diff options
author | sthen <> | 2018-12-16 12:08:32 +0000 |
---|---|---|
committer | sthen <> | 2018-12-16 12:08:32 +0000 |
commit | 0599cb3332122792b1eb29f7f3f541c967bea459 (patch) | |
tree | 3aed245f9274bb9eeea46b527e8d2ef7e3be2d9a /src | |
parent | f0a158d5d8088db193cd639773ed40b1e6248be9 (diff) | |
download | openbsd-0599cb3332122792b1eb29f7f3f541c967bea459.tar.gz openbsd-0599cb3332122792b1eb29f7f3f541c967bea459.tar.bz2 openbsd-0599cb3332122792b1eb29f7f3f541c967bea459.zip |
Regenerate root CA list using updated format-pem.pl. Specifically this
drops CA certificates whose validity dates don't comply with the rules on
ASN.1 encoding in RFC 5280 (and predecessors - same rule goes back to at
least RFC 2459, section 4.1.2.5).
LibreSSL strictly enforces this, so attempting to validate certificates
signed by these CAs just result in the following:
error 13 at 1 depth lookup:format error in certificate's notBefore field
"probably" beck@
Diffstat (limited to 'src')
-rw-r--r-- | src/lib/libcrypto/cert.pem | 102 |
1 files changed, 1 insertions, 101 deletions
diff --git a/src/lib/libcrypto/cert.pem b/src/lib/libcrypto/cert.pem index 6587ae5950..4390c0b690 100644 --- a/src/lib/libcrypto/cert.pem +++ b/src/lib/libcrypto/cert.pem | |||
@@ -1,4 +1,4 @@ | |||
1 | # $OpenBSD: cert.pem,v 1.17 2018/09/12 22:17:08 sthen Exp $ | 1 | # $OpenBSD: cert.pem,v 1.18 2018/12/16 12:08:32 sthen Exp $ |
2 | ### /C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068 | 2 | ### /C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068 |
3 | 3 | ||
4 | === /C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068 | 4 | === /C=ES/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068 |
@@ -786,52 +786,6 @@ CkcO8DdZEv8tmZQoTipPNU0zWgIxAOp1AE47xDqUEpHJWEadIRNyp4iciuRMStuW | |||
786 | 786 | ||
787 | ### AS Sertifitseerimiskeskus | 787 | ### AS Sertifitseerimiskeskus |
788 | 788 | ||
789 | === /C=EE/O=AS Sertifitseerimiskeskus/CN=EE Certification Centre Root CA/emailAddress=pki@sk.ee | ||
790 | Certificate: | ||
791 | Data: | ||
792 | Version: 3 (0x2) | ||
793 | Serial Number: | ||
794 | 54:80:f9:a0:73:ed:3f:00:4c:ca:89:d8:e3:71:e6:4a | ||
795 | Signature Algorithm: sha1WithRSAEncryption | ||
796 | Validity | ||
