[Midnightbsd-cvs] [MidnightBSD/src] 0835a1: caroot: Generate both trusted and untrusted

Dag-Erling Smørgrav noreply at github.com
Thu May 21 10:59:47 EDT 2026


  Branch: refs/heads/stable/4.0
  Home:   https://github.com/MidnightBSD/src
  Commit: 0835a10256411461227122254250208def33d0df
      https://github.com/MidnightBSD/src/commit/0835a10256411461227122254250208def33d0df
  Author: Dag-Erling Smørgrav <des at FreeBSD.org>
  Date:   2026-05-21 (Thu, 21 May 2026)

  Changed paths:
    M secure/caroot/MAca-bundle.pl
    M secure/caroot/Makefile
    M secure/caroot/blacklisted/Makefile
    M secure/caroot/trusted/Makefile

  Log Message:
  -----------
  caroot: Generate both trusted and untrusted

Until now, the untrusted directory has been maintained manually.  Modify
the script used to maintain the trusted directory so it can handle both.
While here, clean it up a bit.

MFC after:	1 week
Reviewed by:	mandree, markj
Differential Revision:	https://reviews.freebsd.org/D51774

(cherry picked from commit b88b0bb784c7fdcfb8174806e822c1f8983c223f)


  Commit: 95fac7fc439a2d7fe35b37aed008daaf7289ba22
      https://github.com/MidnightBSD/src/commit/95fac7fc439a2d7fe35b37aed008daaf7289ba22
  Author: Dag-Erling Smørgrav <des at FreeBSD.org>
  Date:   2026-05-21 (Thu, 21 May 2026)

  Changed paths:
    R secure/caroot/MAca-bundle.pl
    M secure/caroot/Makefile
    A secure/caroot/ca-extract.pl

  Log Message:
  -----------
  caroot: Rename script and normalize license

MFC after:	1 week
Reviewed by:	mandree, markj
Differential Revision:	https://reviews.freebsd.org/D51775

(cherry picked from commit 0886019bf853bd30b70aa4b8cdb059830ca6aaad)


  Commit: b4697b7bbc160e8227041fe0bdc9302ec3de131d
      https://github.com/MidnightBSD/src/commit/b4697b7bbc160e8227041fe0bdc9302ec3de131d
  Author: Dag-Erling Smørgrav <des at FreeBSD.org>
  Date:   2026-05-21 (Thu, 21 May 2026)

