Information for build ca-certificates-2021.2.50-80.0.oc8

ID478
Package Nameca-certificates
Version2021.2.50
Release80.0.oc8
Epoch
Sourceca-certificates-2021.2.50-80.0.oc8.src.rpm
SummaryThe Mozilla CA root certificate bundle
DescriptionThis package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI.
Built byopencloudkoji
State complete
Volume DEFAULT
StartedThu, 26 May 2022 21:33:24 CST
CompletedThu, 26 May 2022 21:35:04 CST
Taskbuild (dist-oc8, ca-certificates-2021.2.50-80.0.el8_4.src.rpm)
Extra{'source': {'original_url': 'ca-certificates-2021.2.50-80.0.oc8.src.rpm'}}
Tags
dist-oc8
dist-oc8-compose
RPMs
src
ca-certificates-2021.2.50-80.0.oc8.src.rpm (info) (download)
noarch
ca-certificates-2021.2.50-80.0.oc8.noarch.rpm (info) (download)
Logs
noarch
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
Changelog * Wed Jun 16 2021 Bob Relyea <rrelyea@redhat.com> - 2021.2.50-80.0 - Update to CKBI 2.50 from NSS 3.67 - version number update only * Fri Jun 11 2021 Bob Relyea <rrelyea@redhat.com> - 2021.2.48-80.0 - Update to CKBI 2.48 from NSS 3.66 - Removing: - # Certificate "Verisign Class 3 Public Primary Certification Authority - G3" - # Certificate "GeoTrust Global CA" - # Certificate "GeoTrust Universal CA" - # Certificate "GeoTrust Universal CA 2" - # Certificate "QuoVadis Root CA" - # Certificate "Sonera Class 2 Root CA" - # Certificate "Taiwan GRCA" - # Certificate "GeoTrust Primary Certification Authority" - # Certificate "thawte Primary Root CA" - # Certificate "VeriSign Class 3 Public Primary Certification Authority - G5" - # Certificate "GeoTrust Primary Certification Authority - G3" - # Certificate "thawte Primary Root CA - G2" - # Certificate "thawte Primary Root CA - G3" - # Certificate "GeoTrust Primary Certification Authority - G2" - # Certificate "VeriSign Universal Root Certification Authority" - # Certificate "VeriSign Class 3 Public Primary Certification Authority - G4" - # Certificate "Trustis FPS Root CA" - # Certificate "EE Certification Centre Root CA" - # Certificate "LuxTrust Global Root 2" - # Certificate "Symantec Class 1 Public Primary Certification Authority - G4" - # Certificate "Symantec Class 2 Public Primary Certification Authority - G4" - Adding: - # Certificate "Microsoft ECC Root Certificate Authority 2017" - # Certificate "Microsoft RSA Root Certificate Authority 2017" - # Certificate "e-Szigno Root CA 2017" - # Certificate "certSIGN Root CA G2" - # Certificate "Trustwave Global Certification Authority" - # Certificate "Trustwave Global ECC P256 Certification Authority" - # Certificate "Trustwave Global ECC P384 Certification Authority" - # Certificate "NAVER Global Root Certification Authority" - # Certificate "AC RAIZ FNMT-RCM SERVIDORES SEGUROS" - # Certificate "GlobalSign Secure Mail Root R45" - # Certificate "GlobalSign Secure Mail Root E45" - # Certificate "GlobalSign Root R46" - # Certificate "GlobalSign Root E46" - # Certificate "GLOBALTRUST 2020" - # Certificate "ANF Secure Server Root CA" - # Certificate "Certum EC-384 CA" - # Certificate "Certum Trusted Root CA" * Wed Jun 17 2020 Bob Relyea <rrelyea@redhat.com> - 2020.2.41-82 - fix post issues * Wed Jun 10 2020 Bob Relyea <rrelyea@redhat.com> - 2020.2.41-81 - Update to CKBI 2.41 from NSS 3.53.0 - Removing: - # Certificate "AddTrust Low-Value Services Root" - # Certificate "AddTrust External Root" - # Certificate "UTN USERFirst Email Root CA" - # Certificate "Certplus Class 2 Primary CA" - # Certificate "Deutsche Telekom Root CA 2" - # Certificate "Staat der Nederlanden Root CA - G2" - # Certificate "Swisscom Root CA 2" - # Certificate "Certinomis - Root CA" - Adding: - # Certificate "Entrust Root Certification Authority - G4" * Fri Jun 21 2019 Bob Relyea <rrelyea@redhat.com> - 2019.2.32-1 - Update to CKBI 2.32 from NSS 3.44 - Removing: - # Certificate "Visa eCommerce Root" - # Certificate "AC Raiz