Bug#767272: Bug#866670: ca-certificates: update-ca-certificates -f does not pass removed certs to hooks

Michael Shuler michael at pbandjelly.org
Fri Jul 21 15:19:01 UTC 2017


Testing against a new build for jessie, it looks as if the
ca-certificates-java hook does nothing with new CA certificate
additions, either? None of the newly added CAs appear to have made it to
the keystore upon package upgrade, but were added in --fresh. It appears
the hook is not doing the right thing in either add/remove case.

Just wanted to let you know I've taken a quick look, but I'm not sure
what the real issue is, at this moment.

(test stdout attached)

-- 
Kind regards,
Michael
-------------- next part --------------
mshuler at hana:~$ sudo apt-get install ca-certificates=20141019+deb8u4
Reading package lists... Done
Building dependency tree       
Reading state information... Done
The following packages will be upgraded:
  ca-certificates
1 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 196 kB of archives.
After this operation, 70.7 kB of additional disk space will be used.
WARNING: The following packages cannot be authenticated!
  ca-certificates
Install these packages without verification? [y/N] y
Get:1 http://www.pbandjelly.org/debian/ ./ ca-certificates 20141019+deb8u4 [196 kB]
Fetched 196 kB in 0s (1,513 kB/s)       
Reading changelogs... Done
Preconfiguring packages ...
(Reading database ... 278491 files and directories currently installed.)
Preparing to unpack .../ca-certificates_20141019+deb8u4_all.deb ...
Unpacking ca-certificates (20141019+deb8u4) over (20141019+deb8u3) ...
Processing triggers for man-db (2.7.0.2-5) ...
Setting up ca-certificates (20141019+deb8u4) ...
Updating certificates in /etc/ssl/certs... 12 added, 24 removed; done.
Processing triggers for ca-certificates (20141019+deb8u4) ...
Updating certificates in /etc/ssl/certs... 0 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d....
done.
done.
mshuler at hana:~$ 
mshuler at hana:~$ 
mshuler at hana:~$ sudo update-ca-certificates --fresh --verbose       
Clearing symlinks in /etc/ssl/certs...done.
Updating certificates in /etc/ssl/certs... Doing .
SwissSign_Silver_CA_-_G2.pem => 57bcb2da.0
SwissSign_Silver_CA_-_G2.pem => 5046c355.0
Entrust_Root_Certification_Authority.pem => 6b99d060.0
Entrust_Root_Certification_Authority.pem => bf64f35b.0
AC_RAIZ_FNMT-RCM.pem => cd8c0d63.0
AC_RAIZ_FNMT-RCM.pem => b936d1c6.0
Entrust_Root_Certification_Authority_-_G2.pem => 02265526.0
Entrust_Root_Certification_Authority_-_G2.pem => 455f1b52.0
T-TeleSec_GlobalRoot_Class_2.pem => 1e09d511.0
T-TeleSec_GlobalRoot_Class_2.pem => d06393bb.0
SZAFIR_ROOT_CA2.pem => fe8a2cd8.0
SZAFIR_ROOT_CA2.pem => a81e292b.0
Trustis_FPS_Root_CA.pem => d853d49e.0
Trustis_FPS_Root_CA.pem => c51c224c.0
DigiCert_Trusted_Root_G4.pem => 75d1b2ed.0
DigiCert_Trusted_Root_G4.pem => a2c66da8.0
IdenTrust_Commercial_Root_CA_1.pem => ef954a4e.0
IdenTrust_Commercial_Root_CA_1.pem => d18e9066.0
ssl-cert-snakeoil.pem => 2781bb9b.0
ssl-cert-snakeoil.pem => 548bcbf5.0
TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem => ff34af3f.0
TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem => 31188b5e.0
SwissSign_Gold_CA_-_G2.pem => 4f316efb.0
SwissSign_Gold_CA_-_G2.pem => 3c860d51.0
DigiCert_Global_Root_G2.pem => 607986c7.0
DigiCert_Global_Root_G2.pem => c90bc37d.0
CFCA_EV_ROOT.pem => 0b1b94ef.0