797 | Not Before: Oct 30 10:10:30 2010 GMT | ||
798 | Not After : Dec 17 23:59:59 2030 GMT | ||
799 | Subject: C=EE, O=AS Sertifitseerimiskeskus, CN=EE Certification Centre Root CA/emailAddress=pki@sk.ee | ||
800 | X509v3 extensions: | ||
801 | X509v3 Basic Constraints: critical | ||
802 | CA:TRUE | ||
803 | X509v3 Key Usage: critical | ||
804 | Certificate Sign, CRL Sign | ||
805 | X509v3 Subject Key Identifier: | ||
806 | 12:F2:5A:3E:EA:56:1C:BF:CD:06:AC:F1:F1:25:C9:A9:4B:D4:14:99 | ||
807 | X509v3 Extended Key Usage: | ||
808 | TLS Web Client Authentication, TLS Web Server Authentication, Code Signing, E-mail Protection, Time Stamping, OCSP Signing | ||
809 | SHA1 Fingerprint=C9:A8:B9:E7:55:80:5E:58:E3:53:77:A7:25:EB:AF:C3:7B:27:CC:D7 | ||
810 | SHA256 Fingerprint=3E:84:BA:43:42:90:85:16:E7:75:73:C0:99:2F:09:79:CA:08:4E:46:85:68:1F:F1:95:CC:BA:8A:22:9B:8A:76 | ||
811 | -----BEGIN CERTIFICATE----- | ||
812 | MIIEAzCCAuugAwIBAgIQVID5oHPtPwBMyonY43HmSjANBgkqhkiG9w0BAQUFADB1 | ||
813 | MQswCQYDVQQGEwJFRTEiMCAGA1UECgwZQVMgU2VydGlmaXRzZWVyaW1pc2tlc2t1 | ||
814 | czEoMCYGA1UEAwwfRUUgQ2VydGlmaWNhdGlvbiBDZW50cmUgUm9vdCBDQTEYMBYG | ||
815 | CSqGSIb3DQEJARYJcGtpQHNrLmVlMCIYDzIwMTAxMDMwMTAxMDMwWhgPMjAzMDEy | ||
816 | MTcyMzU5NTlaMHUxCzAJBgNVBAYTAkVFMSIwIAYDVQQKDBlBUyBTZXJ0aWZpdHNl | ||
817 | ZXJpbWlza2Vza3VzMSgwJgYDVQQDDB9FRSBDZXJ0aWZpY2F0aW9uIENlbnRyZSBS | ||
818 | b290IENBMRgwFgYJKoZIhvcNAQkBFglwa2lAc2suZWUwggEiMA0GCSqGSIb3DQEB | ||
819 | AQUAA4IBDwAwggEKAoIBAQDIIMDs4MVLqwd4lfNE7vsLDP90jmG7sWLqI9iroWUy | ||
820 | euuOF0+W2Ap7kaJjbMeMTC55v6kF/GlclY1i+blw7cNRfdCT5mzrMEvhvH2/UpvO | ||
821 | bntl8jixwKIy72KyaOBhU8E2lf/slLo2rpwcpzIP5Xy0xm90/XsY6KxX7QYgSzIw | ||
822 | WFv9zajmofxwvI6Sc9uXp3whrj3B9UiHbCe9nyV0gVWw93X2PaRka9ZP585ArQ/d | ||
823 | MtO8ihJTmMmJ+xAdTX7Nfh9WDSFwhfYggx/2uh8Ej+p3iDXE/+pOoYtNP2MbRMNE | ||
824 | 1CV2yreN1x5KZmTNXMWcg+HCCIia7E6j8T4cLNlsHaFLAgMBAAGjgYowgYcwDwYD | ||
825 | VR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFBLyWj7qVhy/ | ||
826 | zQas8fElyalL1BSZMEUGA1UdJQQ+MDwGCCsGAQUFBwMCBggrBgEFBQcDAQYIKwYB | ||
827 | BQUHAwMGCCsGAQUFBwMEBggrBgEFBQcDCAYIKwYBBQUHAwkwDQYJKoZIhvcNAQEF | ||
828 | BQADggEBAHv25MANqhlHt01Xo/6tu7Fq1Q+e2+RjxY6hUFaTlrg4wCQiZrxTFGGV | ||
829 | v9DHKpY5P30osxBAIWrEr7BSdxjhlthWXePdNl4dp1BUoMUq5KqMlIpPnTX/dqQG | ||
