Skip to content

Commit

Permalink
Trust store release 2024.10.2
Browse files Browse the repository at this point in the history
Rolling trust store release at 2024-10-14T13:14:23-0700.
$ cfssl-trust -d ./cert.db  -b int release 888h
skipping expired certificate (SKI=d73b82a62b31cdb1949eb7ea66293ac53d16c0bf, serial=239103577347589804392016039354697780213, subject='/Digi-Sign CA Digi-ID/C=IE/O=Digi-Sign Limited/L=Dublin/ST=County Dublin')
skipping expired certificate (SKI=67fd8820142798c709d22519bbe9511163755062, serial=11219189969625805505073711195983176805, subject='/TERENA SSL CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland')
skipping expired certificate (SKI=c2b885d7e1b913bdd148bcfd5edc7d90427a8aa9, serial=15100258180998422066925747664388448148, subject='/TERENA SSL High Assurance CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland')
skipping expired certificate (SKI=ca8782fba642ff63a96c4451cf74f76e8936e6bc, serial=2543951452088144462446830710844548704, subject='/INTEGRIS Direct Intermediate CA/C=US/O=INTEGRIS/OU=INTEGRIS DIRECT Messaging HISP')
skipping expired certificate (SKI=f021e94977739f85ae183be852701406ed42eeca, serial=4381935297294597993058787467913641258, subject='/TERENA Personal CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland')
skipping expired certificate (SKI=29aa1b6e30f9306763a587260cacf1819c697449, serial=16898994241335817362750290230426730092, subject='/TERENA eScience SSL CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland')
skipping expired certificate (SKI=8c9f112ee6e37a04a51e558b460804a6ed9770a6, serial=3612740644231628671459046335609331832, subject='/TERENA eScience Personal CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland')
skipping expired certificate (SKI=c3f7d0b52a30adaf0d9121703954ddbc8970c73a, serial=1372800737, subject='/Entrust Certification Authority - L1M/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2014 Entrust, Inc. - for authorized use only')
1411 certificates rolled
8 certificates skipped
Successfully rolled new int release 2024.10.2
$ cfssl-trust -d ./cert.db  -b ca release 888h
354 certificates rolled
0 certificates skipped
Successfully rolled new ca release 2024.10.2
$ cfssl-trust -d ./cert.db  -r 2024.10.2 -b int bundle int-bundle.crt
selected release 2024.10.2
Selected 1411 certificates for this release.
$ cfssl-trust -d ./cert.db  -r 2024.10.2 -b ca bundle ca-bundle.crt
selected release 2024.10.2
Selected 354 certificates for this release.
$ certdump ca-bundle.crt  > certdata/ca-bundle.txt
$ certdump int-bundle.crt > certdata/int-bundle.txt
$ git status --porcelain -uno
M  cert.db
M  certdata/int-bundle.txt
M  int-bundle.crt
  • Loading branch information
BowonY committed Oct 14, 2024
1 parent 5f8367c commit b1345b4
Show file tree
Hide file tree
Showing 3 changed files with 0 additions and 398 deletions.
Binary file modified cert.db
Binary file not shown.
154 changes: 0 additions & 154 deletions certdata/int-bundle.txt
Original file line number Diff line number Diff line change
Expand Up @@ -3332,27 +3332,6 @@ Details:
OCSP server:
- http://ocspfnmtrcmca.cert.fnmt.es/ocspfnmtrcmca/OcspResponder
CERTIFICATE
Subject: /Digi-Sign CA Digi-ID/C=IE/O=Digi-Sign Limited/L=Dublin/ST=County
Dublin
Issuer: /USERTrust RSA Certification Authority/C=US/O=The USERTRUST
Network/L=Jersey City/ST=New Jersey
Signature algorithm: RSA / SHA384
Details:
Public key: RSA-2048
Serial number: 239103577347589804392016039354697780213
AKI: 53:79:BF:5A:AA:2B:4A:CF:54:80:E1:D8:9B:C0:9D:F2:B2:03:66:CB
SKI: D7:3B:82:A6:2B:31:CD:B1:94:9E:B7:EA:66:29:3A:C5:3D:16:C0:BF
Valid from: 2014-11-07T00:00:00+0000
until: 2024-11-06T23:59:59+0000
Key usages: cert sign, crl sign, digital signature
Extended usages: client auth, s/mime
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
OCSP server:
- http://ocsp.usertrust.com
CERTIFICATE
Subject: /CA 沃通免费SSL证书 G2/C=CN/O=WoSign CA Limited
Issuer: /CA 沃通根证书/C=CN/O=WoSign CA Limited
