Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Feb 2021 01:42:09 GMT
From:      Mark Johnston <markj@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: efc9549ba0c2 - releng/12.2 - MFC r368555: caroot: update bundle
Message-ID:  <202102240142.11O1g9w9054539@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch releng/12.2 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=efc9549ba0c2caffd45e1f7f88fdd75a0225e568

commit efc9549ba0c2caffd45e1f7f88fdd75a0225e568
Author:     Kyle Evans <kevans@FreeBSD.org>
AuthorDate: 2020-12-15 21:50:05 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2021-02-24 01:42:01 +0000

    MFC r368555: caroot: update bundle
    
    Summary:
    - One (1) added
    - Ten (10) removed
    
    Approved by:    so
    Security:       FreeBSD-EN-21:07.caroot
    
    (cherry picked from commit e4e8ecaf63ba6f2767680a7b4666461243d88749)
---
 .../GeoTrust_Global_CA.pem                         |   0
 .../GeoTrust_Primary_Certification_Authority.pem   |   0
 ...oTrust_Primary_Certification_Authority_-_G3.pem |   0
 .../GeoTrust_Universal_CA.pem                      |   0
 .../GeoTrust_Universal_CA_2.pem                    |   0
 ...Public_Primary_Certification_Authority_-_G4.pem |   0
 ...Public_Primary_Certification_Authority_-_G5.pem |   0
 .../thawte_Primary_Root_CA.pem                     |   0
 .../thawte_Primary_Root_CA_-_G2.pem                |   0
 .../thawte_Primary_Root_CA_-_G3.pem                |   0
 .../NAVER_Global_Root_Certification_Authority.pem  | 134 +++++++++++++++++++++
 11 files changed, 134 insertions(+)