830 | E5Gion0ARD9V04I8GtVbvFZMIi5GQ4okQC3zErg7cBqklrkar4dBGmoYDQZPxz5u | ||
831 | uSlNDUmJEYcyW+ZLBMjkXOZ0c5RdFpgTlf7727FE5TpwrDdr5rMzcijJs1eg9gIW | ||
832 | iAYLtqZLICjU3j2LrTcFU3T+bsy8QxdxXvnFzBqpYe73dgzzcvRyrc9yAjYHR8/v | ||
833 | GVCJYMzpJJUPwssd8m92kMfMdcGWxZ0= | ||
834 | -----END CERTIFICATE----- | ||
835 | 789 | ||
836 | ### Atos | 790 | ### Atos |
837 | 791 | ||
@@ -6046,60 +6000,6 @@ J9RHjboNRhx3zxSkHLmkMcScKHQDNP8zGSal6Q10tz6XxnboJ5ajZt3hrvJBW8qY | |||
6046 | VoNzcOSGGtIxQbovvi0TWnZvTuhOgQ4/WwMioBK+ZlgRSssDxLQqKi2WF+A5VLxI | 6000 | VoNzcOSGGtIxQbovvi0TWnZvTuhOgQ4/WwMioBK+ZlgRSssDxLQqKi2WF+A5VLxI |
6047 | 03YnnZotBqbJ7DnSq9ufmgsnAjUpsUCV5/nonFWIGUbWtzT1fs45mtk48VH3Tyw= | 6001 | 03YnnZotBqbJ7DnSq9ufmgsnAjUpsUCV5/nonFWIGUbWtzT1fs45mtk48VH3Tyw= |
6048 | -----END CERTIFICATE----- | 6002 | -----END CERTIFICATE----- |
6049 | === /C=PL/O=Unizeto Technologies S.A./OU=Certum Certification Authority/CN=Certum Trusted Network CA 2 | ||
6050 | Certificate: | ||
6051 | Data: | ||
6052 | Version: 3 (0x2) | ||
6053 | Serial Number: | ||
6054 | 21:d6:d0:4a:4f:25:0f:c9:32:37:fc:aa:5e:12:8d:e9 | ||
6055 | Signature Algorithm: sha512WithRSAEncryption | ||
6056 | Validity | ||
6057 | Not Before: Oct 6 08:39:56 2011 GMT | ||
6058 | Not After : Oct 6 08:39:56 2046 GMT | ||
6059 | Subject: C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA 2 | ||
6060 | X509v3 extensions: | ||
6061 | X509v3 Basic Constraints: critical | ||
6062 | CA:TRUE | ||
6063 | X509v3 Subject Key Identifier: | ||
6064 | B6:A1:54:39:02:C3:A0:3F:8E:8A:BC:FA:D4:F8:1C:A6:D1:3A:0E:FD | ||
6065 | X509v3 Key Usage: critical | ||
6066 | Certificate Sign, CRL Sign | ||
6067 | SHA1 Fingerprint=D3:DD:48:3E:2B:BF:4C:05:E8:AF:10:F5:FA:76:26:CF:D3:DC:30:92 | ||
6068 | SHA256 Fingerprint=B6:76:F2:ED:DA:E8:77:5C:D3:6C:B0:F6:3C:D1:D4:60:39:61:F4:9E:62:65:BA:01:3A:2F:03:07:B6:D0:B8:04 | ||
6069 | -----BEGIN CERTIFICATE----- | ||
6070 | MIIF0jCCA7qgAwIBAgIQIdbQSk8lD8kyN/yqXhKN6TANBgkqhkiG9w0BAQ0FADCB | ||
6071 | gDELMAkGA1UEBhMCUEwxIjAgBgNVBAoTGVVuaXpldG8gVGVjaG5vbG9naWVzIFMu | ||
6072 | QS4xJzAlBgNVBAsTHkNlcnR1bSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEkMCIG | ||
6073 | A1UEAxMbQ2VydHVtIFRydXN0ZWQgTmV0d29yayBDQSAyMCIYDzIwMTExMDA2MDgz | ||
