38 Commits

Author SHA1 Message Date
Dirk Stolle
2bf26d3060 ca-certificates: update to 20250419 2025-07-21 08:56:24 +02:00
Christoph Reiter
a83bfd4312 ca-certificates: Update to 20241223 2025-01-27 06:58:41 +01:00
Christopher Degawa
a1f8e04920
ca-certificates: add .exe for p11-kit
execv would fail on arch when trying to install ca-certificates

Signed-off-by: Christopher Degawa <ccom@randomderp.com>
2024-06-06 09:25:11 -05:00
Christoph Reiter
11a162b0e5 repo: make file executable permissions match the cygwin derived status
In case we have a git clone from Linux that is accessed via cygwin git
the files executable status will be derived from the file content (shebang)
and won't match the git repo, leading to a initially dirty tree.

This can be worked around by setting "core.filemode=false", but let's try
to match the cygwin permissions with the in-repo permissions so this isn't
needed.
2024-04-14 15:17:42 +02:00
Christopher Degawa
6196cf3e1f ca-certificates: update to 20240203
Signed-off-by: Christopher Degawa <ccom@randomderp.com>
2024-02-27 23:05:22 +05:30
Christoph Reiter
de615ba999 ca-certificates: Update to 20230311 2023-03-14 20:53:00 +01:00
Christoph Reiter
a457a256df Various base rebuilds
packages that are still missing file checksums because they haven't
been rebuilt in a while
2022-10-22 11:33:42 +02:00
Christoph Reiter
5b4b900f16 ca-certificates: Update to 20211016
drop patch included upstream
2022-05-13 13:10:50 +02:00
Matthias Aßhauer
78e423ba35 ca-certificates: drop expired "DST Root CA X3"
Let's encrypt signs current certificates based on their root
certificate "ISRG Root X1". They provide two different versions
of "ISRG Root X1", though. One is self-signed using "ISRG Root X1"
and one is cross-signed using "DST Root CA X3" [1]. Some systems
still distribute certificate chains with the cross-signed version.
"DST Root CA X3" expired on 2021-09-30. This can lead to valid
certificates being considered invalid on devices with the expired
certificate still in their CA certificate bundle.

Ubuntu[2] and RedHat[3][4] recently dropped this certificates from their
`ca-certificates` packages for the same reasons.

The blacklist code in certdata2pem is copied from the debian version
of the file as it comes with ca-certificates_20210119.tar.xz.

[1] https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021
[2] https://ubuntu.com/security/notices/USN-5089-1
[3] https://access.redhat.com/errata/RHBA-2021:3649
[4] https://access.redhat.com/articles/6338021
2021-10-02 12:59:16 +02:00
Jason Zavaglia
d81ef82df7 fix pkgrel and checksum 2021-08-15 23:01:18 +10:00
Jason Zavaglia
8176e3faf6 Enhance update-ca-trust to correctly update certificates that were not updating 2021-08-12 23:40:22 +10:00
Christoph Reiter
39e749e6eb ca-certificates: Update to 20210119 2021-04-25 11:41:12 +02:00
Alexey Pavlov
c8c93568f5 ca-certificates: Update to 20190110. Port to python3 2019-11-07 22:38:06 +03:00
Alexey Pavlov
dc32bcda21 ca-certificates: Update to 20180409 2018-11-01 08:02:02 +03:00
Alexey Pavlov
bdbfe1948e ca-certificates: Some fixes 2017-09-12 14:31:56 +03:00
Holger Nahrstaedt
13a4780291 fix 2017-09-11 12:31:55 +02:00
Holger Nahrstaedt
7d1eed0c68 fix pkgbuild 2017-09-11 12:27:02 +02:00
Holger Nahrstaedt
8500cf602d removed unused file 2017-09-11 12:25:18 +02:00
Holger Nahrstaedt
040a75edad fix ca-certificates 2017-09-11 12:12:31 +02:00
Holger Nahrstaedt
0468cbc775 some cleanup 2017-09-11 11:40:50 +02:00
Holger Nahrstaedt
3879cf7fa7 use http://ftp.debian.org/debian/pool/main/c/ca-certificates/ 2017-09-11 10:29:36 +02:00
Holger Nahrstaedt
6084a20481 update p11-kit 2017-09-10 22:29:49 +02:00
Holger Nahrstaedt
64c3d3b0c5 adapt PKGBUILD from mingw-packages 2017-09-08 21:09:14 +02:00
Viktor Szakats
2b119ae43f use secure urls
* follow some redirects
2016-02-23 10:26:02 +01:00
Alexpux
249379576e ca-certificates: Update to 20150426. Add also "StartCom Class 1 Primary Intermediate Server CA" certificate. 2015-06-19 20:32:39 +03:00
Alexpux
022f3879ad ca-certificates: Install root certificates. Add changes from fedora packages. 2015-02-14 00:42:15 +03:00
Renato Silva
b176b369d3 Trailing whitespace cleanup. 2015-02-09 18:47:01 -02:00
Alexpux
651449f973 ca-certificates: Update to 20141019 2015-01-16 09:58:16 +03:00
Ray Donnelly
5f417d6d68 ca-certificates: Clean old neutral-trust.crt and supplement.p11-kit before adding new 2014-08-30 20:17:44 +01:00
Alexpux
99cbe81c43 ca-certificates: Unify with mingw version 2014-08-30 23:00:01 +04:00
Ray Donnelly
44589c10ac ca-certificates: Make repeat runs not accumulate dupe certs 2014-08-30 19:00:13 +01:00
Ray Donnelly
1718d8326b ca-certificates: Updated a checksum 2014-08-30 01:38:55 +01:00
Alexpux
e392c83f78 ca-certificates: Update to 1.97. Prepare to move system to real /usr 2014-06-14 21:17:22 +04:00
Alexpux
34ac3cdf22 Fix format in PKGBUILD's 2014-04-28 09:52:34 +04:00
Alexpux
9841d13dd8 Fix installation of some packages on new root. 2014-02-05 15:02:15 +04:00
Alexpux
2aa8c3f326 ca-certificates: Update to 1.96 2014-02-05 00:55:04 +04:00
Alexpux
ea24d0f5e5 ca-certificates: fix for p11-kit-0.19+ 2013-11-09 23:17:17 +04:00
Alexpux
794c6661b6 Add ca-certificates package 2013-11-03 19:59:01 +04:00