diff --git a/secure/caroot/trusted/GeoTrust_Global_CA.pem b/secure/caroot/blacklisted/GeoTrust_Global_CA.pem
similarity index 100%
rename from secure/caroot/trusted/GeoTrust_Global_CA.pem
rename to secure/caroot/blacklisted/GeoTrust_Global_CA.pem
diff --git a/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem b/secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority.pem
similarity index 100%
rename from secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem
rename to secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority.pem
diff --git a/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem b/secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G3.pem
similarity index 100%
rename from secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
rename to secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G3.pem
diff --git a/secure/caroot/trusted/GeoTrust_Universal_CA.pem b/secure/caroot/blacklisted/GeoTrust_Universal_CA.pem
similarity index 100%
rename from secure/caroot/trusted/GeoTrust_Universal_CA.pem
rename to secure/caroot/blacklisted/GeoTrust_Universal_CA.pem
diff --git a/secure/caroot/trusted/GeoTrust_Universal_CA_2.pem b/secure/caroot/blacklisted/GeoTrust_Universal_CA_2.pem
similarity index 100%
rename from secure/caroot/trusted/GeoTrust_Universal_CA_2.pem
rename to secure/caroot/blacklisted/GeoTrust_Universal_CA_2.pem
diff --git a/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem b/secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
similarity index 100%
rename from secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
rename to secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
diff --git a/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem b/secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
similarity index 100%
rename from secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
rename to secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
diff --git a/secure/caroot/trusted/thawte_Primary_Root_CA.pem b/secure/caroot/blacklisted/thawte_Primary_Root_CA.pem
similarity index 100%
rename from secure/caroot/trusted/thawte_Primary_Root_CA.pem
rename to secure/caroot/blacklisted/thawte_Primary_Root_CA.pem
diff --git a/secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem b/secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G2.pem
similarity index 100%
rename from secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem
rename to secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G2.pem
diff --git a/secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem b/secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G3.pem
similarity index 100%
rename from secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem
rename to secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G3.pem
diff --git a/secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem b/secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem
new file mode 100644
index 000000000000..3b042c1c2716
--- /dev/null
+++ b/secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem
@@ -0,0 +1,134 @@
+##
+##  NAVER Global Root Certification Authority
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            01:94:30:1e:a2:0b:dd:f5:c5:33:2a:b1:43:44:71:f8:d6:50:4d:0d
+        Signature Algorithm: sha384WithRSAEncryption
+        Issuer: C = KR, O = NAVER BUSINESS PLATFORM Corp., CN = NAVER Global Root Certification Authority
