From 2e24aac01d41070c994d798590524e821d6d1d84 Mon Sep 17 00:00:00 2001 From: Pawel Winogrodzki Date: Mon, 24 Nov 2025 10:57:57 -0800 Subject: [PATCH] Added 2 CAs to 'ca-certificates-base': 'Microsoft TLS RSA Root G2' and 'Microsoft TLS ECC Root G2' --- .../ca-certificates.signatures.json | 2 +- SPECS/ca-certificates/ca-certificates.spec | 5 +- SPECS/ca-certificates/certdata.base.txt | 305 ++++++++++++++++++ .../prebuilt-ca-certificates-base.spec | 5 +- .../prebuilt-ca-certificates.spec | 5 +- .../manifests/package/pkggen_core_aarch64.txt | 8 +- .../manifests/package/pkggen_core_x86_64.txt | 8 +- .../manifests/package/toolchain_aarch64.txt | 10 +- .../manifests/package/toolchain_x86_64.txt | 10 +- 9 files changed, 336 insertions(+), 22 deletions(-) diff --git a/SPECS/ca-certificates/ca-certificates.signatures.json b/SPECS/ca-certificates/ca-certificates.signatures.json index 2c2ca0acc54..ab345e37c76 100644 --- a/SPECS/ca-certificates/ca-certificates.signatures.json +++ b/SPECS/ca-certificates/ca-certificates.signatures.json @@ -10,7 +10,7 @@ "README.src": "86184318d451bec55d70c84e618cbfe10c8adb7dc893964ce4aaecff99d83433", "README.usr": "0d2e90b6cf575678cd9d4f409d92258ef0d676995d4d733acdb2425309a38ff8", "bundle2pem.sh": "a61e0d9f34e21456cfe175e9a682f56959240e66dfeb75bd2457226226aa413a", - "certdata.base.txt": "771a6c9995ea00bb4ce50fd842a252454fe9b26acad8b0568a1055207442db57", + "certdata.base.txt": "482bb6e43102b679d83892f8afaf70b04ce935f029b1d503fabdfeaa48eb704c", "certdata.distrusted.txt": "536b1235c5b0b3c82ddf303eca696ec164cdb21899cd9e5313d8b29ce9cdc268", "certdata.microsoft.txt": "38cd7da10bce27751cfee01b2fdaa55f52321cdf1a408ec658bbf591b64cc484", "certdata2pem.py": "4f5848c14210758f19ab9fdc9ffd83733303a48642a3d47c4d682f904fdc0f33", diff --git a/SPECS/ca-certificates/ca-certificates.spec b/SPECS/ca-certificates/ca-certificates.spec index a324b211114..cda3f2e0a19 100644 --- a/SPECS/ca-certificates/ca-certificates.spec +++ b/SPECS/ca-certificates/ca-certificates.spec @@ -47,7 +47,7 @@ Name: ca-certificates # When updating, "Epoch, "Version", AND "Release" tags must be updated in the "prebuilt-ca-certificates*" packages as well. Epoch: 1 Version: 2.0.0 -Release: 24%{?dist} +Release: 25%{?dist} License: MPLv2.0 Vendor: Microsoft Corporation Distribution: Mariner @@ -340,6 +340,9 @@ rm -f %{pkidir}/tls/certs/*.{0,pem} %{_bindir}/bundle2pem.sh %changelog +* Mon Nov 24 2025 Pawel Winogrodzki - 1:2.0.0-25 +- Adding 2 new base CAs: 'Microsoft TLS RSA Root G2' and 'Microsoft TLS ECC Root G2'. + * Thu Oct 30 2025 Andrew Phelps - 1:2.0.0-24 - Revert: Adding 2 new base CAs: 'Microsoft TLS RSA Root G2' and 'Microsoft TLS ECC Root G2'. diff --git a/SPECS/ca-certificates/certdata.base.txt b/SPECS/ca-certificates/certdata.base.txt index ccec242c41e..ba3c76d4ee0 100644 --- a/SPECS/ca-certificates/certdata.base.txt +++ b/SPECS/ca-certificates/certdata.base.txt @@ -3194,3 +3194,308 @@ CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_MUST_VERIFY_TRUST CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE + +# +# Certificate "Microsoft TLS ECC Root G2" +# +# Issuer: CN=DigiCert Global Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US +# Serial Number:08:d3:c6:d0:01:f2:6c:b5:a2:3f:0c:7d:6a:73:ff:b6 +# Subject: CN=Microsoft TLS ECC Root G2,O=Microsoft Corporation,C=US +# Not Valid Before: Wed May 21 00:00:00 2025 +# Not Valid After : Tue Jun 19 23:59:59 2029 +# Fingerprint (SHA-256): 61:79:9E:35:94:F6:FA:6C:9F:61:90:31:E4:A3:C9:F6:43:FD:A3:8C:08:37:04:A5:07:5E:57:09:A2:1B:1A:B7 +# Fingerprint (SHA1): 