Signature algorithm: RSA / SHA256
Expand Down Expand Up @@ -3410,139 +3389,6 @@ Details:
OCSP server:
- http://ocsp1.wosign.com/ca1
CERTIFICATE
Subject: /TERENA SSL CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland
Issuer: /DigiCert Assured ID Root CA/C=US/O=DigiCert Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 11219189969625805505073711195983176805
AKI: 45:EB:A2:AF:F4:92:CB:82:31:2D:51:8B:A7:A7:21:9D:F3:6D:C8:0F
SKI: 67:FD:88:20:14:27:98:C7:09:D2:25:19:BB:E9:51:11:63:75:50:62
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /TERENA SSL High Assurance CA
3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland
Issuer: /DigiCert High Assurance EV Root CA/C=US/O=DigiCert
Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 15100258180998422066925747664388448148
AKI: B1:3E:C3:69:03:F8:BF:47:01:D4:98:26:1A:08:02:EF:63:64:2B:C3
SKI: C2:B8:85:D7:E1:B9:13:BD:D1:48:BC:FD:5E:DC:7D:90:42:7A:8A:A9
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /INTEGRIS Direct Intermediate CA/C=US/O=INTEGRIS/OU=INTEGRIS DIRECT
Messaging HISP
Issuer: /DigiCert Federated Trust CA/C=US/O=DigiCert Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 2543951452088144462446830710844548704
AKI: 46:08:38:5A:A9:8E:20:BB:0C:AF:5E:31:BA:89:B3:28:BF:AC:8C:36
SKI: CA:87:82:FB:A6:42:FF:63:A9:6C:44:51:CF:74:F7:6E:89:36:E6:BC
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/aiaINTEGRISDirectIntermediateCA.p7c
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /TERENA Personal CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland
Issuer: /DigiCert Assured ID Root CA/C=US/O=DigiCert Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 4381935297294597993058787467913641258
AKI: 45:EB:A2:AF:F4:92:CB:82:31:2D:51:8B:A7:A7:21:9D:F3:6D:C8:0F
SKI: F0:21:E9:49:77:73:9F:85:AE:18:3B:E8:52:70:14:06:ED:42:EE:CA
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /TERENA eScience SSL CA 3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland
Issuer: /DigiCert Assured ID Root CA/C=US/O=DigiCert Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 16898994241335817362750290230426730092
AKI: 45:EB:A2:AF:F4:92:CB:82:31:2D:51:8B:A7:A7:21:9D:F3:6D:C8:0F
SKI: 29:AA:1B:6E:30:F9:30:67:63:A5:87:26:0C:AC:F1:81:9C:69:74:49
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /TERENA eScience Personal CA
3/C=NL/O=TERENA/L=Amsterdam/ST=Noord-Holland
Issuer: /DigiCert Assured ID Root CA/C=US/O=DigiCert Inc/OU=www.digicert.com
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 3612740644231628671459046335609331832
AKI: 45:EB:A2:AF:F4:92:CB:82:31:2D:51:8B:A7:A7:21:9D:F3:6D:C8:0F
SKI: 8C:9F:11:2E:E6:E3:7A:04:A5:1E:55:8B:46:08:04:A6:ED:97:70:A6
Valid from: 2014-11-18T12:00:00+0000
until: 2024-11-18T12:00:00+0000
Key usages: cert sign, crl sign, digital signature
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
1 AIA:
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
OCSP server:
- http://ocsp.digicert.com
CERTIFICATE
Subject: /Entrust Certification Authority - L1M/C=US/O=Entrust, Inc./OU=See
www.entrust.net/legal-terms/OU=(c) 2014 Entrust, Inc. - for authorized use
only
Issuer: /Entrust Root Certification Authority/C=US/O=Entrust,
Inc./OU=www.entrust.net/CPS is incorporated by reference/OU=(c) 2006
Entrust, Inc.
Signature algorithm: RSA / SHA256
Details:
Public key: RSA-2048
Serial number: 1372800737
AKI: 68:90:E4:67:A4:A6:53:80:C7:86:66:A4:F1:F7:4B:43:FB:84:BD:6D
SKI: C3:F7:D0:B5:2A:30:AD:AF:0D:91:21:70:39:54:DD:BC:89:70:C7:3A
Valid from: 2014-11-18T20:59:32+0000
until: 2024-11-19T06:33:02+0000
Key usages: cert sign, crl sign
Extended usages: client auth, server auth
Basic constraints: valid, is a CA certificate, max path length 0
SANs (0):
OCSP server:
- http://ocsp.entrust.net
CERTIFICATE
Subject: /COMODO/HP Secure Email CA 2/C=GB/O=COMODO CA
Limited/L=Salford/ST=Greater Manchester
Issuer: /COMODO RSA Certification Authority/C=GB/O=COMODO CA
Expand Down
Loading

0 comments on commit b1345b4

Please sign in to comment.