CFCA_EV_ROOT.pem => 9282e51c.0
Global_Chambersign_Root_-_2008.pem => 0c4c9b6c.0
Global_Chambersign_Root_-_2008.pem => 9f533518.0
Network_Solutions_Certificate_Authority.pem => 4304c5e5.0
Network_Solutions_Certificate_Authority.pem => 2fa87019.0
Swisscom_Root_CA_1.pem => 667c66d4.0
Swisscom_Root_CA_1.pem => e60bf0c0.0
GlobalSign_Root_CA.pem => 5ad8a5d6.0
GlobalSign_Root_CA.pem => b0f3e76e.0
AddTrust_Qualified_Certificates_Root.pem => e536d871.0
AddTrust_Qualified_Certificates_Root.pem => 052e396b.0
GlobalSign_ECC_Root_CA_-_R5.pem => 1d3472b9.0
GlobalSign_ECC_Root_CA_-_R5.pem => 2add47b6.0
GeoTrust_Primary_Certification_Authority_-_G3.pem => e2799e36.0
GeoTrust_Primary_Certification_Authority_-_G3.pem => c7e2a638.0
DigiCert_Global_Root_G3.pem => dd8e9d41.0
DigiCert_Global_Root_G3.pem => ed39abd0.0
Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem => 1320b215.0
Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem => 0708417d.0
Entrust_Root_Certification_Authority_-_EC1.pem => 106f3e4d.0
Entrust_Root_Certification_Authority_-_EC1.pem => b3fb433b.0
AffirmTrust_Premium.pem => b727005e.0
AffirmTrust_Premium.pem => dbc54cab.0
Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem => 26312675.0
Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem => b6782d18.0
QuoVadis_Root_CA_1_G3.pem => 749e9e03.0
QuoVadis_Root_CA_1_G3.pem => 52b525c7.0
S-TRUST_Universal_Root_CA.pem => 19c1fa33.0
S-TRUST_Universal_Root_CA.pem => 631c779f.0
GeoTrust_Primary_Certification_Authority_-_G2.pem => 116bf586.0
GeoTrust_Primary_Certification_Authority_-_G2.pem => 27af790d.0
TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem => 65b876bd.0
TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem => 418595b9.0
SecureSign_RootCA11.pem => 18856ac4.0
SecureSign_RootCA11.pem => ab5346f4.0
Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem => 4d4ba017.0
Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem => 8951b75e.0
Certum_Trusted_Network_CA.pem => 48bec511.0
Certum_Trusted_Network_CA.pem => 95aff9e3.0
Amazon_Root_CA_3.pem => 8cb5ee0f.0
Amazon_Root_CA_3.pem => 7a7c655d.0
DigiCert_Assured_ID_Root_CA.pem => b1159c4c.0
DigiCert_Assured_ID_Root_CA.pem => 69105f4f.0
Staat_der_Nederlanden_EV_Root_CA.pem => 03179a64.0
Staat_der_Nederlanden_EV_Root_CA.pem => 3c6676aa.0
Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem => 1636090b.0
Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem => 40dc992e.0
GlobalSign_Root_CA_-_R3.pem => 062cdee6.0
GlobalSign_Root_CA_-_R3.pem => 1e8e7201.0
Certigna.pem => e113c810.0
Certigna.pem => fde84897.0
QuoVadis_Root_CA.pem => 080911ac.0
QuoVadis_Root_CA.pem => 5cf9d536.0
AddTrust_Low-Value_Services_Root.pem => 861a399d.0
AddTrust_Low-Value_Services_Root.pem => e268a4c5.0
Actalis_Authentication_Root_CA.pem => 930ac5d2.0
Actalis_Authentication_Root_CA.pem => 5f47b495.0
ISRG_Root_X1.pem => 4042bcee.0
ISRG_Root_X1.pem => 6187b673.0
AddTrust_Public_Services_Root.pem => 8b59b1ad.0
AddTrust_Public_Services_Root.pem => a2df7ad7.0
D-TRUST_Root_CA_3_2013.pem => 0b7c536a.0
D-TRUST_Root_CA_3_2013.pem => c6127c60.0
DigiCert_Assured_ID_Root_G2.pem => 9d04f354.0
DigiCert_Assured_ID_Root_G2.pem => 8d6437c3.0
Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem => c0ff1f52.0
Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem => 7d453d8f.0
Baltimore_CyberTrust_Root.pem => 653b494a.0
Baltimore_CyberTrust_Root.pem => 3ad48a91.0
