[El-errata] ELBA-2020-3380 Oracle Linux 8 ca-certificates bug fix and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Aug 11 07:11:03 PDT 2020


Oracle Linux Bug Fix Advisory ELBA-2020-3380

http://linux.oracle.com/errata/ELBA-2020-3380.html

The following updated rpms for Oracle Linux 8 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
ca-certificates-2020.2.41-80.0.el8_2.noarch.rpm

aarch64:
ca-certificates-2020.2.41-80.0.el8_2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ca-certificates-2020.2.41-80.0.el8_2.src.rpm



Description of changes:

[2020.2.41-80.0]
- Update to CKBI 2.41 from NSS 3.53.0
- Removing:
- # Certificate "AddTrust Low-Value Services Root"
- # Certificate "AddTrust External Root"
- # Certificate "UTN USERFirst Email Root CA"
- # Certificate "Certplus Class 2 Primary CA"
- # Certificate "Deutsche Telekom Root CA 2"
- # Certificate "Staat der Nederlanden Root CA - G2"
- # Certificate "Swisscom Root CA 2"
- # Certificate "Certinomis - Root CA"
- Adding:
- # Certificate "Entrust Root Certification Authority - G4"

[2019.2.32-1]
- Update to CKBI 2.32 from NSS 3.44
- Removing:
- # Certificate "Visa eCommerce Root"
- # Certificate "AC Raiz Certicamara S.A."
- # Certificate "ComSign CA"
- # Certificate "Certplus Root CA G1"
- # Certificate "Certplus Root CA G2"
- # Certificate "OpenTrust Root CA G1"
- # Certificate "OpenTrust Root CA G2"
- # Certificate "OpenTrust Root CA G3"
- Adding:
- # Certificate "GlobalSign Root CA - R6"
- # Certificate "OISTE WISeKey Global Root GC CA"
- # Certificate "GTS Root R1"
- # Certificate "GTS Root R2"
- # Certificate "GTS Root R3"
- # Certificate "GTS Root R4"
- # Certificate "UCA Global G2 Root"
- # Certificate "UCA Extended Validation Root"
- # Certificate "Certigna Root CA"
- # Certificate "emSign Root CA - G1"
- # Certificate "emSign ECC Root CA - G3"
- # Certificate "emSign Root CA - C1"
- # Certificate "emSign ECC Root CA - C3"
- # Certificate "Hongkong Post Root CA 3"

[2018.2.24-6.1]
- Test gating

[2018.2.24-6]
- Use __python3 macro when invoking Python

[2018.2.24-5]
- Ported scripts to python3

[2018.2.24-4]
- Extract certificate bundle in EDK2 format, suggested by Laszlo Ersek

[2018.2.24-3]
- Adjust ghost file permissions, rhbz#1564432

[2018.2.24-2]
- Update to CKBI 2.24 from NSS 3.37

[2018.2.22-4]
- Update Python 2 dependency declarations to new packaging standards
(See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)

[2018.2.22-3]
- Add post dep on coreutils for ln(1)

[2018.2.22-2]
- Update to CKBI 2.22 from NSS 3.35

[2017.2.20-6]
- Depend on bash, grep, sed. Required for ca-legacy script execution.
- p11-kit is already required at %post execution time. (rhbz#1537127)

[2017.2.20-5]
- Use the force, script! (Which sln did by default).

[2017.2.20-4]
- stop using sln in ca-legacy script.

[2017.2.20-3]
- Use ln -s, because sln was removed from glibc. rhbz#1536349

[2017.2.20-2]
- Update to CKBI 2.20 from NSS 3.34.1

[2017.2.16-4]
- Set P11_KIT_NO_USER_CONFIG=1 to prevent p11-kit from reading user
configuration files (rhbz#1478172).

[2017.2.16-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[2017.2.16-2]
- Update to (yet unreleased) CKBI 2.16 which is planned for NSS 3.32.
Mozilla removed all trust bits for code signing.

[2017.2.14-2]
- Update to CKBI 2.14 from NSS 3.30.2

[2017.2.11-5]
- For CAs trusted by Mozilla, set attribute nss-mozilla-ca-policy: true
- Set attribute modifiable: false
- Require p11-kit 0.23.4

[2017.2.11-4]
- Changed the packaged bundle to use the flexible p11-kit-object-v1 file 
format,
as a preparation to fix bugs in the interaction between p11-kit-trust and
Mozilla applications, such as Firefox, Thunderbird etc.
- Changed update-ca-trust to add comments to extracted PEM format files.
- Added an utility to help with comparing output of the trust dump command.