Certicamara S.A." - # Certificate "ComSign CA" - # Certificate "Certplus Root CA G1" - # Certificate "Certplus Root CA G2" - # Certificate "OpenTrust Root CA G1" - # Certificate "OpenTrust Root CA G2" - # Certificate "OpenTrust Root CA G3" - Adding: - # Certificate "GlobalSign Root CA - R6" - # Certificate "OISTE WISeKey Global Root GC CA" - # Certificate "GTS Root R1" - # Certificate "GTS Root R2" - # Certificate "GTS Root R3" - # Certificate "GTS Root R4" - # Certificate "UCA Global G2 Root" - # Certificate "UCA Extended Validation Root" - # Certificate "Certigna Root CA" - # Certificate "emSign Root CA - G1" - # Certificate "emSign ECC Root CA - G3" - # Certificate "emSign Root CA - C1" - # Certificate "emSign ECC Root CA - C3" - # Certificate "Hongkong Post Root CA 3" * Fri May 10 2019 Robert Relyea <rrelyea@redhat.com> - 2018.2.24-6.1 - Test gating * Mon Aug 13 2018 Tomáš Mráz <tmraz@redhat.com> - 2018.2.24-6 - Use __python3 macro when invoking Python * Thu Jun 28 2018 Kai Engert <kaie@redhat.com> - 2018.2.24-5 - Ported scripts to python3 * Mon Jun 11 2018 Daiki Ueno <dueno@redhat.com> - 2018.2.24-4 - Extract certificate bundle in EDK2 format, suggested by Laszlo Ersek * Mon Jun 04 2018 Kai Engert <kaie@redhat.com> - 2018.2.24-3 - Adjust ghost file permissions, rhbz#1564432 * Fri May 18 2018 Kai Engert <kaie@redhat.com> - 2018.2.24-2 - Update to CKBI 2.24 from NSS 3.37 * Wed Mar 14 2018 Iryna Shcherbina <ishcherb@redhat.com> - 2018.2.22-4 - Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3) * Fri Feb 23 2018 Patrick Uiterwijk <puiterwijk@redhat.com> - 2018.2.22-3 - Add post dep on coreutils for ln(1) * Tue Feb 06 2018 Kai Engert <kaie@redhat.com> - 2018.2.22-2 - Update to CKBI 2.22 from NSS 3.35 * Mon Jan 22 2018 Kai Engert <kaie@redhat.com> - 2017.2.20-6 - Depend on bash, grep, sed. Required for ca-legacy script execution. - p11-kit is already required at %post execution time. (rhbz#1537127) * Fri Jan 19 2018 Kai Engert <kaie@redhat.com> - 2017.2.20-5 - Use the force, script! (Which sln did by default). * Fri Jan 19 2018 Kai Engert <kaie@redhat.com> - 2017.2.20-4 - stop using sln in ca-legacy script. * Fri Jan 19 2018 Kai Engert <kaie@redhat.com> - 2017.2.20-3 - Use ln -s, because sln was removed from glibc. rhbz#1536349 * Mon Nov 27 2017 Kai Engert <kaie@redhat.com> - 2017.2.20-2 - Update to CKBI 2.20 from NSS 3.34.1 * Tue Aug 15 2017 Kai Engert <kaie@redhat.com> - 2017.2.16-4 - Set P11_KIT_NO_USER_CONFIG=1 to prevent p11-kit from reading user configuration files (rhbz#1478172). * Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 2017.2.16-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Wed Jul 19 2017 Kai Engert <kaie@redhat.com> - 2017.2.16-2 - Update to (yet unreleased) CKBI 2.16 which is planned for NSS 3.32. Mozilla removed all trust bits for code signing. * Wed Apr 26 2017 Kai Engert <kaie@redhat.com> - 2017.2.14-2 - Update to CKBI 2.14 from NSS 3.30.2 * Thu Feb 23 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-5 - For CAs trusted by Mozilla, set attribute nss-mozilla-ca-policy: true - Set attribute modifiable: false - Require p11-kit 0.23.4 * Mon Feb 13 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-4 - Changed the packaged bundle to use the flexible p11-kit-object-v1 file format, as a preparation to fix bugs in the interaction between p11-kit-trust and Mozilla applications, such as Firefox, Thunderbird etc. - Changed update-ca-trust to add comments to extracted PEM format files. - Added an utility to help with comparing output of the trust dump command. * Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 2017.2.11-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Wed Jan 11 2017 Kai Engert <kaie@redhat.com> - 2017.2.11-2 - Update to CKBI 2.11 from NSS 3.28.1 * Thu Sep 29 2016 Kai Engert <kaie@redhat.com> - 2016.2.10-2 - Update to CKBI 2.10 from NSS 