<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto/cert.pem, branch OPENBSD_7_9</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_7_9</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_7_9'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2026-03-18T21:50:06+00:00</updated>
<entry>
<title>sync with Mozilla root CA store, ok tb@</title>
<updated>2026-03-18T21:50:06+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2026-03-18T21:50:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=80318abdaa00a71f2fb14771bf4222c73b975fff'/>
<id>urn:sha1:80318abdaa00a71f2fb14771bf4222c73b975fff</id>
<content type='text'>
- remove CommScope CA (they requested it themselves;
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866)

- add new cert:
/C=HU/L=Budapest/O=Microsec Ltd./2.5.4.97=VATHU-23584497/CN=e-Szigno TLS Root CA 2023
</content>
</entry>
<entry>
<title>sync cert.pem with updated Mozilla list; ok tb@</title>
<updated>2025-11-17T20:15:35+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2025-11-17T20:15:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=489ae508803e6c32fbcbf76aa1daebeefeb53477'/>
<id>urn:sha1:489ae508803e6c32fbcbf76aa1daebeefeb53477</id>
<content type='text'>
changes are:

+OISTE Foundation
+  /C=CH/O=OISTE Foundation/CN=OISTE Server Root ECC G1
+  /C=CH/O=OISTE Foundation/CN=OISTE Server Root RSA G1

 SwissSign AG
   /C=CH/O=SwissSign AG/CN=SwissSign Gold CA - G2
+  /C=CH/O=SwissSign AG/CN=SwissSign RSA TLS Root CA 2022 - 1

 TrustAsia Technologies, Inc.
   /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia Global Root CA G3
   /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia Global Root CA G4
+  /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia TLS ECC Root CA
+  /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia TLS RSA Root CA
</content>
</entry>
<entry>
<title>sync CA certificates from newer mozilla list, ok tb@</title>
<updated>2025-08-06T09:45:53+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2025-08-06T09:45:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7f1c71331199c4470a5778b8e97607290e406e88'/>
<id>urn:sha1:7f1c71331199c4470a5778b8e97607290e406e88</id>
<content type='text'>
https://raw.githubusercontent.com/mozilla-firefox/firefox/refs/heads/release/security/nss/lib/ckfw/builtins/certdata.txt
SHA256 (certdata.txt) = 579f336ace2e5717b8ecc06002ce0cce96f70623d188e1999c34b0f77696d3e9

Removals:

-  /C=IE/O=Baltimore/OU=CyberTrust/CN=Baltimore CyberTrust Root
-  /C=GB/ST=Greater Manchester/L=Salford/O=Comodo CA Limited/CN=AAA Certificate Services
-  /O=Entrust.net/OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)/OU=(c) 1999 Entrust.net Limited/CN=Entrust.net Certification Authority (2048)
-  /C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA
-  /C=US/O=Starfield Technologies, Inc./OU=Starfield Class 2 Certification Authority
-  /C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority
-  /C=US/OU=www.xrampsecurity.com/O=XRamp Security Services Inc/CN=XRamp Global Certification Authority

Addition:

+  /C=PL/O=Unizeto Technologies S.A./OU=Certum Certification Authority/CN=Certum Trusted Network CA 2
</content>
</entry>
<entry>
<title>Update cert.pem, ok sthen</title>
<updated>2025-03-16T07:44:35+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2025-03-16T07:44:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2bd4b5e63f49e724170a2adad15a615ed2a24274'/>
<id>urn:sha1:2bd4b5e63f49e724170a2adad15a615ed2a24274</id>
<content type='text'>
Added to existing CA

  /C=DE/O=D-Trust GmbH/CN=D-TRUST BR Root CA 2 2023
  /C=DE/O=D-Trust GmbH/CN=D-TRUST EV Root CA 2 2023

Added back:

  /C=AT/O=e-commerce monitoring GmbH/CN=GLOBALTRUST 2020

Deleted:

  /C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2015 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - G4
  /C=JP/O=Japan Certification Services, Inc./CN=SecureSign RootCA11
  /C=JP/O=SECOM Trust Systems CO.,LTD./CN=Security Communication RootCA3
  /C=CH/O=SwissSign AG/CN=SwissSign Silver CA - G2
</content>
</entry>
<entry>
<title>Update cert.pem, ok sthen</title>
<updated>2024-11-01T11:30:12+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-11-01T11:30:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3c32f5d82eb2e59b3a6ca0165691cdceca0d8357'/>
<id>urn:sha1:3c32f5d82eb2e59b3a6ca0165691cdceca0d8357</id>
<content type='text'>
New:

CommScope
  /C=US/O=CommScope/CN=CommScope Public Trust ECC Root-01
  /C=US/O=CommScope/CN=CommScope Public Trust ECC Root-02
  /C=US/O=CommScope/CN=CommScope Public Trust RSA Root-01
  /C=US/O=CommScope/CN=CommScope Public Trust RSA Root-02
Cybertrust Japan Co., Ltd.
  /C=JP/O=Cybertrust Japan Co., Ltd./CN=SecureSign Root CA12
  /C=JP/O=Cybertrust Japan Co., Ltd./CN=SecureSign Root CA14
  /C=JP/O=Cybertrust Japan Co., Ltd./CN=SecureSign Root CA15
Deutsche Telekom Security GmbH
  /C=DE/O=Deutsche Telekom Security GmbH/CN=Telekom Security TLS ECC Root 2020
  /C=DE/O=Deutsche Telekom Security GmbH/CN=Telekom Security TLS RSA Root 2023
Firmaprofesional SA
  /C=ES/O=Firmaprofesional SA/2.5.4.97=VATES-A62634068/CN=FIRMAPROFESIONAL CA ROOT-A WEB
TrustAsia Technologies, Inc.
  /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia Global Root CA G3
  /C=CN/O=TrustAsia Technologies, Inc./CN=TrustAsia Global Root CA G4

Added to existing:

  /C=TW/O=TAIWAN-CA/OU=Root CA/CN=TWCA CYBER Root CA

Deleted:

e-commerce monitoring GmbH
  /C=AT/O=e-commerce monitoring GmbH/CN=GLOBALTRUST 2020
</content>
</entry>
<entry>
<title>regen cert.pem after sort order change in format-pem.pl</title>
<updated>2024-11-01T11:23:27+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-11-01T11:23:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a3d1e4f268cfe9c937b4fa09beda6f32b0f5bb8f'/>
<id>urn:sha1:a3d1e4f268cfe9c937b4fa09beda6f32b0f5bb8f</id>
<content type='text'>
ok sthen
</content>
</entry>
<entry>
<title>Regen cert.pem</title>
<updated>2023-11-27T21:44:21+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-11-27T21:44:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=ea92f31dc14ec1875abcb00d9af9fe8aac0692ce'/>
<id>urn:sha1:ea92f31dc14ec1875abcb00d9af9fe8aac0692ce</id>
<content type='text'>
ok sthen

New Roots for existing CA:
  /CN=Atos TrustedRoot Root CA ECC TLS 2021/O=Atos/C=DE
  /CN=Atos TrustedRoot Root CA RSA TLS 2021/O=Atos/C=DE

New CA:
BEIJING CERTIFICATE AUTHORITY
  /C=CN/O=BEIJING CERTIFICATE AUTHORITY/CN=BJCA Global Root CA1
  /C=CN/O=BEIJING CERTIFICATE AUTHORITY/CN=BJCA Global Root CA2

Two E-Tugra roots were removed due to a breach:
  /C=TR/L=Ankara/O=E-Tugra EBG A.S./OU=E-Tugra Trust Center/CN=E-Tugra Global Root CA ECC v3
  /C=TR/L=Ankara/O=E-Tugra EBG A.S./OU=E-Tugra Trust Center/CN=E-Tugra Global Root CA RSA v3
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A

Removed expired root:
  /C=HK/O=Hongkong Post/CN=Hongkong Post Root CA 1

Removed expired CA:
SECOM Trust.net
  /C=JP/O=SECOM Trust.net/OU=Security Communication RootCA1

New CA:
Sectigo Limited
  /C=GB/O=Sectigo Limited/CN=Sectigo Public Server Authentication Root E46
  /C=GB/O=Sectigo Limited/CN=Sectigo Public Server Authentication Root R46