  Changed paths:
    M secure/caroot/Makefile
    M secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
    M secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
    M secure/caroot/blacklisted/Certum_Root_CA.pem
    M secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
    M secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
    M secure/caroot/blacklisted/E-Tugra_Global_Root_CA_ECC_v3.pem
    M secure/caroot/blacklisted/E-Tugra_Global_Root_CA_RSA_v3.pem
    M secure/caroot/blacklisted/EC-ACC.pem
    M secure/caroot/blacklisted/EE_Certification_Centre_Root_CA.pem
    M secure/caroot/blacklisted/Entrust_Root_Certification_Authority_-_G4.pem
    M secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority.pem
    M secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
    M secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G3.pem
    M secure/caroot/blacklisted/GeoTrust_Universal_CA.pem
    M secure/caroot/blacklisted/GeoTrust_Universal_CA_2.pem
    M secure/caroot/blacklisted/Global_Chambersign_Root_-_2008.pem
    M secure/caroot/blacklisted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
    M secure/caroot/blacklisted/LuxTrust_Global_Root_2.pem
    M secure/caroot/blacklisted/Network_Solutions_Certificate_Authority.pem
    M secure/caroot/blacklisted/OISTE_WISeKey_Global_Root_GA_CA.pem
    M secure/caroot/blacklisted/SecureSign_RootCA11.pem
    M secure/caroot/blacklisted/Security_Communication_RootCA3.pem
    M secure/caroot/blacklisted/Staat_der_Nederlanden_Root_CA_-_G3.pem
    M secure/caroot/blacklisted/SwissSign_Platinum_CA_-_G2.pem
    M secure/caroot/blacklisted/SwissSign_Silver_CA_-_G2.pem
    M secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
    M secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
    M secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
    M secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
    M secure/caroot/blacklisted/Taiwan_GRCA.pem
    M secure/caroot/blacklisted/TrustCor_ECA-1.pem
    M secure/caroot/blacklisted/TrustCor_RootCert_CA-1.pem
    M secure/caroot/blacklisted/TrustCor_RootCert_CA-2.pem
    M secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
    M secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
    M secure/caroot/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
    M secure/caroot/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
    M secure/caroot/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
    M secure/caroot/blacklisted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
    M secure/caroot/blacklisted/thawte_Primary_Root_CA.pem
    M secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G2.pem
    M secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G3.pem
    M secure/caroot/ca-extract.pl
    M secure/caroot/trusted/ACCVRAIZ1.pem
    M secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
    M secure/caroot/trusted/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
    M secure/caroot/trusted/ANF_Secure_Server_Root_CA.pem
    M secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
    M secure/caroot/trusted/AffirmTrust_Commercial.pem
    M secure/caroot/trusted/AffirmTrust_Networking.pem
    M secure/caroot/trusted/AffirmTrust_Premium.pem
    M secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
    M secure/caroot/trusted/Amazon_Root_CA_1.pem
    M secure/caroot/trusted/Amazon_Root_CA_2.pem
    M secure/caroot/trusted/Amazon_Root_CA_3.pem
    M secure/caroot/trusted/Amazon_Root_CA_4.pem
    M secure/caroot/trusted/Atos_TrustedRoot_2011.pem
    M secure/caroot/trusted/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.pem
    M secure/caroot/trusted/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.pem
    M secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
    M secure/caroot/trusted/BJCA_Global_Root_CA1.pem
    M secure/caroot/trusted/BJCA_Global_Root_CA2.pem
    M secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
    M secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
    M secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
    M secure/caroot/trusted/CA_Disig_Root_R2.pem
    M secure/caroot/trusted/CFCA_EV_ROOT.pem
    M secure/caroot/trusted/COMODO_Certification_Authority.pem
    M secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
    M secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
    M secure/caroot/trusted/Certainly_Root_E1.pem
    M secure/caroot/trusted/Certainly_Root_R1.pem
    M secure/caroot/trusted/Certigna.pem
    M secure/caroot/trusted/Certigna_Root_CA.pem
    M secure/caroot/trusted/Certum_EC-384_CA.pem
    M secure/caroot/trusted/Certum_Trusted_Network_CA.pem
    M secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
    M secure/caroot/trusted/Certum_Trusted_Root_CA.pem
    M secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-01.pem
    M secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-02.pem
    M secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-01.pem
    M secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-02.pem
    M secure/caroot/trusted/Comodo_AAA_Services_root.pem
    M secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem
    M secure/caroot/trusted/D-TRUST_BR_Root_CA_2_2023.pem
    M secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem
    M secure/caroot/trusted/D-TRUST_EV_Root_CA_2_2023.pem
    M secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
    M secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
    M secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
    M secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
    M secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
    M secure/caroot/trusted/DigiCert_Global_Root_CA.pem
    M secure/caroot/trusted/DigiCert_Global_Root_G2.pem
    M secure/caroot/trusted/DigiCert_Global_Root_G3.pem