USERTrust_RSA_Certification_Authority.pem => fc5a8f99.0
USERTrust_RSA_Certification_Authority.pem => 35105088.0
AffirmTrust_Commercial.pem => 2b349938.0
AffirmTrust_Commercial.pem => e48193cf.0
CNNIC_ROOT.pem => bd1910d4.0
CNNIC_ROOT.pem => 895cad1a.0
Certplus_Root_CA_G1.pem => 9168f543.0
Certplus_Root_CA_G1.pem => 02756ea4.0
Buypass_Class_2_Root_CA.pem => 54657681.0
Buypass_Class_2_Root_CA.pem => 82223c44.0
China_Internet_Network_Information_Center_EV_Certificates_Root.pem => 1874d4aa.0
China_Internet_Network_Information_Center_EV_Certificates_Root.pem => 1676090a.0
OISTE_WISeKey_Global_Root_GA_CA.pem => b1b8a7f3.0
OISTE_WISeKey_Global_Root_GA_CA.pem => 3a3b02ce.0
TURKTRUST_Certificate_Services_Provider_Root_2007.pem => 592c0a9a.0
TURKTRUST_Certificate_Services_Provider_Root_2007.pem => d66b55d9.0
DigiCert_Assured_ID_Root_G3.pem => 7f3d5d1d.0
DigiCert_Assured_ID_Root_G3.pem => c491639e.0
E-Tugra_Certification_Authority.pem => 5273a94c.0
E-Tugra_Certification_Authority.pem => cb156124.0
Amazon_Root_CA_4.pem => de6d66f3.0
Amazon_Root_CA_4.pem => d41b5e2a.0
Microsec_e-Szigno_Root_CA_2009.pem => 8160b96c.0
Microsec_e-Szigno_Root_CA_2009.pem => e8651083.0
AC_Raíz_Certicámara_S.A..pem => 6f2c1157.0
AC_Raíz_Certicámara_S.A..pem => c8763593.0
AffirmTrust_Premium_ECC.pem => 9c8dfbd4.0
AffirmTrust_Premium_ECC.pem => ccc52f49.0
TWCA_Root_Certification_Authority.pem => b7a5b843.0
TWCA_Root_Certification_Authority.pem => b7db1890.0
TWCA_Global_Root_CA.pem => 5f15c80c.0
TWCA_Global_Root_CA.pem => b0ed035a.0
USERTrust_ECC_Certification_Authority.pem => f30dd6ad.0
USERTrust_ECC_Certification_Authority.pem => 04f60c28.0
thawte_Primary_Root_CA.pem => 2e4eed3c.0
thawte_Primary_Root_CA.pem => 00673b5b.0
GeoTrust_Primary_Certification_Authority.pem => 480720ec.0
GeoTrust_Primary_Certification_Authority.pem => 9772ca32.0
SwissSign_Platinum_CA_-_G2.pem => a8dee976.0
SwissSign_Platinum_CA_-_G2.pem => 46b2fd3b.0
Hongkong_Post_Root_CA_1.pem => 3e45d192.0
Hongkong_Post_Root_CA_1.pem => 9685a493.0
AffirmTrust_Networking.pem => 93bc0acc.0
AffirmTrust_Networking.pem => 86212b19.0
Comodo_Secure_Services_root.pem => c9f83a1c.0
Comodo_Secure_Services_root.pem => 02b73561.0
NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem => 988a38cb.0
NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem => 60afe812.0
Staat_der_Nederlanden_Root_CA_-_G2.pem => 5c44d531.0
Staat_der_Nederlanden_Root_CA_-_G2.pem => 3d441de8.0
COMODO_ECC_Certification_Authority.pem => eed8c118.0
COMODO_ECC_Certification_Authority.pem => 89c02a45.0
QuoVadis_Root_CA_3_G3.pem => e18bfb83.0
QuoVadis_Root_CA_3_G3.pem => e442e424.0
Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem => 62744ee1.0
Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem => 43eb08c7.0
Visa_eCommerce_Root.pem => a760e1bd.0
Visa_eCommerce_Root.pem => 6fcc125d.0
LuxTrust_Global_Root_2.pem => def36a68.0
LuxTrust_Global_Root_2.pem => c907e29b.0
Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem => 3bde41ac.0
Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem => d16a5865.0
GlobalSign_ECC_Root_CA_-_R4.pem => b0e59380.0
GlobalSign_ECC_Root_CA_-_R4.pem => 0d69c7e1.0
Certum_Root_CA.pem => 442adcac.0
Certum_Root_CA.pem => 6e8bf996.0
Camerfirma_Chambers_of_Commerce_Root.pem => f90208f7.0
Camerfirma_Chambers_of_Commerce_Root.pem => ee7cd6fb.0
VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem => b204d74a.0
VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem => facacbc6.0
OpenTrust_Root_CA_G1.pem => 87229d21.0
OpenTrust_Root_CA_G1.pem => 9c3323d4.0
GeoTrust_Global_CA_2.pem => cbeee9e2.0
GeoTrust_Global_CA_2.pem => 57692373.0
Deutsche_Telekom_Root_CA_2.pem => 812e17de.0
Deutsche_Telekom_Root_CA_2.pem => 4e18c148.0
Buypass_Class_3_Root_CA.pem => e8de2f56.0
Buypass_Class_3_Root_CA.pem => 2d9dafe4.0
Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem => 32888f65.0
Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem => dc99f41e.0
DST_ACES_CA_X6.pem => 790a7190.0
DST_ACES_CA_X6.pem => 1dac3003.0
thawte_Primary_Root_CA_-_G3.pem => ba89ed3b.0
thawte_Primary_Root_CA_-_G3.pem => 67495436.0
DST_Root_CA_X3.pem => 2e5ac55d.0
DST_Root_CA_X3.pem => 12d55845.0
Entrust.net_Premium_2048_Secure_Server_CA.pem => aee5f10d.0
Entrust.net_Premium_2048_Secure_Server_CA.pem => 3e7271e8.0
VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem => 7d0b38bd.0
VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem => 5e4e69e7.0
AddTrust_External_Root.pem => 157753a5.0
AddTrust_External_Root.pem => 3c58f906.0
Go_Daddy_Root_Certificate_Authority_-_G2.pem => cbf06781.0
Go_Daddy_Root_Certificate_Authority_-_G2.pem => bc3f2570.0
D-TRUST_Root_Class_3_CA_2_EV_2009.pem => d4dae3dd.0
D-TRUST_Root_Class_3_CA_2_EV_2009.pem => d7746a63.0
Security_Communication_EV_RootCA1.pem => 9d520b32.0
Security_Communication_EV_RootCA1.pem => 9dbefe7b.0
COMODO_RSA_Certification_Authority.pem => d6325660.0
COMODO_RSA_Certification_Authority.pem => d4c339cb.0
Starfield_Class_2_CA.pem => f387163d.0
Starfield_Class_2_CA.pem => 23f4c490.0
Comodo_Trusted_Services_root.pem => 56657bde.0
Comodo_Trusted_Services_root.pem => 124bbd54.0
TC_TrustCenter_Class_3_CA_II.pem => 5620c4aa.0
TC_TrustCenter_Class_3_CA_II.pem => 7a481e66.0
EC-ACC.pem => 349f2832.0
EC-ACC.pem => aeb67534.0
Taiwan_GRCA.pem => 6410666e.0
Taiwan_GRCA.pem => 1dcd6f4c.0
Amazon_Root_CA_1.pem => ce5e74ef.0
Amazon_Root_CA_1.pem => fd08c599.0
Chambers_of_Commerce_Root_-_2008.pem => c47d9980.0
Chambers_of_Commerce_Root_-_2008.pem => 1eb37bdf.0
UTN_USERFirst_Hardware_Root_CA.pem => b13cc6df.0
UTN_USERFirst_Hardware_Root_CA.pem => ff783690.0
Certinomis_-_Autorité_Racine.pem => d957f522.0
Certinomis_-_Autorité_Racine.pem => 7672ac4b.0
EE_Certification_Centre_Root_CA.pem => 128805a3.0
EE_Certification_Centre_Root_CA.pem => 91739615.0
OpenTrust_Root_CA_G2.pem => 608a55ad.0
OpenTrust_Root_CA_G2.pem => 3929ec9f.0
Cybertrust_Global_Root.pem => 76cb8f92.0
Cybertrust_Global_Root.pem => 343eb6cb.0
Izenpe.com.pem => cc450945.0
Izenpe.com.pem => 48a195d8.0
Go_Daddy_Class_2_CA.pem => f081611a.0
Go_Daddy_Class_2_CA.pem => 219d9499.0
DigiCert_High_Assurance_EV_Root_CA.pem => 244b5494.0
DigiCert_High_Assurance_EV_Root_CA.pem => 81b9768f.0
certSIGN_ROOT_CA.pem => 8d86cdd1.0
certSIGN_ROOT_CA.pem => 882de061.0
COMODO_Certification_Authority.pem => 40547a79.0
COMODO_Certification_Authority.pem => 5a3f0ff8.0
Sonera_Class_2_Root_CA.pem => 9c2e7d30.0
Sonera_Class_2_Root_CA.pem => a7605362.0
PSCProcert.pem => c5d3212a.0
PSCProcert.pem => 8c24b137.0
ACCVRAIZ1.pem => a94d09e5.0
ACCVRAIZ1.pem => 3c9a4d3b.0
GeoTrust_Universal_CA_2.pem => 8867006a.0
GeoTrust_Universal_CA_2.pem => 87753b0d.0
QuoVadis_Root_CA_3.pem => 76faf6c0.0
QuoVadis_Root_CA_3.pem => 9339512a.0
Comodo_AAA_Services_root.pem => ee64a828.0
Comodo_AAA_Services_root.pem => 75680d2e.0