[2017.2.11-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

[2017.2.11-2]
- Update to CKBI 2.11 from NSS 3.28.1

[2016.2.10-2]
- Update to CKBI 2.10 from NSS 3.27

[2016.2.9-3]
- Revert to the unmodified upstream CA list, changing the legacy trust
to an empty list. Keeping the ca-legacy tool and existing config,
however, the configuration has no effect after this change.

[2016.2.9-2]
- Update to CKBI 2.9 from NSS 3.26 with legacy modifications

[2016.2.8-2]
- Update to CKBI 2.8 from NSS 3.25 with legacy modifications

[2016.2.7-5]
- Only create backup files if there is an original file (bug 999017).

[2016.2.7-4]
- Use sln, not ln, to avoid the dependency on coreutils.

[2016.2.7-3]
- Fix typos in a manual page and in a README file.

[2016.2.7-2]
- Update to CKBI 2.7 from NSS 3.23 with legacy modifications

[2015.2.6-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild

[2015.2.6-2]
- Update to CKBI 2.6 from NSS 3.21 with legacy modifications

[2015.2.5-2]
- Update to CKBI 2.5 from NSS 3.19.3 with legacy modifications

[2015.2.4-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild

[2015.2.4-2]
- Update to CKBI 2.4 from NSS 3.18.1 with legacy modifications

[2015.2.3-4]
- Fixed a typo in the ca-legacy manual page.

[2015.2.3-3]
- Don't use "enable" as a value for the legacy configuration, instead
of the value "default", to make it clear that this preference isn't
a promise to keep certificates enabled, but rather that we only
keep them enabled as long as it's considered necessary.
- Changed the configuration file, the ca-legacy utility and filenames
to use the term "default" (instead of the term "enable").
- Added a manual page for the ca-legacy utility.
- Fixed the ca-legacy utility to handle absence of the configuration
setting and treat absence as the default setting.

[2015.2.3-2]
- Update to CKBI 2.3 from NSS 3.18 with legacy modifications
- Fixed a mistake in the legacy handling of the upstream 2.2 release:
Removed two AOL certificates from the legacy group, because
upstream didn't remove them as part of phasing out 1024-bit
certificates, which means it isn't necessary to keep them.
- Fixed a mistake in the legacy handling of the upstream 2.1 release:
Moved two NetLock certificates into the legacy group.

[2014.2.2-2]
- Update to CKBI 2.2 from NSS 3.17.3 with legacy modifications
- Update project URL
- Cleanup

[2014.2.1-7]
- Restore Requires: coreutils

[2014.2.1-6]
- A proper fix for rhbz#1158343

[2014.2.1-5]
- add Requires: coreutils (rhbz#1158343)

[2014.2.1-4]
- Introduce the ca-legacy utility and a ca-legacy.conf configuration file.
By default, legacy roots required for OpenSSL/GnuTLS compatibility
are kept enabled. Using the ca-legacy utility, the legacy roots can be
disabled. If disabled, the system will use the trust set as provided
by the upstream Mozilla CA list. (See also: rhbz#1158197)

[2014.2.1-3]
- Temporarily re-enable several legacy root CA certificates because of
compatibility issues with software based on OpenSSL/GnuTLS,
see rhbz#1144808

[2014.2.1-2]
- Update to CKBI 2.1 from NSS 3.16.4
- Fix rhbz#1130226

[2013.1.97-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild

[2013.1.97-2]
- Update to CKBI 1.97 from NSS 3.16

[2013.1.96-3]
- Remove openjdk build dependency

[2013.1.96-2]
- Own the %{_datadir}/pki dir.

[2013.1.96-1]
- Update to CKBI 1.96 from NSS 3.15.4

[2013.1.95-1]
- Update to CKBI 1.95 from NSS 3.15.3.1

[2013.1.94-18]
- Update the Entrust root stapled extension for compatibility with
p11-kit version 0.19.2, patch by Stef Walter, rhbz#988745

[2013.1.94-17]
- merge manual improvement from f19

[2013.1.94-16]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild

[2013.1.94-15]
- clarification updates to manual page

[2013.1.94-14]
- added a manual page and related build requirements
- simplify the README files now that we have a manual page
- set a certificate alias in trusted bundle (thanks to Ludwig Nussel)

[2013.1.94-13]
- use correct command in README files, rhbz#961809

[2013.1.94-12]
- update to version 1.94 provided by NSS 3.15 (beta)

[2012.87-12]
- Use both label and serial to identify cert during conversion, rhbz#927601
- Add myself as contributor to certdata2.pem.py and remove use of rcs/ident.
(thanks to Michael Shuler for suggesting to do so)
- Update source URLs and comments, add source file for version information.