    M secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
    M secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem
    M secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem
    M secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
    M secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
    M secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
    M secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
    M secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
    M secure/caroot/trusted/FIRMAPROFESIONAL_CA_ROOT-A_WEB.pem
    M secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
    M secure/caroot/trusted/GLOBALTRUST_2020.pem
    M secure/caroot/trusted/GTS_Root_R1.pem
    M secure/caroot/trusted/GTS_Root_R2.pem
    M secure/caroot/trusted/GTS_Root_R3.pem
    M secure/caroot/trusted/GTS_Root_R4.pem
    M secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
    M secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
    M secure/caroot/trusted/GlobalSign_Root_CA.pem
    M secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
    M secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
    M secure/caroot/trusted/GlobalSign_Root_E46.pem
    M secure/caroot/trusted/GlobalSign_Root_R46.pem
    M secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
    M secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
    M secure/caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem
    M secure/caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem
    M secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
    M secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
    M secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem
    M secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
    M secure/caroot/trusted/ISRG_Root_X1.pem
    M secure/caroot/trusted/ISRG_Root_X2.pem
    M secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
    M secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
    M secure/caroot/trusted/Izenpe_com.pem
    M secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
    M secure/caroot/trusted/Microsoft_ECC_Root_Certificate_Authority_2017.pem
    M secure/caroot/trusted/Microsoft_RSA_Root_Certificate_Authority_2017.pem
    M secure/caroot/trusted/NAVER_Global_Root_Certification_Authority.pem
    M secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
    M secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
    M secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
    M secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
    M secure/caroot/trusted/QuoVadis_Root_CA_2.pem
    M secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
    M secure/caroot/trusted/QuoVadis_Root_CA_3.pem
    M secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
    M secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
    M secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
    M secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
    M secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
    M secure/caroot/trusted/SSL_com_TLS_ECC_Root_CA_2022.pem
    M secure/caroot/trusted/SSL_com_TLS_RSA_Root_CA_2022.pem
    M secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
    M secure/caroot/trusted/Sectigo_Public_Server_Authentication_Root_E46.pem
    M secure/caroot/trusted/Sectigo_Public_Server_Authentication_Root_R46.pem
    M secure/caroot/trusted/SecureSign_Root_CA12.pem
    M secure/caroot/trusted/SecureSign_Root_CA14.pem
    M secure/caroot/trusted/SecureSign_Root_CA15.pem
    M secure/caroot/trusted/SecureTrust_CA.pem
    M secure/caroot/trusted/Secure_Global_CA.pem
    M secure/caroot/trusted/Security_Communication_ECC_RootCA1.pem
    M secure/caroot/trusted/Security_Communication_RootCA2.pem
    M secure/caroot/trusted/Starfield_Class_2_CA.pem
    M secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
    M secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
    M secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
    M secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
    M secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
    M secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
    M secure/caroot/trusted/TWCA_CYBER_Root_CA.pem
    M secure/caroot/trusted/TWCA_Global_Root_CA.pem
    M secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
    M secure/caroot/trusted/Telekom_Security_TLS_ECC_Root_2020.pem
    M secure/caroot/trusted/Telekom_Security_TLS_RSA_Root_2023.pem
    M secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
    M secure/caroot/trusted/Telia_Root_CA_v2.pem
    M secure/caroot/trusted/TrustAsia_Global_Root_CA_G3.pem
    M secure/caroot/trusted/TrustAsia_Global_Root_CA_G4.pem
    M secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem
    M secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
    M secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
    M secure/caroot/trusted/TunTrust_Root_CA.pem
    M secure/caroot/trusted/UCA_Extended_Validation_Root.pem
    M secure/caroot/trusted/UCA_Global_G2_Root.pem
    M secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
    M secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
    M secure/caroot/trusted/XRamp_Global_CA_Root.pem
    M secure/caroot/trusted/certSIGN_ROOT_CA.pem
    M secure/caroot/trusted/certSIGN_Root_CA_G2.pem
    M secure/caroot/trusted/e-Szigno_Root_CA_2017.pem
    M secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
    M secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
    M secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
    M secure/caroot/trusted/emSign_Root_CA_-_C1.pem
    M secure/caroot/trusted/emSign_Root_CA_-_G1.pem
    M secure/caroot/trusted/vTrus_ECC_Root_CA.pem
    M secure/caroot/trusted/vTrus_Root_CA.pem