Swisscom_Root_EV_CA_2.pem => 034868d6.0
Swisscom_Root_EV_CA_2.pem => 9ab62355.0
ComSign_CA.pem => bb2d49a0.0
ComSign_CA.pem => ff588423.0
TeliaSonera_Root_CA_v1.pem => 5cd81ad7.0
TeliaSonera_Root_CA_v1.pem => 63a2c897.0
Certinomis_-_Root_CA.pem => 9f0f5fd6.0
Certinomis_-_Root_CA.pem => d6e6eab9.0
UTN_USERFirst_Email_Root_CA.pem => c5e082db.0
UTN_USERFirst_Email_Root_CA.pem => 9ec3a561.0
GlobalSign_Root_CA_-_R2.pem => 4a6481c9.0
GlobalSign_Root_CA_-_R2.pem => 111e6273.0
Amazon_Root_CA_2.pem => 6d41d539.0
Amazon_Root_CA_2.pem => fb5fa911.0
CA_Disig_Root_R1.pem => 9007ae68.0
CA_Disig_Root_R1.pem => 21855f49.0
Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem => 7719f463.0
Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem => 9479c8c3.0
SecureTrust_CA.pem => f39fc864.0
SecureTrust_CA.pem => cf701eeb.0
GeoTrust_Global_CA.pem => 2c543cd1.0
GeoTrust_Global_CA.pem => 7999be0d.0
Swisscom_Root_CA_2.pem => 3efd4dc0.0
Swisscom_Root_CA_2.pem => 450c6e38.0
OpenTrust_Root_CA_G3.pem => 2c11d503.0
OpenTrust_Root_CA_G3.pem => 559f7c71.0
Security_Communication_Root_CA.pem => f3377b1b.0
Security_Communication_Root_CA.pem => a3896b44.0
Certplus_Root_CA_G2.pem => 451b5485.0
Certplus_Root_CA_G2.pem => d8317ada.0
QuoVadis_Root_CA_2.pem => d7e8dc79.0
QuoVadis_Root_CA_2.pem => 7a819ef2.0
VeriSign_Universal_Root_Certification_Authority.pem => c01cdfa2.0
VeriSign_Universal_Root_Certification_Authority.pem => 524d9b43.0
Starfield_Root_Certificate_Authority_-_G2.pem => 4bfab552.0
Starfield_Root_Certificate_Authority_-_G2.pem => 85cde254.0
Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem => ee1365c0.0
Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem => 11f154d6.0
CA_Disig_Root_R2.pem => 2ae6433e.0
CA_Disig_Root_R2.pem => 9576d26b.0
T-TeleSec_GlobalRoot_Class_3.pem => 5443e9e3.0
T-TeleSec_GlobalRoot_Class_3.pem => 1e1eab7c.0
TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem => 7992b8bb.0
TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem => 0d5a4e1c.0
Certplus_Class_2_Primary_CA.pem => f060240e.0
Certplus_Class_2_Primary_CA.pem => 17b51fe6.0
Certum_Trusted_Network_CA_2.pem => 40193066.0
Certum_Trusted_Network_CA_2.pem => cb1c3204.0
Starfield_Services_Root_Certificate_Authority_-_G2.pem => 09789157.0
Starfield_Services_Root_Certificate_Authority_-_G2.pem => 10531352.0
Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem => dc45b0bd.0
Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem => d78a75c7.0
spi-cacert-2008.pem => ec87c655.0
spi-cacert-2008.pem => 56e29e75.0
DigiCert_Global_Root_CA.pem => 3513523f.0
DigiCert_Global_Root_CA.pem => 399e7759.0
XRamp_Global_CA_Root.pem => 706f604c.0
XRamp_Global_CA_Root.pem => 76579174.0
thawte_Primary_Root_CA_-_G2.pem => c089bbbd.0
thawte_Primary_Root_CA_-_G2.pem => a7d2cf64.0
GeoTrust_Universal_CA.pem => ad088e1d.0
GeoTrust_Universal_CA.pem => e775ed2d.0
Camerfirma_Global_Chambersign_Root.pem => cb59f961.0
Camerfirma_Global_Chambersign_Root.pem => a0bc6fbb.0
IdenTrust_Public_Sector_Root_CA_1.pem => 1e08bfd1.0
IdenTrust_Public_Sector_Root_CA_1.pem => 4be590e0.0
Staat_der_Nederlanden_Root_CA_-_G3.pem => 5a4d6896.0
Staat_der_Nederlanden_Root_CA_-_G3.pem => 5a250ea7.0
Atos_TrustedRoot_2011.pem => e36a6752.0
Atos_TrustedRoot_2011.pem => b872f2b4.0
D-TRUST_Root_Class_3_CA_2_2009.pem => c28a8a30.0
D-TRUST_Root_Class_3_CA_2_2009.pem => 1df5a75f.0
ACEDICOM_Root.pem => 381ce4dd.0
