summaryrefslogtreecommitdiff
path: root/blacklist.txt
AgeCommit message (Collapse)AuthorFilesLines
2020-06-02Revert "blacklist: distrust Symantec Root CAs"20200603Max Rees1-24/+0
As of this writing there are still large service providers still using GeoTrust-based certificates, such as Apple Mail: Certificate chain 0 s:CN = imap.mail.me.com, OU = management:idms.group.859635, O = Apple Inc., ST = California, C = US i:CN = Apple IST CA 2 - G1, OU = Certification Authority, O = Apple Inc., C = US 1 s:CN = Apple IST CA 2 - G1, OU = Certification Authority, O = Apple Inc., C = US i:C = US, O = GeoTrust Inc., CN = GeoTrust Global CA 2 s:C = US, O = GeoTrust Inc., CN = GeoTrust Global CA i:C = US, O = GeoTrust Inc., CN = GeoTrust Global CA This reverts commit 4023193aac8706830d99720de6628cc0d8eabd84.
2020-06-02Add machinery to detect expired certificatesMax Rees1-0/+8
2020-06-02blacklist: distrust Symantec Root CAsMax Rees1-0/+24
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=911289
2020-06-02blacklist: silence untrusted errorsMax Rees1-0/+12
When certdata2pem is run, it checks whether certificates are marked as untrusted. If they are, it excludes them but emits a loud warning that they were not explicitly blacklisted. Silence this warning by explicitly blacklisting them.
2020-06-02blacklist: remove old DigiNotar entryMax Rees1-2/+0
This certificate no longer exists in certdata.txt.
2018-06-24Update for 20180411A. Wilcox1-19/+0
Remove WoSign from blacklist since the certs themselves are gone. Update certdata.txt from NSS upstream. Update VERSION file for new release.
2017-07-31import ca-certificates 20170726 data20170726William Pitcock1-0/+23