+        Validity
+            Not Before: Aug 18 08:58:42 2017 GMT
+            Not After : Aug 18 23:59:59 2037 GMT
+        Subject: C = KR, O = NAVER BUSINESS PLATFORM Corp., CN = NAVER Global Root Certification Authority
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:b6:d4:f1:93:5c:b5:40:89:0a:ab:0d:90:5b:50:
+                    63:ae:90:94:74:17:45:72:d6:7b:65:5a:29:4b:a7:
+                    56:a0:4b:b8:2f:42:75:e9:d9:7b:24:5a:31:65:ab:
+                    17:17:d1:33:3a:d9:11:dc:40:36:87:df:c7:6a:e9:
+                    26:5e:59:8a:77:e3:e8:48:9c:31:16:fa:3e:91:b1:
+                    ca:c9:a3:e2:9f:ce:21:53:a3:02:36:30:cb:52:02:
+                    e5:da:32:5d:c3:c5:e6:f9:ee:11:c7:8b:c9:44:1e:
+                    84:93:18:4a:b4:9f:e5:12:64:69:d0:26:85:62:01:
+                    b6:c9:02:1d:be:83:51:bb:5c:da:f8:ad:15:6a:99:
+                    f7:92:54:f7:34:5b:e9:bf:ea:29:81:12:d4:53:91:
+                    96:b3:91:5a:dd:fe:90:73:28:fb:30:46:b5:ca:08:
+                    07:c7:71:72:c9:66:d3:34:97:f6:8c:f4:18:4a:e1:
+                    d0:3d:5a:45:b6:69:a7:29:fb:23:ce:88:d8:12:9c:
+                    00:48:a8:a6:0f:b3:3b:92:8d:71:0e:74:c5:8b:c8:
+                    4c:f9:f4:9b:8e:b8:3c:69:ed:6f:3b:50:2f:58:ed:
+                    c4:b0:d0:1c:1b:6a:0c:e2:bc:44:aa:d8:cd:14:5d:
+                    94:78:61:bf:0e:6e:da:2a:bc:2f:0c:0b:71:a6:b3:
+                    16:3f:9c:e6:f9:cc:9f:53:35:e2:03:a0:a0:18:bf:
+                    bb:f1:be:f4:d6:8c:87:0d:42:f7:06:b9:f1:6d:ed:
+                    04:94:a8:fe:b6:d3:06:c6:40:61:df:9d:9d:f3:54:
+                    76:ce:53:3a:01:a6:92:41:ec:04:a3:8f:0d:a2:d5:
+                    09:ca:d6:cb:9a:f1:ef:43:5d:c0:ab:a5:41:cf:5c:
+                    53:70:70:c9:88:a6:2d:d4:6b:61:73:50:26:86:61:
+                    0e:5f:1b:c2:2b:e2:8c:d5:bb:9d:c1:03:42:ba:94:
+                    da:5f:a9:b0:ca:cc:4d:0a:ef:47:69:03:2f:22:fb:
+                    f1:28:ce:bf:5d:50:65:a8:90:6d:b3:74:b0:08:c7:
+                    ac:a8:d1:eb:3e:9c:fc:5d:1a:83:2e:2b:cb:b5:f3:
+                    44:9d:3a:a7:17:61:96:a2:71:d3:70:96:15:4d:b7:
+                    4c:73:ee:19:5c:c5:5b:3e:41:fe:ac:75:60:3b:1b:
+                    63:ce:00:dd:da:08:90:62:b4:e5:2d:ee:48:a7:6b:
+                    17:99:54:be:87:4a:e3:a9:5e:04:4c:eb:10:6d:54:
+                    d6:ef:f1:e8:f2:62:16:cb:80:6b:ed:3d:ed:f5:1f:
+                    30:a5:ae:4b:c9:13:ed:8a:01:01:c9:b8:51:58:c0:
+                    66:3a:b1:66:4b:c4:d5:31:02:62:e9:74:84:0c:db:
+                    4d:46:2d
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                D2:9F:88:DF:A1:CD:2C:BD:EC:F5:3B:01:01:93:33:27:B2:EB:60:4B
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+    Signature Algorithm: sha384WithRSAEncryption
+         32:ca:80:b3:9d:3d:54:06:dd:d2:d2:2e:f0:a4:01:21:0b:67:
+         48:ca:6d:8e:e0:c8:aa:0d:aa:8d:21:57:8f:c6:3e:7a:ca:db:
+         51:d4:52:b3:d4:96:84:a5:58:60:7f:e5:0b:8e:1f:f5:dc:0a:
+         15:81:e5:3b:b6:b7:22:2f:09:9c:13:16:b1:6c:0c:35:08:6d:
+         ab:63:72:ed:dc:be:ec:c7:57:e6:30:20:71:d6:d7:10:c1:13:
+         55:01:8c:2a:43:e4:41:f1:cf:3a:7a:53:92:ce:a2:03:05:0d:
+         38:df:02:bb:10:2e:d9:3b:d2:9b:7a:c0:a1:a6:f8:b5:31:e6:
+         f4:75:c9:b9:53:99:75:47:22:5a:14:15:c7:78:1b:b6:9d:e9:
+         0c:f8:1b:76:f1:85:84:de:a1:da:12:ef:a4:e2:10:97:7a:78:
+         de:0c:51:97:a8:21:40:8b:86:bd:0d:f0:5e:4e:4b:36:bb:3b:
