12 15:58:35 +00:00
0845f3d677
- Updated to 2.1 (bnc#888534) - The following 1024-bit CA certificates were removed - Entrust.net Secure Server Certification Authority - ValiCert Class 1 Policy Validation Authority - ValiCert Class 2 Policy Validation Authority - ValiCert Class 3 Policy Validation Authority - TDC Internet Root CA - The following CA certificates were added: - Certification Authority of WoSign - CA 沃通根证书 - DigiCert Assured ID Root G2 - DigiCert Assured ID Root G3 - DigiCert Global Root G2 - DigiCert Global Root G3 - DigiCert Trusted Root G4 - QuoVadis Root CA 1 G3 - QuoVadis Root CA 2 G3 - QuoVadis Root CA 3 G3 - The Trust Bits were changed for the following CA certificates - Class 3 Public Primary Certification Authority - Class 3 Public Primary Certification Authority - Class 2 Public Primary Certification Authority - G2 - VeriSign Class 2 Public Primary Certification Authority - G3 - AC Raíz Certicámara S.A. - NetLock Uzleti (Class B) Tanusitvanykiado - NetLock Expressz (Class C) Tanusitvanykiado
Marcus Meissner2014-09-25 13:26:14 +00:00
69dda2cf9d
- Updated to 2.1 (bnc#888534) - The following 1024-bit CA certificates were removed - Entrust.net Secure Server Certification Authority - ValiCert Class 1 Policy Validation Authority - ValiCert Class 2 Policy Validation Authority - ValiCert Class 3 Policy Validation Authority - TDC Internet Root CA - The following CA certificates were added: - Certification Authority of WoSign - CA 沃通根证书 - DigiCert Assured ID Root G2 - DigiCert Assured ID Root G3 - DigiCert Global Root G2 - DigiCert Global Root G3 - DigiCert Trusted Root G4 - QuoVadis Root CA 1 G3 - QuoVadis Root CA 2 G3 - QuoVadis Root CA 3 G3 - The Trust Bits were changed for the following CA certificates - Class 3 Public Primary Certification Authority - Class 3 Public Primary Certification Authority - Class 2 Public Primary Certification Authority - G2 - VeriSign Class 2 Public Primary Certification Authority - G3 - AC Raíz Certicámara S.A. - NetLock Uzleti (Class B) Tanusitvanykiado - NetLock Expressz (Class C) Tanusitvanykiado
Marcus Meissner2014-09-25 13:26:14 +00:00
41d76155ab
Accepting request 247731 from Base:System
Stephan Kulow
2014-09-08 19:28:14 +00:00
b8aeb0b64e
Accepting request 247731 from Base:System
Stephan Kulow
2014-09-08 19:28:14 +00:00
f4def07a1b
Accepting request 246744 from Base:System
Stephan Kulow
2014-08-30 16:55:49 +00:00
0ddfa86465
Accepting request 246744 from Base:System
Stephan Kulow
2014-08-30 16:55:49 +00:00
965844d5ff
Accepting request 246743 from home:msmeissn:branches:Base:System
Marcus Meissner2014-08-28 15:42:49 +00:00
76f2437395
Accepting request 246743 from home:msmeissn:branches:Base:System
Marcus Meissner2014-08-28 15:42:49 +00:00
fbc396b74a
Accepting request 238154 from Base:System
Stephan Kulow
2014-06-25 13:23:59 +00:00
d38879273b
Accepting request 238154 from Base:System
Stephan Kulow
2014-06-25 13:23:59 +00:00
eef0a7995e
Accepting request 237977 from home:msmeissn:branches:Base:System
Marcus Meissner2014-06-20 12:36:04 +00:00
c5d39025fa
Accepting request 237977 from home:msmeissn:branches:Base:System
Marcus Meissner2014-06-20 12:36:04 +00:00
740e09f169
Accepting request 237853 from Base:System
Stephan Kulow
2014-06-18 08:59:38 +00:00
953990ba52
Accepting request 237853 from Base:System
Stephan Kulow
2014-06-18 08:59:38 +00:00
3d7b75087c
- in sle11 we bumped openssl-certs version to match the NSS version, so provide/obsolete the current version.
Marcus Meissner2014-06-10 12:52:56 +00:00
16feb434c8
- in sle11 we bumped openssl-certs version to match the NSS version, so provide/obsolete the current version.
