-
Tue Jun 09 2020 Bob Relyea <rrelyea@redhat.com> - 2020.2.41-70.0
- Update to CKBI 2.41 from NSS 3.53.0
- Removing:
- # Certificate "AddTrust Low-Value Services Root"
- # Certificate "AddTrust External Root"
- # Certificate "UTN USERFirst Email Root CA"
- # Certificate "Certplus Class 2 Primary CA"
- # Certificate "Deutsche Telekom Root CA 2"
- # Certificate "Staat der Nederlanden Root CA - G2"
- # Certificate "Swisscom Root CA 2"
- # Certificate "Certinomis - Root CA"
- Adding:
- # Certificate "Entrust Root Certification Authority - G4"
- fix permissions on ghosted files.
-
Fri Jun 21 2019 Bob Relyea <rrelyea@redhat.com> - 2019.2.32-76
- Update to CKBI 2.32 from NSS 3.44
- Removing:
- # Certificate "Visa eCommerce Root"
- # Certificate "AC Raiz Certicamara S.A."
- # Certificate "TC TrustCenter Class 3 CA II"
- # Certificate "ComSign CA"
- # Certificate "S-TRUST Universal Root CA"
- # Certificate "TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5"
- # Certificate "Certplus Root CA G1"
- # Certificate "Certplus Root CA G2"
- # Certificate "OpenTrust Root CA G1"
- # Certificate "OpenTrust Root CA G2"
- # Certificate "OpenTrust Root CA G3"
- Adding:
- # Certificate "GlobalSign Root CA - R6"
- # Certificate "OISTE WISeKey Global Root GC CA"
- # Certificate "GTS Root R1"
- # Certificate "GTS Root R2"
- # Certificate "GTS Root R3"
- # Certificate "GTS Root R4"
- # Certificate "UCA Global G2 Root"
- # Certificate "UCA Extended Validation Root"
- # Certificate "Certigna Root CA"
- # Certificate "emSign Root CA - G1"
- # Certificate "emSign ECC Root CA - G3"
- # Certificate "emSign Root CA - C1"
- # Certificate "emSign ECC Root CA - C3"
- # Certificate "Hongkong Post Root CA 3"
-
Wed Mar 14 2018 Kai Engert <kaie@redhat.com> - 2018.2.22-70.0
- Update to CKBI 2.22 from NSS 3.35
-
Wed Nov 29 2017 Kai Engert <kaie@redhat.com> - 2017.2.20-71
- Update to CKBI 2.20 from NSS 3.34.1
-
Thu Oct 26 2017 Kai Engert <kaie@redhat.com> - 2017.2.18-71
- Update to CKBI 2.18 (pre-release snapshot)
-
Tue Sep 26 2017 Kai Engert <kaie@redhat.com> - 2017.2.16-71
- Update to CKBI 2.16 from NSS 3.32. In addition to removals/additions,
Mozilla removed code signing trust from all CAs (rhbz#1472933)
-
Fri Apr 28 2017 Kai Engert <kaie@redhat.com> - 2017.2.14-71
- Update to CKBI 2.14 from NSS 3.30.2
-
Fri Mar 10 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-73
- No longer trust legacy CAs
-
Fri Mar 10 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-72
- Changed the packaged bundle to use the flexible p11-kit-object-v1 file format,
as a preparation to fix bugs in the interaction between p11-kit-trust and
Mozilla applications, such as Firefox, Thunderbird etc.
- For CAs trusted by Mozilla, set attribute nss-mozilla-ca-policy: true
- Require p11-kit 0.23.5
- Added an utility to help with comparing output of the trust dump command.
-
Tue Jan 17 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-71
- Update to CKBI 2.11 from NSS 3.28.1 with legacy modifications.
- Use comments in extracted bundle files.
- Change packaging script to support empty legacy bundles.