  Log Message:
  -----------
  caroot: Clean up

* Get certdata.txt directly from the NSS Mercurial repository, rather
  than from the Mozilla Firefox repository which imports it from NSS at
  irregular intervals.

* Instead of always fetching the latest certdata.txt, fetch a specific
  version.  For this commit, we set this to the version that was last
  imported in May 2025.

* Add a refrence to the MPL to the generated files.

* Regenerate with latest OpenSSL.  This is purely cosmetic; mostly, the
  certificate names now contain less unnecessary whitespace and some
  elements are quoted.

MFC after:	1 week
Reviewed by:	michaelo, kevans
Differential Revision:	https://reviews.freebsd.org/D56620

(cherry picked from commit ce33d6396aadb0613f1e74661bdbec571f836a60)


  Commit: 5dbfdb32d1895f54ba07ae9922406c29789376af
      https://github.com/MidnightBSD/src/commit/5dbfdb32d1895f54ba07ae9922406c29789376af
  Author: Dag-Erling Smørgrav <des at FreeBSD.org>
  Date:   2026-05-21 (Thu, 21 May 2026)

  Changed paths:
    M ObsoleteFiles.inc
    M secure/caroot/Makefile
    A secure/caroot/blacklisted/Atos_TrustedRoot_Root_CA_ECC_G2_2020.pem
    A secure/caroot/blacklisted/Atos_TrustedRoot_Root_CA_RSA_G2_2020.pem
    A secure/caroot/blacklisted/COMODO_Certification_Authority.pem
    R secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
    R secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
    A secure/caroot/blacklisted/Certigna.pem
    R secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
    A secure/caroot/blacklisted/Comodo_AAA_Services_root.pem
    A secure/caroot/blacklisted/D-Trust_SBR_Root_CA_1_2022.pem
    A secure/caroot/blacklisted/D-Trust_SBR_Root_CA_2_2022.pem
    A secure/caroot/blacklisted/DIGITALSIGN_GLOBAL_ROOT_ECDSA_CA.pem
    A secure/caroot/blacklisted/DIGITALSIGN_GLOBAL_ROOT_RSA_CA.pem
    A secure/caroot/blacklisted/DigiCert_Assured_ID_Root_CA.pem
    A secure/caroot/blacklisted/DigiCert_Global_Root_CA.pem
    A secure/caroot/blacklisted/DigiCert_High_Assurance_EV_Root_CA.pem
    A secure/caroot/blacklisted/DigiCert_SMIME_ECC_P384_Root_G5.pem
    A secure/caroot/blacklisted/DigiCert_SMIME_RSA4096_Root_G5.pem
    R secure/caroot/blacklisted/E-Tugra_Global_Root_CA_ECC_v3.pem
    R secure/caroot/blacklisted/E-Tugra_Global_Root_CA_RSA_v3.pem
    R secure/caroot/blacklisted/EC-ACC.pem
    R secure/caroot/blacklisted/EE_Certification_Centre_Root_CA.pem
    A secure/caroot/blacklisted/Entrust_Root_Certification_Authority.pem
    A secure/caroot/blacklisted/Entrust_Root_Certification_Authority_-_EC1.pem
    A secure/caroot/blacklisted/Entrust_Root_Certification_Authority_-_G2.pem
    A secure/caroot/blacklisted/Entrust_net_Premium_2048_Secure_Server_CA.pem
    A secure/caroot/blacklisted/GTS_Root_R2.pem
    R secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority.pem
    R secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G2.pem
    R secure/caroot/blacklisted/GeoTrust_Primary_Certification_Authority_-_G3.pem
    R secure/caroot/blacklisted/GeoTrust_Universal_CA.pem
    R secure/caroot/blacklisted/GeoTrust_Universal_CA_2.pem
    A secure/caroot/blacklisted/GlobalSign_Root_CA.pem
    A secure/caroot/blacklisted/GlobalSign_Secure_Mail_Root_E45.pem
    A secure/caroot/blacklisted/GlobalSign_Secure_Mail_Root_R45.pem
    R secure/caroot/blacklisted/Global_Chambersign_Root_-_2008.pem
    A secure/caroot/blacklisted/Go_Daddy_Class_2_CA.pem
    A secure/caroot/blacklisted/HARICA_Client_ECC_Root_CA_2021.pem
    A secure/caroot/blacklisted/HARICA_Client_RSA_Root_CA_2021.pem
    R secure/caroot/blacklisted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
    A secure/caroot/blacklisted/LAWtrust_Root_CA2__4096_.pem
    R secure/caroot/blacklisted/LuxTrust_Global_Root_2.pem
    R secure/caroot/blacklisted/Network_Solutions_Certificate_Authority.pem
    A secure/caroot/blacklisted/OISTE_Client_Root_ECC_G1.pem
    A secure/caroot/blacklisted/OISTE_Client_Root_RSA_G1.pem
    A secure/caroot/blacklisted/QuoVadis_Root_CA_2.pem
    A secure/caroot/blacklisted/QuoVadis_Root_CA_3.pem
    A secure/caroot/blacklisted/SSL_com_Client_ECC_Root_CA_2022.pem
    A secure/caroot/blacklisted/SSL_com_Client_RSA_Root_CA_2022.pem
    A secure/caroot/blacklisted/Sectigo_Public_Email_Protection_Root_E46.pem
    A secure/caroot/blacklisted/Sectigo_Public_Email_Protection_Root_R46.pem
    R secure/caroot/blacklisted/SecureSign_RootCA11.pem
    R secure/caroot/blacklisted/Security_Communication_RootCA3.pem
    A secure/caroot/blacklisted/Starfield_Class_2_CA.pem
    A secure/caroot/blacklisted/SwissSign_Gold_CA_-_G2.pem
    R secure/caroot/blacklisted/SwissSign_Platinum_CA_-_G2.pem