[2012.87-11]
- adjust to changed and new functionality provided by p11-kit 0.17.3
- updated READMEs to describe the new directory-specific treatment of files
- ship a new file that contains certificates with neutral trust
- ship a new file that contains distrust objects, and also staple a
basic constraint extension to one legacy root contained in the
Mozilla CA list
- adjust the build script to dynamically produce most of above files
- add and own the anchors and blacklist subdirectories
- file generate-cacerts.pl is no longer required

[2012.87-9]
- Major rework for the Fedora SharedSystemCertificates feature.
- Only ship a PEM bundle file using the BEGIN TRUSTED CERTIFICATE file 
format.
- Require the p11-kit package that contains tools to automatically create
other file format bundles.
- Convert old file locations to symbolic links that point to dynamically
generated files.
- Old files, which might have been locally modified, will be saved in backup
files with .rpmsave extension.
- Added a update-ca-certificates script which can be used to regenerate
the merged trusted output.
- Refer to the various README files that have been added for more detailed
explanation of the new system.
- No longer require rsc for building.
- Add explanation for the future version numbering scheme,
because the old numbering scheme was based on upstream using cvs,
which is no longer true, and therefore can no longer be used.
- Includes changes from rhbz#873369.

[2012.87-2.fc19.1]
- Ship trust bundle file in /usr/share/pki/ca-trust-source/, temporarily 
in addition.
This location will soon become the only place containing this file.

[2012.87-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild

[2012.87-1]
- Updated to r1.87 to blacklist mis-issued turktrust CA certs

[2012.86-2]
- Updated blacklist with 20 entries (Diginotar, Trustwave, Comodo(?)
- Fix to certdata2pem.py to also check for CKT_NSS_NOT_TRUSTED

[2012.86-1]
- update to r1.86

[2012.85-2]
- add openssl to BuildRequires

[2012.85-1]
- update to r1.85

[2012.81-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild

[2012.81-1]
- update to r1.81

[2011.80-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild

[2011.80-1]
- update to r1.80
- fix handling of certs with dublicate Subject names (#733032)

[2011.78-1]
- update to r1.78, removing trust from DigiNotar root (#734679)

[2011.75-1]
- update to r1.75

[2011.74-1]
- update to r1.74

[2011.70-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild

[2011.70-1]
- update to r1.70

[2010.65-3]
- update to r1.65

[2010.63-3]
- package /etc/ssl/certs symlink for third-party apps (#572725)

[2010.63-2]
- rebuild

[2010.63-1]
- update to certdata.txt r1.63
- use upstream RCS version in Version

[2010-4]
- fix ca-bundle.crt (#575111)

[2010-3]
- update to certdata.txt r1.58
- add /etc/pki/tls/certs/ca-bundle.trust.crt using 'TRUSTED CERTICATE' 
format
- exclude ECC certs from the Java cacerts database
- catch keytool failures
- fail parsing certdata.txt on finding untrusted but not blacklisted cert

[2010-2]
- fix Java cacert database generation: use Subject rather than Issuer
for alias name; add diagnostics; fix some alias names.

[2010-1]
- adopt Python certdata.txt parsing script from Debian

[2009-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

[2009-1]
- update to certdata.txt r1.53

[2008-8]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

[2008-7]
- update to certdata.txt r1.49

[2008-6]
- Change generate-cacerts.pl to produce pretty aliases.

[2008-5]
- include /etc/pki/tls/cert.pem symlink to ca-bundle.crt

[2008-4]
- use package name for temp dir, recreate it in prep

[2008-3]
- fix source script perms
- mark packaged files as config(noreplace)

[2008-2]
- add (but don't use) mkcabundle.pl
- tweak description
- use /usr/bin/keytool directly; BR java-openjdk

[2008-1]
- Initial build (#448497)





More information about the El-errata mailing list