3.27 * Tue Aug 16 2016 Kai Engert <kaie@redhat.com> - 2016.2.9-3 - Revert to the unmodified upstream CA list, changing the legacy trust to an empty list. Keeping the ca-legacy tool and existing config, however, the configuration has no effect after this change. * Tue Aug 16 2016 Kai Engert <kaie@redhat.com> - 2016.2.9-2 - Update to CKBI 2.9 from NSS 3.26 with legacy modifications * Fri Jul 15 2016 Kai Engert <kaie@redhat.com> - 2016.2.8-2 - Update to CKBI 2.8 from NSS 3.25 with legacy modifications * Tue May 10 2016 Kai Engert <kaie@redhat.com> - 2016.2.7-5 - Only create backup files if there is an original file (bug 999017). * Tue May 10 2016 Kai Engert <kaie@redhat.com> - 2016.2.7-4 - Use sln, not ln, to avoid the dependency on coreutils. * Mon Apr 25 2016 Kai Engert <kaie@redhat.com> - 2016.2.7-3 - Fix typos in a manual page and in a README file. * Wed Mar 16 2016 Kai Engert <kaie@redhat.com> - 2016.2.7-2 - Update to CKBI 2.7 from NSS 3.23 with legacy modifications * Wed Feb 03 2016 Fedora Release Engineering <releng@fedoraproject.org> - 2015.2.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Mon Nov 23 2015 Kai Engert <kaie@redhat.com> - 2015.2.6-2 - Update to CKBI 2.6 from NSS 3.21 with legacy modifications * Thu Aug 13 2015 Kai Engert <kaie@redhat.com> - 2015.2.5-2 - Update to CKBI 2.5 from NSS 3.19.3 with legacy modifications * Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2015.2.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Tue May 05 2015 Kai Engert <kaie@redhat.com> - 2015.2.4-2 - Update to CKBI 2.4 from NSS 3.18.1 with legacy modifications * Tue May 05 2015 Kai Engert <kaie@redhat.com> - 2015.2.3-4 - Fixed a typo in the ca-legacy manual page. * Tue Mar 31 2015 Kai Engert <kaie@redhat.com> - 2015.2.3-3 - Don't use "enable" as a value for the legacy configuration, instead of the value "default", to make it clear that this preference isn't a promise to keep certificates enabled, but rather that we only keep them enabled as long as it's considered necessary. - Changed the configuration file, the ca-legacy utility and filenames to use the term "default" (instead of the term "enable"). - Added a manual page for the ca-legacy utility. - Fixed the ca-legacy utility to handle absence of the configuration setting and treat absence as the default setting. * Fri Mar 20 2015 Kai Engert <kaie@redhat.com> - 2015.2.3-2 - Update to CKBI 2.3 from NSS 3.18 with legacy modifications - Fixed a mistake in the legacy handling of the upstream 2.2 release: Removed two AOL certificates from the legacy group, because upstream didn't remove them as part of phasing out 1024-bit certificates, which means it isn't necessary to keep them. - Fixed a mistake in the legacy handling of the upstream 2.1 release: Moved two NetLock certificates into the legacy group. * Tue Dec 16 2014 Kai Engert <kaie@redhat.com> - 2014.2.2-2 - Update to CKBI 2.2 from NSS 3.17.3 with legacy modifications - Update project URL - Cleanup * Sat Nov 15 2014 Peter Lemenkov <lemenkov@gmail.com> - 2014.2.1-7 - Restore Requires: coreutils * Fri Nov 14 2014 Peter Lemenkov <lemenkov@gmail.com> - 2014.2.1-6 - A proper fix for rhbz#1158343 * Wed Oct 29 2014 Kai Engert <kaie@redhat.com> - 2014.2.1-5 - add Requires: coreutils (rhbz#1158343) * Tue Oct 28 2014 Kai Engert <kaie@redhat.com> - 2014.2.1-4 - Introduce the ca-legacy utility and a ca-legacy.conf configuration file. By default, legacy roots required for OpenSSL/GnuTLS compatibility are kept enabled. Using the ca-legacy utility, the legacy roots can be disabled. If disabled, the system will use the trust set as provided by the upstream Mozilla CA list. (See also: rhbz#1158197) * Sun Sep 21 2014 Kai Engert <kaie@redhat.com> - 2014.2.1-3 - Temporarily re-enable several legacy root CA certificates because of compatibility issues with software based on OpenSSL/GnuTLS, see rhbz#1144808 * Thu Aug 14 2014 Kai Engert <kaie@redhat.com> - 2014.2.1-2 - Update to CKBI 2.1 from NSS 3.16.4 - Fix rhbz#1130226 * Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2013.1.97-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Wed Mar 19 2014 Kai Engert <kaie@redhat.com> - 2013.1.97-2 - Update to CKBI 1.97 from NSS 3.16 * Mon Feb 10 2014 Kai Engert <kaie@redhat.com> - 2013.1.96-3 - Remove openjdk build dependency * Sat Jan 25 2014 Ville Skyttä <ville.skytta@iki.fi> - 2013.1.96-2 - Own the %{_datadir}/pki dir. * Thu Jan 09 2014 Kai Engert <kaie@redhat.com> - 2013.1.96-1 - Update to CKBI 1.96 from NSS 3.15.4 * Tue Dec 17 2013 Kai Engert <kaie@redhat.com> - 2013.1.95-1 - Update to CKBI 1.95 from NSS 3.15.3.1 * Fri Sep 06 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-18 - Update the Entrust root stapled extension for compatibility with p11-kit version 0.19.2, patch by Stef Walter, rhbz#988745 * Tue Sep 03 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-17 - merge manual improvement from f19 * Sat Aug 03 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2013.1.94-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Tue Jul 09 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-15 - clarification updates to manual page * Mon Jul 08 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-14 - added a manual page and related build requirements - simplify the README files now that we have a manual page - set a certificate alias in trusted bundle (thanks to Ludwig Nussel) * Mon May 27 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-13 - use correct command in README files, rhbz#961809 * Mon May 27 2013 Kai Engert <kaie@redhat.com> - 2013.1.94-12 - update to version 1.94 provided by NSS 3.15 (beta) * Mon Apr 22 2013 Kai Engert <kaie@redhat.com> - 2012.87-12 - Use both label and serial to identify cert during conversion, rhbz#927601 - Add myself as contributor to certdata2.pem.py and remove use of rcs/ident. (thanks to Michael Shuler for suggesting to do so) - Update source URLs and comments, add source file for version information. * Tue Mar 19 2013 Kai Engert <kaie@redhat.com> - 2012.87-11 - adjust to changed and new functionality provided by p11-kit 0.17.3 - updated READMEs to describe the new directory-specific treatment of files - ship a new file that contains certificates with neutral trust - ship a new file that contains distrust objects, and also staple a basic constraint extension to one legacy root contained in the Mozilla CA list - adjust the build script to dynamically produce most of above files - add and own the anchors and blacklist subdirectories - file generate-cacerts.pl is no longer required * Fri Mar 08 2013 Kai Engert <kaie@redhat.com> - 2012.87-9 - Major rework for the Fedora SharedSystemCertificates feature. - Only ship a PEM bundle file using the BEGIN TRUSTED CERTIFICATE file format. - Require the p11-kit package that contains tools to automatically create other file format bundles. - Convert old file locations to symbolic links that point to dynamically generated files. - Old files, which might have been locally modified, will be saved in backup files with .rpmsave extension. - Added a update-ca-certificates script which can be used to regenerate the merged trusted output. - Refer to the various README files that have been added for more detailed explanation of the new system. - No longer require rsc for building. - Add explanation for the future version numbering scheme, because the old numbering scheme was based on upstream using cvs, which is no longer true, and therefore can no longer be used. - Includes changes from rhbz#873369. * Thu Mar 07 2013 Kai Engert <kaie@redhat.com> - 2012.87-2.fc19.1 - Ship trust bundle file in /usr/share/pki/ca-trust-source/, temporarily in addition. This location will soon become the only place containing this file. * Wed