ACEDICOM_Root.pem => ea169617.0
QuoVadis_Root_CA_2_G3.pem => 064e0aa9.0
QuoVadis_Root_CA_2_G3.pem => 1f58a078.0
ePKI_Root_Certification_Authority.pem => ca6e4ad9.0
ePKI_Root_Certification_Authority.pem => 9d6523ce.0
Secure_Global_CA.pem => b66938e9.0
Secure_Global_CA.pem => bdacca6f.0
OISTE_WISeKey_Global_Root_GB_CA.pem => e73d606e.0
OISTE_WISeKey_Global_Root_GB_CA.pem => dfc0fe80.0
Security_Communication_RootCA2.pem => cd58d51e.0
Security_Communication_RootCA2.pem => d59297b8.0
162 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d....
Replacing debian:ACCVRAIZ1.pem
Replacing debian:ACEDICOM_Root.pem
Replacing debian:AC_Raíz_Certicámara_S.A..pem
Replacing debian:Actalis_Authentication_Root_CA.pem
Replacing debian:AddTrust_External_Root.pem
Replacing debian:AddTrust_Low-Value_Services_Root.pem
Replacing debian:AddTrust_Public_Services_Root.pem
Replacing debian:AddTrust_Qualified_Certificates_Root.pem
Replacing debian:AffirmTrust_Commercial.pem
Replacing debian:AffirmTrust_Networking.pem
Replacing debian:AffirmTrust_Premium.pem
Replacing debian:AffirmTrust_Premium_ECC.pem
Replacing debian:Atos_TrustedRoot_2011.pem
Replacing debian:Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
Replacing debian:Baltimore_CyberTrust_Root.pem
Replacing debian:Buypass_Class_2_Root_CA.pem
Replacing debian:Buypass_Class_3_Root_CA.pem
Replacing debian:CA_Disig_Root_R1.pem
Replacing debian:CA_Disig_Root_R2.pem
Replacing debian:Camerfirma_Chambers_of_Commerce_Root.pem
Replacing debian:Camerfirma_Global_Chambersign_Root.pem
Replacing debian:Certigna.pem
Replacing debian:Certinomis_-_Autorité_Racine.pem
Replacing debian:Certinomis_-_Root_CA.pem
Replacing debian:Certplus_Class_2_Primary_CA.pem
Replacing debian:certSIGN_ROOT_CA.pem
Replacing debian:Certum_Root_CA.pem
Replacing debian:Certum_Trusted_Network_CA.pem
Replacing debian:CFCA_EV_ROOT.pem
Replacing debian:Chambers_of_Commerce_Root_-_2008.pem
Replacing debian:China_Internet_Network_Information_Center_EV_Certificates_Root.pem
Replacing debian:CNNIC_ROOT.pem
Replacing debian:Comodo_AAA_Services_root.pem
Replacing debian:COMODO_Certification_Authority.pem
Replacing debian:COMODO_ECC_Certification_Authority.pem
Replacing debian:COMODO_RSA_Certification_Authority.pem
Replacing debian:Comodo_Secure_Services_root.pem
Replacing debian:Comodo_Trusted_Services_root.pem
Replacing debian:ComSign_CA.pem
Replacing debian:Cybertrust_Global_Root.pem
Replacing debian:Deutsche_Telekom_Root_CA_2.pem
Replacing debian:DigiCert_Assured_ID_Root_CA.pem
Replacing debian:DigiCert_Assured_ID_Root_G2.pem
Replacing debian:DigiCert_Assured_ID_Root_G3.pem
Replacing debian:DigiCert_Global_Root_CA.pem
Replacing debian:DigiCert_Global_Root_G2.pem
Replacing debian:DigiCert_Global_Root_G3.pem
Replacing debian:DigiCert_High_Assurance_EV_Root_CA.pem
Replacing debian:DigiCert_Trusted_Root_G4.pem
Replacing debian:DST_ACES_CA_X6.pem
Replacing debian:DST_Root_CA_X3.pem
Replacing debian:D-TRUST_Root_Class_3_CA_2_2009.pem
Replacing debian:D-TRUST_Root_Class_3_CA_2_EV_2009.pem
Replacing debian:EC-ACC.pem
Replacing debian:EE_Certification_Centre_Root_CA.pem
Replacing debian:Entrust.net_Premium_2048_Secure_Server_CA.pem
Replacing debian:Entrust_Root_Certification_Authority.pem
Replacing debian:Entrust_Root_Certification_Authority_-_EC1.pem
Replacing debian:Entrust_Root_Certification_Authority_-_G2.pem
Replacing debian:ePKI_Root_Certification_Authority.pem
