From 7e2d698df7d214b4e5b1b10c12d42fd0a40b77cb Mon Sep 17 00:00:00 2001 From: Sergey Cherevko Date: Wed, 10 Jul 2024 13:04:42 +0300 Subject: [PATCH] fixup! Added TCI ECDSA and GOST root certificates --- SOURCES/certdata.txt | 89 -------------------------------------- SPECS/ca-certificates.spec | 6 ++- 2 files changed, 5 insertions(+), 90 deletions(-) diff --git a/SOURCES/certdata.txt b/SOURCES/certdata.txt index b8a0190..d1d086a 100644 --- a/SOURCES/certdata.txt +++ b/SOURCES/certdata.txt @@ -56421,95 +56421,6 @@ CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_TRUSTED_DELEGATOR CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE -# -# Certificate "TCI GOST ROOT A1" -# -# Issuer: CN=TCI GOST ROOT A1 -# Serial Number:02:de:ad:c0:de:00:8c:19:78:3c:7a:d6 -# Subject: CN=TCI GOST ROOT A1 -# Not Valid Before: Wed Mar 30 09:33:18 2022 -# Not Valid After : Tue Mar 30 09:33:18 2032 -# Fingerprint (SHA-256): 66:4B:2C:6F:77:02:EB:F3:32:09:87:88:BC:FF:73:04:4E:A8:39:BC:45:06:48:16:4F:C4:8D:7C:F2:56:4A:9E -# Fingerprint (SHA1): 1A:02:D2:5D:C1:3A:DF:20:6E:7F:E6:E8:AC:4E:E0:67:75:C6:E2:62 -CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE -CKA_TOKEN CK_BBOOL CK_TRUE -CKA_PRIVATE CK_BBOOL CK_FALSE -CKA_MODIFIABLE CK_BBOOL CK_FALSE -CKA_LABEL UTF8 "TCI GOST ROOT A1" -CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509 -CKA_SUBJECT MULTILINE_OCTAL -\060\033\061\031\060\027\006\003\125\004\003\014\020\124\103\111 -\040\107\117\123\124\040\122\117\117\124\040\101\061 -END -CKA_ID UTF8 "0" -CKA_ISSUER MULTILINE_OCTAL -\060\033\061\031\060\027\006\003\125\004\003\014\020\124\103\111 -\040\107\117\123\124\040\122\117\117\124\040\101\061 -END -CKA_SERIAL_NUMBER MULTILINE_OCTAL -\002\014\002\336\255\300\336\000\214\031\170\074\172\326 -END -CKA_VALUE MULTILINE_OCTAL -\060\202\001\135\060\202\001\010\240\003\002\001\002\002\014\002 -\336\255\300\336\000\214\031\170\074\172\326\060\014\006\010\052 -\205\003\007\001\001\003\002\005\000\060\033\061\031\060\027\006 -\003\125\004\003\014\020\124\103\111\040\107\117\123\124\040\122 -\117\117\124\040\101\061\060\036\027\015\062\062\060\063\063\060 -\060\071\063\063\061\070\132\027\015\063\062\060\063\063\060\060 -\071\063\063\061\070\132\060\033\061\031\060\027\006\003\125\004 -\003\014\020\124\103\111\040\107\117\123\124\040\122\117\117\124 -\040\101\061\060\146\060\037\006\010\052\205\003\007\001\001\001 -\001\060\023\006\007\052\205\003\002\002\043\001\006\010\052\205 -\003\007\001\001\002\002\003\103\000\004\100\112\041\076\073\121 -\271\311\177\011\214\204\264\106\144\066\042\155\205\051\335\021 -\205\263\255\166\066\250\002\053\301\337\054\033\034\261\233\351 -\327\220\005\027\177\063\002\317\330\212\337\041\227\025\157\204 -\017\344\364\230\242\120\377\042\357\204\305\243\043\060\041\060 -\016\006\003\125\035\017\001\001\377\004\004\003\002\001\206\060 -\017\006\003\125\035\023\001\001\377\004\005\060\003\001\001\377 -\060\014\006\010\052\205\003\007\001\001\003\002\005\000\003\101 -\000\350\272\016\176\351\305\257\322\111\265\172\076\307\321\070 -\102\263\260\031\327\350\141\240\202\217\160\070\102\356\144\247 -\303\141\334\274\363\377\166\312\275\200\152\130\276\174\110\336 -\353\165\352\204\172\031\023\021\064\010\322\350\235\303\067\001 -\027 -END -CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE -CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE -CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE - -# Trust for "TCI GOST ROOT A1" -# Issuer: CN=TCI GOST ROOT A1 -# Serial Number:02:de:ad:c0:de:00:8c:19:78:3c:7a:d6 -# Subject: CN=TCI GOST ROOT A1 -# Not Valid Before: Wed Mar 30 09:33:18 2022 -# Not Valid After : Tue Mar 30 09:33:18 2032 -# Fingerprint (SHA-256): 66:4B:2C:6F:77:02:EB:F3:32:09:87:88:BC:FF:73:04:4E:A8:39:BC:45:06:48:16:4F:C4:8D:7C:F2:56:4A:9E -# Fingerprint (SHA1): 1A:02:D2:5D:C1:3A:DF:20:6E:7F:E6:E8:AC:4E:E0:67:75:C6:E2:62 -CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST -CKA_TOKEN CK_BBOOL CK_TRUE -CKA_PRIVATE CK_BBOOL CK_FALSE -CKA_MODIFIABLE CK_BBOOL CK_FALSE -CKA_LABEL UTF8 "TCI GOST ROOT A1" -CKA_CERT_SHA1_HASH MULTILINE_OCTAL -\032\002\322\135\301\072\337\040\156\177\346\350\254\116\340\147 -\165\306\342\142 -END -CKA_CERT_MD5_HASH MULTILINE_OCTAL -\127\150\125\352\304\302\171\075\316\310\250\022\102\122\253\002 -END -CKA_ISSUER MULTILINE_OCTAL -\060\033\061\031\060\027\006\003\125\004\003\014\020\124\103\111 -\040\107\117\123\124\040\122\117\117\124\040\101\061 -END -CKA_SERIAL_NUMBER MULTILINE_OCTAL -\002\014\002\336\255\300\336\000\214\031\170\074\172\326 -END -CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR -CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR -CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_TRUSTED_DELEGATOR -CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE - # # Certificate "TCI ECDSA ROOT A1" # diff --git a/SPECS/ca-certificates.spec b/SPECS/ca-certificates.spec index 4f61d55..2813302 100644 --- a/SPECS/ca-certificates.spec +++ b/SPECS/ca-certificates.spec @@ -39,7 +39,7 @@ Version: 2023.2.60_v7.0.306 # On RHEL 8.x, please keep the release version >= 80 # When rebasing on Y-Stream (8.y), use 81, 82, 83, ... # When rebasing on Z-Stream (8.y.z), use 80.0, 80.1, 80.2, .. -Release: 80.0%{?dist}.inferit.1 +Release: 80.0%{?dist}.inferit.2 License: Public Domain Group: System Environment/Base @@ -408,6 +408,10 @@ fi %changelog +* Wed Jul 10 2024 Sergey Cherevko - 2023.2.60_v7.0.306-80.0.inferit.2 +- Fixed addition TCI GOST certificate +- Bump version + * Tue Jul 09 2024 Sergey Cherevko - 2023.2.60_v7.0.306-80.0.inferit.1 - Added TCI ECDSA and GOST root certificates