Feb 13 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2012.87-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild * Fri Jan 04 2013 Paul Wouters <pwouters@redhat.com> - 2012.87-1 - Updated to r1.87 to blacklist mis-issued turktrust CA certs * Wed Oct 24 2012 Paul Wouters <pwouters@redhat.com> - 2012.86-2 - Updated blacklist with 20 entries (Diginotar, Trustwave, Comodo(?) - Fix to certdata2pem.py to also check for CKT_NSS_NOT_TRUSTED * Tue Oct 23 2012 Paul Wouters <pwouters@redhat.com> - 2012.86-1 - update to r1.86 * Mon Jul 23 2012 Joe Orton <jorton@redhat.com> - 2012.85-2 - add openssl to BuildRequires * Mon Jul 23 2012 Joe Orton <jorton@redhat.com> - 2012.85-1 - update to r1.85 * Wed Jul 18 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2012.81-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Mon Feb 13 2012 Joe Orton <jorton@redhat.com> - 2012.81-1 - update to r1.81 * Thu Jan 12 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2011.80-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild * Wed Nov 09 2011 Joe Orton <jorton@redhat.com> - 2011.80-1 - update to r1.80 - fix handling of certs with dublicate Subject names (#733032) * Thu Sep 01 2011 Joe Orton <jorton@redhat.com> - 2011.78-1 - update to r1.78, removing trust from DigiNotar root (#734679) * Wed Aug 03 2011 Joe Orton <jorton@redhat.com> - 2011.75-1 - update to r1.75 * Wed Apr 20 2011 Joe Orton <jorton@redhat.com> - 2011.74-1 - update to r1.74 * Tue Feb 08 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2011.70-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Wed Jan 12 2011 Joe Orton <jorton@redhat.com> - 2011.70-1 - update to r1.70 * Tue Nov 09 2010 Joe Orton <jorton@redhat.com> - 2010.65-3 - update to r1.65 * Wed Apr 07 2010 Joe Orton <jorton@redhat.com> - 2010.63-3 - package /etc/ssl/certs symlink for third-party apps (#572725) * Wed Apr 07 2010 Joe Orton <jorton@redhat.com> - 2010.63-2 - rebuild * Wed Apr 07 2010 Joe Orton <jorton@redhat.com> - 2010.63-1 - update to certdata.txt r1.63 - use upstream RCS version in Version * Fri Mar 19 2010 Joe Orton <jorton@redhat.com> - 2010-4 - fix ca-bundle.crt (#575111) * Thu Mar 18 2010 Joe Orton <jorton@redhat.com> - 2010-3 - update to certdata.txt r1.58 - add /etc/pki/tls/certs/ca-bundle.trust.crt using 'TRUSTED CERTICATE' format - exclude ECC certs from the Java cacerts database - catch keytool failures - fail parsing certdata.txt on finding untrusted but not blacklisted cert * Fri Jan 15 2010 Joe Orton <jorton@redhat.com> - 2010-2 - fix Java cacert database generation: use Subject rather than Issuer for alias name; add diagnostics; fix some alias names. * Mon Jan 11 2010 Joe Orton <jorton@redhat.com> - 2010-1 - adopt Python certdata.txt parsing script from Debian * Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2009-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Wed Jul 22 2009 Joe Orton <jorton@redhat.com> 2009-1 - update to certdata.txt r1.53 * Mon Feb 23 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2008-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Tue Oct 14 2008 Joe Orton <jorton@redhat.com> 2008-7 - update to certdata.txt r1.49 * Wed Jun 25 2008 Thomas Fitzsimmons <fitzsim@redhat.com> - 2008-6 - Change generate-cacerts.pl to produce pretty aliases. * Mon Jun 02 2008 Joe Orton <jorton@redhat.com> 2008-5 - include /etc/pki/tls/cert.pem symlink to ca-bundle.crt * Tue May 27 2008 Joe Orton <jorton@redhat.com> 2008-4 - use package name for temp dir, recreate it in prep * Tue May 27 2008 Joe Orton <jorton@redhat.com> 2008-3 - fix source script perms - mark packaged files as config(noreplace) * Tue May 27 2008 Joe Orton <jorton@redhat.com> 2008-2 - add (but don't use) mkcabundle.pl - tweak description - use /usr/bin/keytool directly; BR java-openjdk * Tue May 27 2008 Joe Orton <jorton@redhat.com> 2008-1 - Initial build (#448497)