Marcus Meissner2014-06-10 12:52:56 +00:00
5f915a1213
Accepting request 223628 from Base:System
Tomáš Chvátal
2014-02-25 15:41:06 +00:00
f557786cea
Accepting request 223628 from Base:System
Tomáš Chvátal
2014-02-25 15:41:06 +00:00
f5c7eb0f1d
Accepting request 223627 from home:msmeissn:branches:Base:System
Marcus Meissner2014-02-24 08:53:37 +00:00
817799ae13
Accepting request 223627 from home:msmeissn:branches:Base:System
Marcus Meissner2014-02-24 08:53:37 +00:00
db81679020
Accepting request 211084 from Base:System
Stephan Kulow
2013-12-17 09:00:36 +00:00
e859c2a51b
Accepting request 211084 from Base:System
Stephan Kulow
2013-12-17 09:00:36 +00:00
cfac814a19
- Updated to 1.95 Distrust a sub-ca that issued google.com certificates. "Distrusted AC DG Tresor SSL" (bnc#854367)
Marcus Meissner2013-12-09 16:03:09 +00:00
993d8b9f94
- Updated to 1.95 Distrust a sub-ca that issued google.com certificates. "Distrusted AC DG Tresor SSL" (bnc#854367)
Marcus Meissner2013-12-09 16:03:09 +00:00
7181a3b2a3
- fix handling of certificates with same name (bnc#854163)
Ludwig Nussel2013-12-09 10:01:15 +00:00
ba1b821fcd
- fix handling of certificates with same name (bnc#854163)
Ludwig Nussel2013-12-09 10:01:15 +00:00
333df1932c
Accepting request 205921 from Base:System
Stephan Kulow
2013-11-07 07:34:02 +00:00
901fd4e824
Accepting request 205921 from Base:System
Stephan Kulow
2013-11-07 07:34:02 +00:00
a620c96994
- removed temporary Entrust.net_Premium_2048_Secure_Server_CA.p11-kit override.
Marcus Meissner2013-10-29 14:13:23 +00:00
f17e1e87bb
- removed temporary Entrust.net_Premium_2048_Secure_Server_CA.p11-kit override.
Marcus Meissner2013-10-29 14:13:23 +00:00
a173ef93a3
- Updated to 1.94 * new: CA_Disig_Root_R1:2.9.0.195.3.154.238.80.144.110.40.crt server auth, code signing, email signing * new: CA_Disig_Root_R2:2.9.0.146.184.136.219.176.138.193.99.crt server auth, code signing, email signing * new: China_Internet_Network_Information_Center_EV_Certificates_Root:2.4.72.159.0.1.crt server auth * changed: Digital_Signature_Trust_Co._Global_CA_1:2.4.54.112.21.150.crt removed code signing and server auth abilities * changed: Digital_Signature_Trust_Co._Global_CA_3:2.4.54.110.211.206.crt removed code signing and server auth abilities * new: D-TRUST_Root_Class_3_CA_2_2009:2.3.9.131.243.crt server auth * new: D-TRUST_Root_Class_3_CA_2_EV_2009:2.3.9.131.244.crt server auth * removed: Entrust.net_Premium_2048_Secure_Server_CA:2.4.56.99.185.102.crt * new: Entrust.net_Premium_2048_Secure_Server_CA:2.4.56.99.222.248.crt I think the missing flags were adjusted. * removed: Equifax_Secure_eBusiness_CA_2:2.4.55.112.207.181.crt * new: PSCProcert:2.1.11.crt server auth, code signing, email signing * new: Swisscom_Root_CA_2:2.16.30.158.40.232.72.242.229.239.195.124.74.30.90.24.103.182.crt server auth, code signing, email signing * new: Swisscom_Root_EV_CA_2:2.17.0.242.250.100.226.116.99.211.141.253.16.29.4.31.118.202.88.crt server auth, code signing * changed: TC_TrustCenter_Universal_CA_III:2.14.99.37.0.1.0.2.20.141.51.21.2.228.108.244.crt removed all abilities * new: TURKTRUST_Certificate_Services_Provider_Root_2007:2.1.1.crt server auth, code signing * changed: TWCA_Root_Certification_Authority:2.1.1.crt
Marcus Meissner2013-10-29 13:59:48 +00:00
8edc6e871f