New roots for existing CA:
  /C=US/O=SSL Corporation/CN=SSL.com TLS ECC Root CA 2022
  /C=US/O=SSL Corporation/CN=SSL.com TLS RSA Root CA 2022
</content>
</entry>
<entry>
<title>Remove some trailing whitespace</title>
<updated>2023-11-27T19:27:21+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-11-27T19:27:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8c836e8da0ecad4ba46b700ac35732587993b407'/>
<id>urn:sha1:8c836e8da0ecad4ba46b700ac35732587993b407</id>
<content type='text'>
x509_prn.c r1.6 changed the output of 'openssl -in foo.pem -noout -text'
by removing trailing whitespace from non-critical certificate extensions.
Committing the difference now to reduces noise in an upcoming diff.

There's some trailing whitespace remaining. That's because we try to print
a BMPString in an User Notice's Explicit Text with "%*s". That doesn't work
so well with an encoding full of NULs...
</content>
</entry>
<entry>
<title>Regen cert.pem</title>
<updated>2023-05-06T17:55:38+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-05-06T17:55:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f3c306cb6cad88706603553b6806bcc9db108349'/>
<id>urn:sha1:f3c306cb6cad88706603553b6806bcc9db108349</id>
<content type='text'>
This drops a few certs per the CA's request and TrustCor because of drama.
Certainly, a new CA, is added as well as new certs for DigiCert, SECOM and
E-Tugra. Unizeto still haven't fixed one of their certs and we still don't
want the alternative Firmaprofesional with sha1WithRSAEncryption.

ok sthen
</content>
</entry>
<entry>
<title>Sync cert.pem with certdata.txt from the NSS release branch. OK tb@ bcook@</title>
<updated>2022-07-11T09:05:16+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2022-07-11T09:05:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8a8db03fa6782097eef1ebe394fd68d9bc3bbd52'/>
<id>urn:sha1:8a8db03fa6782097eef1ebe394fd68d9bc3bbd52</id>
<content type='text'>
remove (expired):
/O=Cybertrust, Inc/CN=Cybertrust Global Root
/OU=GlobalSign Root CA - R2/O=GlobalSign/CN=GlobalSign

remove:
/C=ES/O=Agencia Catalana de Certificacio (NIF Q-0801176-I)/OU=Serveis Publics de Certificacio/OU=Vegeu https://www.catcert.net/verarrel (c)03/OU=Jerarquia Entitats de Certificacio Catalanes/CN=EC-ACC
/C=GB/O=Trustis Limited/OU=Trustis FPS Root CA

add new root (existing CAs):
/C=TW/O=Chunghwa Telecom Co., Ltd./CN=HiPKI Root CA - G1
/C=DE/O=D-Trust GmbH/CN=D-TRUST BR Root CA 1 2020
/C=DE/O=D-Trust GmbH/CN=D-TRUST EV Root CA 1 2020
/C=GR/O=Hellenic Academic and Research Institutions CA/CN=HARICA TLS ECC Root CA 2021
/C=GR/O=Hellenic Academic and Research Institutions CA/CN=HARICA TLS RSA Root CA 2021
/C=US/O=Internet Security Research Group/CN=ISRG Root X2
/C=PL/O=Unizeto Technologies S.A./OU=Certum Certification Authority/CN=Certum Trusted Network CA 2

add (new CAs):
/C=TN/O=Agence Nationale de Certification Electronique/CN=TunTrust Root CA
/serialNumber=G63287510/C=ES/O=ANF Autoridad de Certificacion/OU=ANF CA Raiz/CN=ANF Secure Server Root CA
/C=PL/O=Asseco Data Systems S.A./OU=Certum Certification Authority/CN=Certum EC-384 CA
/C=PL/O=Asseco Data Systems S.A./OU=Certum Certification Authority/CN=Certum Trusted Root CA
/C=AT/O=e-commerce monitoring GmbH/CN=GLOBALTRUST 2020
/C=CN/O=iTrusChina Co.,Ltd./CN=vTrus ECC Root CA
/C=CN/O=iTrusChina Co.,Ltd./CN=vTrus Root CA
/C=FI/O=Telia Finland Oyj/CN=Telia Root CA v2

replace with another cert with same CN (SHA1 vs SHA256):
/C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068
</content>
</entry>
</feed>