Replacing debian:E-Tugra_Certification_Authority.pem
Replacing debian:GeoTrust_Global_CA_2.pem
Replacing debian:GeoTrust_Global_CA.pem
Replacing debian:GeoTrust_Primary_Certification_Authority.pem
Replacing debian:GeoTrust_Primary_Certification_Authority_-_G2.pem
Replacing debian:GeoTrust_Primary_Certification_Authority_-_G3.pem
Replacing debian:GeoTrust_Universal_CA_2.pem
Replacing debian:GeoTrust_Universal_CA.pem
Replacing debian:Global_Chambersign_Root_-_2008.pem
Replacing debian:GlobalSign_ECC_Root_CA_-_R4.pem
Replacing debian:GlobalSign_ECC_Root_CA_-_R5.pem
Replacing debian:GlobalSign_Root_CA.pem
Replacing debian:GlobalSign_Root_CA_-_R2.pem
Replacing debian:GlobalSign_Root_CA_-_R3.pem
Replacing debian:Go_Daddy_Class_2_CA.pem
Replacing debian:Go_Daddy_Root_Certificate_Authority_-_G2.pem
Replacing debian:Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
Replacing debian:Hongkong_Post_Root_CA_1.pem
Replacing debian:IdenTrust_Commercial_Root_CA_1.pem
Replacing debian:IdenTrust_Public_Sector_Root_CA_1.pem
Replacing debian:Izenpe.com.pem
Replacing debian:Microsec_e-Szigno_Root_CA_2009.pem
Replacing debian:NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem
Replacing debian:Network_Solutions_Certificate_Authority.pem
Replacing debian:OISTE_WISeKey_Global_Root_GA_CA.pem
Replacing debian:OISTE_WISeKey_Global_Root_GB_CA.pem
Replacing debian:PSCProcert.pem
Replacing debian:QuoVadis_Root_CA_1_G3.pem
Replacing debian:QuoVadis_Root_CA_2.pem
Replacing debian:QuoVadis_Root_CA_2_G3.pem
Replacing debian:QuoVadis_Root_CA_3.pem
Replacing debian:QuoVadis_Root_CA_3_G3.pem
Replacing debian:QuoVadis_Root_CA.pem
Replacing debian:Secure_Global_CA.pem
Replacing debian:SecureSign_RootCA11.pem
Replacing debian:SecureTrust_CA.pem
Replacing debian:Security_Communication_EV_RootCA1.pem
Replacing debian:Security_Communication_RootCA2.pem
Replacing debian:Security_Communication_Root_CA.pem
Replacing debian:Sonera_Class_2_Root_CA.pem
Replacing debian:Staat_der_Nederlanden_EV_Root_CA.pem
Replacing debian:Staat_der_Nederlanden_Root_CA_-_G2.pem
Replacing debian:Staat_der_Nederlanden_Root_CA_-_G3.pem
Replacing debian:Starfield_Class_2_CA.pem
Replacing debian:Starfield_Root_Certificate_Authority_-_G2.pem
Replacing debian:Starfield_Services_Root_Certificate_Authority_-_G2.pem
Replacing debian:S-TRUST_Universal_Root_CA.pem
Replacing debian:Swisscom_Root_CA_1.pem
Replacing debian:Swisscom_Root_CA_2.pem
Replacing debian:Swisscom_Root_EV_CA_2.pem
Replacing debian:SwissSign_Gold_CA_-_G2.pem
Replacing debian:SwissSign_Platinum_CA_-_G2.pem
Replacing debian:SwissSign_Silver_CA_-_G2.pem
Replacing debian:Taiwan_GRCA.pem
Replacing debian:TC_TrustCenter_Class_3_CA_II.pem
Replacing debian:TeliaSonera_Root_CA_v1.pem
Replacing debian:thawte_Primary_Root_CA.pem
Replacing debian:thawte_Primary_Root_CA_-_G2.pem
Replacing debian:thawte_Primary_Root_CA_-_G3.pem
Replacing debian:Trustis_FPS_Root_CA.pem
Replacing debian:T-TeleSec_GlobalRoot_Class_2.pem
Replacing debian:T-TeleSec_GlobalRoot_Class_3.pem
Replacing debian:TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem
Replacing debian:TURKTRUST_Certificate_Services_Provider_Root_2007.pem
Replacing debian:TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem
Replacing debian:TWCA_Global_Root_CA.pem
Replacing debian:TWCA_Root_Certification_Authority.pem
Replacing debian:USERTrust_ECC_Certification_Authority.pem