- Updated to 1.94 * new: CA_Disig_Root_R1:2.9.0.195.3.154.238.80.144.110.40.crt server auth, code signing, email signing * new: CA_Disig_Root_R2:2.9.0.146.184.136.219.176.138.193.99.crt server auth, code signing, email signing * new: China_Internet_Network_Information_Center_EV_Certificates_Root:2.4.72.159.0.1.crt server auth * changed: Digital_Signature_Trust_Co._Global_CA_1:2.4.54.112.21.150.crt removed code signing and server auth abilities * changed: Digital_Signature_Trust_Co._Global_CA_3:2.4.54.110.211.206.crt removed code signing and server auth abilities * new: D-TRUST_Root_Class_3_CA_2_2009:2.3.9.131.243.crt server auth * new: D-TRUST_Root_Class_3_CA_2_EV_2009:2.3.9.131.244.crt server auth * removed: Entrust.net_Premium_2048_Secure_Server_CA:2.4.56.99.185.102.crt * new: Entrust.net_Premium_2048_Secure_Server_CA:2.4.56.99.222.248.crt I think the missing flags were adjusted. * removed: Equifax_Secure_eBusiness_CA_2:2.4.55.112.207.181.crt * new: PSCProcert:2.1.11.crt server auth, code signing, email signing * new: Swisscom_Root_CA_2:2.16.30.158.40.232.72.242.229.239.195.124.74.30.90.24.103.182.crt server auth, code signing, email signing * new: Swisscom_Root_EV_CA_2:2.17.0.242.250.100.226.116.99.211.141.253.16.29.4.31.118.202.88.crt server auth, code signing * changed: TC_TrustCenter_Universal_CA_III:2.14.99.37.0.1.0.2.20.141.51.21.2.228.108.244.crt removed all abilities * new: TURKTRUST_Certificate_Services_Provider_Root_2007:2.1.1.crt server auth, code signing * changed: TWCA_Root_Certification_Authority:2.1.1.crt
Marcus Meissner2013-10-29 13:59:48 +00:00
474d3e1d08
Accepting request 196630 from Base:System
Stephan Kulow
2013-08-30 09:33:02 +00:00
88ef6e8428
Accepting request 196630 from Base:System
Stephan Kulow
2013-08-30 09:33:02 +00:00
f0e9c466d6
Accepting request 196618 from home:lnussel:branches:Base:System
Marcus Meissner2013-08-28 08:42:46 +00:00
b5121d850d
Accepting request 196618 from home:lnussel:branches:Base:System
Marcus Meissner2013-08-28 08:42:46 +00:00
42b214ce63
Accepting request 184205 from Base:System
Stephan Kulow
2013-07-25 11:18:17 +00:00
c3f99f810e
Accepting request 184205 from Base:System
Stephan Kulow
2013-07-25 11:18:17 +00:00
e0dd7139c9
- remove superfluous double quotes from certificate names
Ludwig Nussel2013-07-24 15:07:12 +00:00
a410738a83
- remove superfluous double quotes from certificate names
Ludwig Nussel2013-07-24 15:07:12 +00:00
fb04b44016
- add nssckbi.h that matches certdata.txt; make sure package has the correct version number which is currently 1.93. No actual content change in certdata.txt compared to 1.85, it's just that the versioning scheme changed.
Ludwig Nussel2013-07-24 14:45:48 +00:00
c7e4526057
- add nssckbi.h that matches certdata.txt; make sure package has the correct version number which is currently 1.93. No actual content change in certdata.txt compared to 1.85, it's just that the versioning scheme changed.
Ludwig Nussel2013-07-24 14:45:48 +00:00
9773ac22b9
- add fake basic contraints to Entrust root so p11-kit export the cert (bnc#829471)
Ludwig Nussel2013-07-24 14:32:44 +00:00
abed6a95f8
- add fake basic contraints to Entrust root so p11-kit export the cert (bnc#829471)
Ludwig Nussel2013-07-24 14:32:44 +00:00
e876708c6a
Accepting request 181769 from Base:System
Stephan Kulow
2013-07-03 08:15:09 +00:00
aa2058350a
Accepting request 181769 from Base:System
Stephan Kulow
2013-07-03 08:15:09 +00:00
4755a03b99
Accepting request 181763 from home:lnussel:branches:Base:System
Ludwig Nussel2013-07-02 13:57:37 +00:00
c8d346e1ec
Accepting request 181763 from home:lnussel:branches:Base:System
Ludwig Nussel2013-07-02 13:57:37 +00:00
1bda67731c
Accepting request 180735 from Base:System
Stephan Kulow
2013-06-25 07:22:50 +00:00
768c79a66f
Accepting request 180735 from Base:System
Stephan Kulow
2013-06-25 07:22:50 +00:00
68f6492888
Accepting request 180733 from home:lnussel:branches:Base:System
Ludwig Nussel2013-06-24 11:21:23 +00:00
b838180707
Accepting request 180733 from home:lnussel:branches:Base:System
Ludwig Nussel2013-06-24 11:21:23 +00:00
00fd771259
fate 314991, use p11-kit for system ca-certificate handling
Ludwig Nussel2013-06-21 12:48:17 +00:00
b9942cd5a7
fate 314991, use p11-kit for system ca-certificate handling
Ludwig Nussel2013-06-21 12:48:17 +00:00