    A secure/caroot/blacklisted/SwissSign_RSA_SMIME_Root_CA_2022_-_1.pem
    R secure/caroot/blacklisted/SwissSign_Silver_CA_-_G2.pem
    R secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
    R secure/caroot/blacklisted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
    R secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
    R secure/caroot/blacklisted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
    A secure/caroot/blacklisted/TWCA_Global_Root_CA_G2.pem
    R secure/caroot/blacklisted/Taiwan_GRCA.pem
    A secure/caroot/blacklisted/Telekom_Security_SMIME_ECC_Root_2021.pem
    A secure/caroot/blacklisted/Telekom_Security_SMIME_RSA_Root_2023.pem
    A secure/caroot/blacklisted/TrustAsia_SMIME_ECC_Root_CA.pem
    A secure/caroot/blacklisted/TrustAsia_SMIME_RSA_Root_CA.pem
    R secure/caroot/blacklisted/TrustCor_ECA-1.pem
    R secure/caroot/blacklisted/TrustCor_RootCert_CA-1.pem
    R secure/caroot/blacklisted/TrustCor_RootCert_CA-2.pem
    R secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
    R secure/caroot/blacklisted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
    R secure/caroot/blacklisted/VeriSign_Universal_Root_Certification_Authority.pem
    R secure/caroot/blacklisted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
    R secure/caroot/blacklisted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
    R secure/caroot/blacklisted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
    R secure/caroot/blacklisted/thawte_Primary_Root_CA.pem
    R secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G2.pem
    R secure/caroot/blacklisted/thawte_Primary_Root_CA_-_G3.pem
    R secure/caroot/trusted/AffirmTrust_Commercial.pem
    R secure/caroot/trusted/AffirmTrust_Networking.pem
    R secure/caroot/trusted/AffirmTrust_Premium.pem
    R secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
    R secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
    R secure/caroot/trusted/COMODO_Certification_Authority.pem
    R secure/caroot/trusted/Certigna.pem
    R secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-01.pem
    R secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-02.pem
    R secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-01.pem
    R secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-02.pem
    R secure/caroot/trusted/Comodo_AAA_Services_root.pem
    R secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
    R secure/caroot/trusted/DigiCert_Global_Root_CA.pem
    R secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
    R secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
    R secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
    R secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
    R secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
    R secure/caroot/trusted/FIRMAPROFESIONAL_CA_ROOT-A_WEB.pem
    R secure/caroot/trusted/GLOBALTRUST_2020.pem
    R secure/caroot/trusted/GTS_Root_R2.pem
    R secure/caroot/trusted/GlobalSign_Root_CA.pem
    R secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
    A secure/caroot/trusted/OISTE_Server_Root_ECC_G1.pem
    A secure/caroot/trusted/OISTE_Server_Root_RSA_G1.pem
    R secure/caroot/trusted/QuoVadis_Root_CA_2.pem
    R secure/caroot/trusted/QuoVadis_Root_CA_3.pem
    R secure/caroot/trusted/SecureTrust_CA.pem
    R secure/caroot/trusted/Secure_Global_CA.pem
    R secure/caroot/trusted/Starfield_Class_2_CA.pem
    R secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
    A secure/caroot/trusted/SwissSign_RSA_TLS_Root_CA_2022_-_1.pem
    R secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
    A secure/caroot/trusted/TrustAsia_TLS_ECC_Root_CA.pem
    A secure/caroot/trusted/TrustAsia_TLS_RSA_Root_CA.pem
    R secure/caroot/trusted/Trustwave_Global_Certification_Authority.pem
    R secure/caroot/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
    R secure/caroot/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
    R secure/caroot/trusted/XRamp_Global_CA_Root.pem
    R secure/caroot/trusted/certSIGN_ROOT_CA.pem
    A secure/caroot/trusted/e-Szigno_TLS_Root_CA_2023.pem

  Log Message:
  -----------
  caroot: Regenerate

Regenerate using certificate data from NSS 3.123.1.

MFC after:	1 week
Reviewed by:	kevans

(cherry picked from commit 07b52233e8b74c5ac884b9c9a894f57fad8dbd00)


Compare: https://github.com/MidnightBSD/src/compare/eaf000bc584f...5dbfdb32d189

To unsubscribe from these emails, change your notification settings at https://github.com/MidnightBSD/src/settings/notifications



More information about the Midnightbsd-cvs mailing list