Replacing debian:USERTrust_RSA_Certification_Authority.pem
Replacing debian:UTN_USERFirst_Email_Root_CA.pem
Replacing debian:UTN_USERFirst_Hardware_Root_CA.pem
Replacing debian:Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
Replacing debian:Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
Replacing debian:Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
Replacing debian:VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
Replacing debian:VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
Replacing debian:VeriSign_Universal_Root_Certification_Authority.pem
Replacing debian:Visa_eCommerce_Root.pem
Replacing debian:XRamp_Global_CA_Root.pem
Replacing debian:spi-cacert-2008.pem
Replacing debian:Certplus_Root_CA_G1.pem
Replacing debian:Certplus_Root_CA_G2.pem
Replacing debian:Certum_Trusted_Network_CA_2.pem
Replacing debian:Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
Replacing debian:Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
Replacing debian:ISRG_Root_X1.pem
Replacing debian:OpenTrust_Root_CA_G1.pem
Replacing debian:OpenTrust_Root_CA_G2.pem
Replacing debian:OpenTrust_Root_CA_G3.pem
Replacing debian:SZAFIR_ROOT_CA2.pem
Adding debian:AC_RAIZ_FNMT-RCM.pem
Adding debian:Amazon_Root_CA_1.pem
Adding debian:Amazon_Root_CA_2.pem
Adding debian:Amazon_Root_CA_3.pem
Adding debian:Amazon_Root_CA_4.pem
Adding debian:D-TRUST_Root_CA_3_2013.pem
Adding debian:LuxTrust_Global_Root_2.pem
Adding debian:Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
Adding debian:Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
Adding debian:Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
Adding debian:Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
Adding debian:TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
done.
done.
mshuler at hana:~$ 
mshuler at hana:~$ 
mshuler at hana:~$ keytool -list -v -keystore /etc/ssl/certs/java/cacerts | egrep 'ApplicationCA|StartCom|Microsec'
Enter keystore password:  changeit
Owner: OU=ApplicationCA, O=Japanese Government, C=JP
Issuer: OU=ApplicationCA, O=Japanese Government, C=JP
Owner: CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL
Issuer: CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL
Owner: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
Issuer: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
0000: 16 29 53 74 61 72 74 43   6F 6D 20 46 72 65 65 20  .)StartCom Free 
Owner: EMAILADDRESS=info at e-szigno.hu, CN=Microsec e-Szigno Root CA 2009, O=Microsec Ltd., L=Budapest, C=HU
Issuer: EMAILADDRESS=info at e-szigno.hu, CN=Microsec e-Szigno Root CA 2009, O=Microsec Ltd., L=Budapest, C=HU
Owner: CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU
Issuer: CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU
[CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU]
     [URIName: http://www.e-szigno.hu/RootCA.crl, URIName: ldap://ldap.e-szigno.hu/CN=Microsec%20e-Szigno%20Root%20CA,OU=e-Szigno%20CA,O=Microsec%20Ltd.,L=Budapest,C=HU?certificateRevocationList;binary]
  C=HU, L=Budapest, O=Microsec Kft., OU=e-Szignó HSZ, CN=Microsec e-Szignó Root CA
Owner: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
Issuer: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
0000: 16 29 53 74 61 72 74 43   6F 6D 20 46 72 65 65 20  .)StartCom Free 
mshuler at hana:~$


More information about the pkg-java-maintainers mailing list