6074 | OTU2WhgPMjA0NjEwMDYwODM5NTZaMIGAMQswCQYDVQQGEwJQTDEiMCAGA1UEChMZ | ||
6075 | VW5pemV0byBUZWNobm9sb2dpZXMgUy5BLjEnMCUGA1UECxMeQ2VydHVtIENlcnRp | ||
6076 | ZmljYXRpb24gQXV0aG9yaXR5MSQwIgYDVQQDExtDZXJ0dW0gVHJ1c3RlZCBOZXR3 | ||
6077 | b3JrIENBIDIwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC9+Xj45tWA | ||
6078 | DGSdhhuWZGc/IjoedQF97/tcZ4zJzFxrqZHmuULlIEub2pt7uZld2ZuAS9eEQCsn | ||
6079 | 0+i6MLs+CRqnSZXvK0AkwpfHp+6bJe+oCgCXhVqqndwpyeI1B+twTUrWwbNWuKFB | ||
6080 | OJvR+zF/j+Bf4bE/D44WSWDXBo0Y+aomEKsq09DRZ40bRr5HMNUuctHFY9rnY3lE | ||
6081 | fktjJImGLjQ/KUxSiyqnwOKRKIm5wFv5HdnnJ63/mgKXwcZQkpsCLL2puTRZCr+E | ||
6082 | Sv/f/rOf69me4Jgj7KZrdxYq28ytOxykh9xGc14ZYmhFV+SQgkK7QtbwYeDBoz1m | ||
6083 | o130GO6IyY0XRSmZMnUCMe4pJshrAua1YkV/NxVaI2iJ1D7eTiew8EAMvE0Xy02i | ||
6084 | sx7QBlrd9pPPV3WZ9fqGGmd4s7+W/jTcvedSVuWz5XV710GRBdxdaeOVDUO5/IOW | ||
6085 | OZV7bIBaTxNyxtd9KXpEulKkKtVBRgkg/iKgtlswjbyJDNXXcPiHUv3a76xRLgez | ||
6086 | Tv7QCdpw75j6VuZt27VXS9zlLCUVyJ4ueE742pyehizKV/Ma5ciSixqClnrDvFAS | ||
6087 | adgOWkaLOusm+iPJtrCBvkIApPjW/jAux9JG9uWOdf3yzLnQh1vMBhBgu4M1t15n | ||
6088 | 3kfsmUjxpKEV/q2MYo45VU85FrmxY53/twIDAQABo0IwQDAPBgNVHRMBAf8EBTAD | ||
6089 | AQH/MB0GA1UdDgQWBBS2oVQ5AsOgP46KvPrU+Bym0ToO/TAOBgNVHQ8BAf8EBAMC | ||
6090 | AQYwDQYJKoZIhvcNAQENBQADggIBAHGlDs7k6b8/ONWJWsQCYftMxRQXLYtPU2sQ | ||
6091 | F/xlhMcQSZDe28cmk4gmb3DWAl45oPePq5a1pRNcgRRtDoGCERuKTsZPpd1iHkTf | ||
6092 | CVn0W3cLN+mLIMb4Ck4uWBzrM9DPhmDJ2vuAL55MYIR4PSFk1vtBHxgP58l1cb29 | ||
6093 | XN40hz5BsA72udY/CROWFC/emh1auVbONTqwX3BNXuMp8SMoclm2q8KMZiYcdywm | ||
6094 | djWLKKdpoPk79SPdhRB0yZADVpHnr7pH1BKXESLjokmUbOe3lEu6LaTaM4tMpkT/ | ||
6095 | WjzGHWTYtTHkpjx6qFcL2+1hGsvxznN3Y6SHb0xRONbkX8eftoEq5IVIeVheO/jb | ||
6096 | AoJnwTnbw3RLPTYe+SmTiGhbqEQZIfCn6IENLOiTNrQ3ssqwGyZ6miUfmpqAnksq | ||
6097 | P/ujmv5zMnHCnsZy4YpoJ/HkD7TETKVhk/iXEAcqMCWpuchxuO9ozC1+9eB+D4Ko | ||
6098 | b7a6bINDd82Kkhehnlt4Fj1F4jNy3eFmypnTycUm/Q1oBEauttmbjL4ZvrHG8hnj | ||
6099 | XALKLNhvSgfZyTXaQHXyxKcZb55CEJh15pWLYLztxRLXis7VmFxWlgPF7ncGNf/P | ||
6100 | 5O4/E2Hu29othfDNrp2yGAlFw5Khchf8R7agCyzxxN5DaAhqXzvwdmP7zAYspsbi | ||
6101 | DrW5viSP | ||
6102 | -----END CERTIFICATE----- | ||
6103 | 6003 | ||
6104 | ### VeriSign, Inc. | 6004 | ### VeriSign, Inc. |
6105 | 6005 | ||