+         20:1f:8a:42:56:e1:0b:1a:bf:7b:d0:22:43:2c:44:8c:fb:e5:
+         2a:b4:6c:1c:1c:ba:94:e0:13:7e:21:e6:9a:c2:cb:c5:42:64:
+         b4:1e:94:7b:08:25:c8:71:cc:87:45:57:85:d3:9f:29:62:22:
+         83:51:97:00:18:97:77:6a:98:92:c9:7c:60:6c:df:6c:7d:4a:
+         e4:70:4c:c2:9e:b8:1d:f7:d0:34:c7:0f:cc:fb:a7:ff:03:be:
+         ad:70:90:da:0b:dd:c8:6d:97:5f:9a:7f:09:32:41:fd:cd:a2:
+         cc:5a:6d:4c:f2:aa:49:fe:66:f8:e9:d8:35:eb:0e:28:1e:ee:
+         48:2f:3a:d0:79:09:38:7c:a6:22:82:93:95:d0:03:be:be:02:
+         a0:05:dd:20:22:e3:6f:1d:88:34:60:c6:e6:0a:b9:09:75:0b:
+         f0:07:e8:69:96:35:c7:fb:23:81:8e:38:39:b8:45:2b:43:78:
+         a2:d1:2c:14:ff:0d:28:72:72:95:9b:5e:09:db:89:44:98:aa:
+         a1:49:bb:71:52:f2:bf:f6:ff:27:a1:36:af:b8:b6:77:88:dd:
+         3a:a4:6d:9b:34:90:dc:14:5d:30:bf:b7:eb:17:e4:87:b7:71:
+         d0:a1:d7:77:15:d4:42:d7:f2:f3:31:99:5d:9b:dd:16:6d:3f:
+         ea:06:23:f8:46:a2:22:ed:93:f6:dd:9a:e6:2a:87:b1:98:54:
+         f1:22:f7:6b:45:e3:e2:8e:76:1d:9a:8d:c4:06:8d:36:b7:14:
+         f3:9d:54:69:b7:8e:3c:d5:a4:6d:93:81:b7:ad:f6:bd:64:7b:
+         c2:c9:68:39:a0:92:9c:cd:34:86:91:90:fa:64:51:9d:fe:fe:
+         eb:a5:f5:75:de:89:f7:72
+SHA1 Fingerprint=8F:6B:F2:A9:27:4A:DA:14:A0:C4:F4:8E:61:27:F9:C0:1E:78:5D:D1
+-----BEGIN CERTIFICATE-----
+MIIFojCCA4qgAwIBAgIUAZQwHqIL3fXFMyqxQ0Rx+NZQTQ0wDQYJKoZIhvcNAQEM
+BQAwaTELMAkGA1UEBhMCS1IxJjAkBgNVBAoMHU5BVkVSIEJVU0lORVNTIFBMQVRG
+T1JNIENvcnAuMTIwMAYDVQQDDClOQVZFUiBHbG9iYWwgUm9vdCBDZXJ0aWZpY2F0
+aW9uIEF1dGhvcml0eTAeFw0xNzA4MTgwODU4NDJaFw0zNzA4MTgyMzU5NTlaMGkx
+CzAJBgNVBAYTAktSMSYwJAYDVQQKDB1OQVZFUiBCVVNJTkVTUyBQTEFURk9STSBD
+b3JwLjEyMDAGA1UEAwwpTkFWRVIgR2xvYmFsIFJvb3QgQ2VydGlmaWNhdGlvbiBB
+dXRob3JpdHkwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC21PGTXLVA
+iQqrDZBbUGOukJR0F0Vy1ntlWilLp1agS7gvQnXp2XskWjFlqxcX0TM62RHcQDaH
+38dq6SZeWYp34+hInDEW+j6RscrJo+KfziFTowI2MMtSAuXaMl3Dxeb57hHHi8lE
+HoSTGEq0n+USZGnQJoViAbbJAh2+g1G7XNr4rRVqmfeSVPc0W+m/6imBEtRTkZaz
+kVrd/pBzKPswRrXKCAfHcXLJZtM0l/aM9BhK4dA9WkW2aacp+yPOiNgSnABIqKYP
+szuSjXEOdMWLyEz59JuOuDxp7W87UC9Y7cSw0BwbagzivESq2M0UXZR4Yb8Obtoq
+vC8MC3GmsxY/nOb5zJ9TNeIDoKAYv7vxvvTWjIcNQvcGufFt7QSUqP620wbGQGHf
+nZ3zVHbOUzoBppJB7ASjjw2i1QnK1sua8e9DXcCrpUHPXFNwcMmIpi3Ua2FzUCaG
+YQ5fG8Ir4ozVu53BA0K6lNpfqbDKzE0K70dpAy8i+/Eozr9dUGWokG2zdLAIx6yo
+0es+nPxdGoMuK8u180SdOqcXYZaicdNwlhVNt0xz7hlcxVs+Qf6sdWA7G2POAN3a
+CJBitOUt7kinaxeZVL6HSuOpXgRM6xBtVNbv8ejyYhbLgGvtPe31HzClrkvJE+2K
+AQHJuFFYwGY6sWZLxNUxAmLpdIQM201GLQIDAQABo0IwQDAdBgNVHQ4EFgQU0p+I
+36HNLL3s9TsBAZMzJ7LrYEswDgYDVR0PAQH/BAQDAgEGMA8GA1UdEwEB/wQFMAMB
+Af8wDQYJKoZIhvcNAQEMBQADggIBADLKgLOdPVQG3dLSLvCkASELZ0jKbY7gyKoN
+qo0hV4/GPnrK21HUUrPUloSlWGB/5QuOH/XcChWB5Tu2tyIvCZwTFrFsDDUIbatj
+cu3cvuzHV+YwIHHW1xDBE1UBjCpD5EHxzzp6U5LOogMFDTjfArsQLtk70pt6wKGm
++LUx5vR1yblTmXVHIloUFcd4G7ad6Qz4G3bxhYTeodoS76TiEJd6eN4MUZeoIUCL
+hr0N8F5OSza7OyAfikJW4Qsav3vQIkMsRIz75Sq0bBwcupTgE34h5prCy8VCZLQe
+lHsIJchxzIdFV4XTnyliIoNRlwAYl3dqmJLJfGBs32x9SuRwTMKeuB330DTHD8z7
+p/8Dvq1wkNoL3chtl1+afwkyQf3NosxabUzyqkn+Zvjp2DXrDige7kgvOtB5CTh8
+piKCk5XQA76+AqAF3SAi428diDRgxuYKuQl1C/AH6GmWNcf7I4GOODm4RStDeKLR
+LBT/DShycpWbXgnbiUSYqqFJu3FS8r/2/yehNq+4tneI3TqkbZs0kNwUXTC/t+sX
+5Ie3cdCh13cV1ELX8vMxmV2b3RZtP+oGI/hGoiLtk/bdmuYqh7GYVPEi92tF4+KO
+dh2ajcQGjTa3FPOdVGm3jjzVpG2Tgbet9r1ke8LJaDmgkpzNNIaRkPpkUZ3+/uul
+9XXeifdy
+-----END CERTIFICATE-----



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202102240142.11O1g9w9054539>