7F:A0:5A:CF:9B:4A:AB:B0:DE:0C:FA:FA:29:7D:DF:92:FD:C5:F3:F5 +CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE +CKA_TOKEN CK_BBOOL CK_TRUE +CKA_PRIVATE CK_BBOOL CK_FALSE +CKA_MODIFIABLE CK_BBOOL CK_FALSE +CKA_LABEL UTF8 "Microsoft TLS ECC Root G2" +CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509 +CKA_SUBJECT MULTILINE_OCTAL +\060\121\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\036\060\034\006\003\125\004\012\023\025\115\151\143\162\157\163 +\157\146\164\040\103\157\162\160\157\162\141\164\151\157\156\061 +\042\060\040\006\003\125\004\003\023\031\115\151\143\162\157\163 +\157\146\164\040\124\114\123\040\105\103\103\040\122\157\157\164 +\040\107\062 +END +CKA_ID UTF8 "0" +CKA_ISSUER MULTILINE_OCTAL +\060\141\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\025\060\023\006\003\125\004\012\023\014\104\151\147\151\103\145 +\162\164\040\111\156\143\061\031\060\027\006\003\125\004\013\023 +\020\167\167\167\056\144\151\147\151\143\145\162\164\056\143\157 +\155\061\040\060\036\006\003\125\004\003\023\027\104\151\147\151 +\103\145\162\164\040\107\154\157\142\141\154\040\122\157\157\164 +\040\107\063 +END +CKA_SERIAL_NUMBER MULTILINE_OCTAL +\002\020\010\323\306\320\001\362\154\265\242\077\014\175\152\163 +\377\266 +END +CKA_VALUE MULTILINE_OCTAL +\060\202\003\073\060\202\002\300\240\003\002\001\002\002\020\010 +\323\306\320\001\362\154\265\242\077\014\175\152\163\377\266\060 +\012\006\010\052\206\110\316\075\004\003\003\060\141\061\013\060 +\011\006\003\125\004\006\023\002\125\123\061\025\060\023\006\003 +\125\004\012\023\014\104\151\147\151\103\145\162\164\040\111\156 +\143\061\031\060\027\006\003\125\004\013\023\020\167\167\167\056 +\144\151\147\151\143\145\162\164\056\143\157\155\061\040\060\036 +\006\003\125\004\003\023\027\104\151\147\151\103\145\162\164\040 +\107\154\157\142\141\154\040\122\157\157\164\040\107\063\060\036 +\027\015\062\065\060\065\062\061\060\060\060\060\060\060\132\027 +\015\062\071\060\066\061\071\062\063\065\071\065\071\132\060\121 +\061\013\060\011\006\003\125\004\006\023\002\125\123\061\036\060 +\034\006\003\125\004\012\023\025\115\151\143\162\157\163\157\146 +\164\040\103\157\162\160\157\162\141\164\151\157\156\061\042\060 +\040\006\003\125\004\003\023\031\115\151\143\162\157\163\157\146 +\164\040\124\114\123\040\105\103\103\040\122\157\157\164\040\107 +\062\060\166\060\020\006\007\052\206\110\316\075\002\001\006\005 +\053\201\004\000\042\003\142\000\004\121\302\070\204\366\153\056 +\265\355\067\026\112\345\343\327\115\000\204\073\100\124\374\011 +\346\364\305\247\246\153\126\104\116\255\140\236\025\230\216\003 +\356\342\262\315\165\075\130\144\300\026\014\337\132\334\054\235 +\100\133\276\113\124\052\316\217\074\277\225\274\216\254\211\357 +\151\076\027\006\367\175\301\270\002\145\043\313\365\035\032\343 +\123\241\364\007\176\012\213\135\131\243\202\001\113\060\202\001 +\107\060\017\006\003\125\035\023\001\001\377\004\005\060\003\001 +\001\377\060\035\006\003\125\035\016\004\026\004\024\157\253\176 +\332\377\227\103\162\354\073\147\167\336\202\141\065\210\107\102 +\205\060\037\006\003\125\035\043\004\030\060\026\200\024\263\333 +\110\244\371\241\305\330\256\066\101\314\021\143\151\142\051\274 +\113\306\060\016\006\003\125\035\017\001\001\377\004\004\003\002 +\001\206\060\023\006\003\125\035\045\004\014\060\012\006\010\053 +\006\001\005\005\007\003\001\060\166\006\010\053\006\001\005\005 +\007\001\001\004\152\060\150\060\044\006\010\053\006\001\005\005 +\007\060\001\206\030\150\164\164\160\072\057\057\157\143\163\160 +\056\144\151\147\151\143\145\162\164\056\143\157\155\060\100\006 +\010\053\006\001\005\005\007\060\002\206\064\150\164\164\160\072 +\057\057\143\141\143\145\162\164\163\056\144\151\147\151\143\145 +\162\164\056\143\157\155\057\104\151\147\151\103\145\162\164\107 +\154\157\142\141\154\122\157\157\164\107\063\056\143\162\164\060 +\102\006\003\125\035\037\004\073\060\071\060\067\240\065\240\063 +\206\061\150\164\164\160\072\057\057\143\162\154\063\056\144\151 +\147\151\143\145\162\164\056\143\157\155\057\104\151\147\151\103 +\145\162\164\107\154\157\142\141\154\122\157\157\164\107\063\056 +\143\162\154\060\023\006\003\125\035\040\004\014\060\012\060\010 +\006\006\147\201\014\001\002\002\060\012\006\010\052\206\110\316 +\075\004\003\003\003\151\000\060\146\002\061\000\205\120\245\373 +\133\054\116\210\034\250\107\365\216\353\271\316\244\324\361\031 +\061\317\357\343\245\203\317\306\367\227\227\027\034\061\030\024 +\134\042\042\171\255\223\022\050\374\033\363\321\002\061\000\201 +\157\056\115\215\354\064\230\320\123\265\355\261\166\146\222\017 +\150\040\373\105\276\270\003\137\005\161\145\016\331\070\126\056 +\323\243\317\160\023\016\036\360\336\305\040\250\262\221\055 +END +CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE +CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE +CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE + +# Trust for "Microsoft TLS ECC Root G2" +# Issuer: CN=DigiCert Global Root G3,OU=www.digicert.com,O=DigiCert Inc,C=US +# Serial Number:08:d3:c6:d0:01:f2:6c:b5:a2:3f:0c:7d:6a:73:ff:b6 +# Subject: CN=Microsoft TLS ECC Root G2,O=Microsoft Corporation,C=US +# Not Valid Before: Wed May 21 00:00:00 2025 +# Not Valid After : Tue Jun 19 23:59:59 2029 +# Fingerprint (SHA-256): 61:79:9E:35:94:F6:FA:6C:9F:61:90:31:E4:A3:C9:F6:43:FD:A3:8C:08:37:04:A5:07:5E:57:09:A2:1B:1A:B7 +# Fingerprint (SHA1): 7F:A0:5A:CF:9B:4A:AB:B0:DE:0C:FA:FA:29:7D:DF:92:FD:C5:F3:F5 +CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST +CKA_TOKEN CK_BBOOL CK_TRUE +CKA_PRIVATE CK_BBOOL CK_FALSE +CKA_MODIFIABLE CK_BBOOL CK_FALSE +CKA_LABEL UTF8 "Microsoft TLS ECC Root G2" +CKA_CERT_SHA1_HASH MULTILINE_OCTAL +\177\240\132\317\233\112\253\260\336\014\372\372\051\175\337\222 +\375\305\363\365 +END +CKA_CERT_MD5_HASH MULTILINE_OCTAL +\356\020\163\272\130\261\301\164\247\315\233\025\264\122\156\034 +END +CKA_ISSUER MULTILINE_OCTAL +\060\141\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\025\060\023\006\003\125\004\012\023\014\104\151\147\151\103\145 +\162\164\040\111\156\143\061\031\060\027\006\003\125\004\013\023 +\020\167\167\167\056\144\151\147\151\143\145\162\164\056\143\157 +\155\061\040\060\036\006\003\125\004\003\023\027\104\151\147\151 +\103\145\162\164\040\107\154\157\142\141\154\040\122\157\157\164 +\040\107\063 +END +CKA_SERIAL_NUMBER MULTILINE_OCTAL +\002\020\010\323\306\320\001\362\154\265\242\077\014\175\152\163 +\377\266 +END +CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR +CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_MUST_VERIFY_TRUST +CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST +CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE + +# +# Certificate "Microsoft TLS RSA Root G2" +# +# Issuer: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US +# Serial Number:0b:0c:6b:2c:46:69:17:b0:47:73:c6:47:d4:af:c0:c8 +# Subject: CN=Microsoft TLS RSA Root G2,O=Microsoft Corporation,C=US +# Not Valid Before: Wed May 21 00:00:00 2025 +# Not Valid After : Tue Jun 19 23:59:59 2029 +# Fingerprint (SHA-256): DD:CD:1E:8A:20:63:8D:4A:AF:F7:20:1B:B1:D5:64:52:AC:D2:C7:59:F1:68:6B:DC:38:F7:3D:D1:57:32:BD:C2 +# Fingerprint (SHA1): B5:EE:89:E7:73:26:AB:2B:F1:77:5B:D9:9C:19:A2:89:47:FF:81:84 +CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE +CKA_TOKEN CK_BBOOL CK_TRUE +CKA_PRIVATE CK_BBOOL CK_FALSE +CKA_MODIFIABLE CK_BBOOL CK_FALSE +CKA_LABEL UTF8 "Microsoft TLS RSA Root G2" +CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509 +CKA_SUBJECT MULTILINE_OCTAL +\060\121\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\036\060\034\006\003\125\004\012\023\025\115\151\143\162\157\163 +\157\146\164\040\103\157\162\160\157\162\141\164\151\157\156\061 +\042\060\040\006\003\125\004\003\023\031\115\151\143\162\157\163 +\157\146\164\040\124\114\123\040\122\123\101\040\122\157\157\164 +\040\107\062 +END +CKA_ID UTF8 "0" +CKA_ISSUER MULTILINE_OCTAL +\060\141\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\025\060\023\006\003\125\004\012\023\014\104\151\147\151\103\145 +\162\164\040\111\156\143\061\031\060\027\006\003\125\004\013\023 +\020\167\167\167\056\144\151\147\151\143\145\162\164\056\143\157 +\155\061\040\060\036\006\003\125\004\003\023\027\104\151\147\151 +\103\145\162\164\040\107\154\157\142\141\154\040\122\157\157\164 +\040\107\062 +END +CKA_SERIAL_NUMBER MULTILINE_OCTAL +\002\020\013\014\153\054\106\151\027\260\107\163\306\107\324\257 +\300\310 +END +CKA_VALUE MULTILINE_OCTAL +\060\202\005\211\060\202\004\161\240\003\002\001\002\002\020\013 +\014\153\054\106\151\027\260\107\163\306\107\324\257\300\310\060 +\015\006\011\052\206\110\206\367\015\001\001\014\005\000\060\141 +\061\013\060\011\006\003\125\004\006\023\002\125\123\061\025\060 +\023\006\003\125\004\012\023\014\104\151\147\151\103\145\162\164 +\040\111\156\143\061\031\060\027\006\003\125\004\013\023\020\167 +\167\167\056\144\151\147\151\143\145\162\164\056\143\157\155\061 +\040\060\036\006\003\125\004\003\023\027\104\151\147\151\103\145 +\162\164\040\107\154\157\142\141\154\040\122\157\157\164\040\107 +\062\060\036\027\015\062\065\060\065\062\061\060\060\060\060\060 +\060\132\027\015\062\071\060\066\061\071\062\063\065\071\065\071 +\132\060\121\061\013\060\011\006\003\125\004\006\023\002\125\123 +\061\036\060\034\006\003\125\004\012\023\025\115\151\143\162\157 +\163\157\146\164\040\103\157\162\160\157\162\141\164\151\157\156 +\061\042\060\040\006\003\125\004\003\023\031\115\151\143\162\157 +\163\157\146\164\040\124\114\123\040\122\123\101\040\122\157\157 +\164\040\107\062\060\202\002\042\060\015\006\011\052\206\110\206 +\367\015\001\001\001\005\000\003\202\002\017\000\060\202\002\012 +\002\202\002\001\000\337\352\213\237\107\341\050\020\161\257\101 +\326\031\333\222\127\336\153\253\346\056\336\255\072\140\203\267 +\023\230\254\133\271\062\013\173\353\237\162\047\153\135\100\253 +\276\030\006\223\262\015\322\022\355\270\164\365\177\057\352\250 +\027\224\366\063\026\127\212\336\040\174\041\335\267\332\254\336 +\116\144\260\132\315\113\165\363\357\002\144\115\355\122\332\243 +\217\004\350\221\370\327\373\077\031\375\116\105\071\136\350\051 +\303\326\362\147\257\263\000\224\301\215\341\360\112\030\230\071 +\372\300\011\204\063\101\005\003\005\253\364\165\341\123\245\041 +\222\134\104\114\346\140\127\244\220\002\227\307\325\330\223\004 +\062\112\355\205\121\355\326\305\272\240\077\066\212\057\157\114 +\071\250\004\151\042\204\073\165\024\367\331\076\264\251\320\007 +\101\070\201\176\106\110\035\350\031\346\160\270\240\252\030\335 +\162\277\176\175\265\154\116\031\160\021\204\004\023\201\324\142 +\375\234\153\361\034\335\377\354\247\340\346\307\215\061\113\277 +\362\153\063\314\321\214\266\376\261\033\243\112\250\137\016\177 +\061\166\070\077\007\107\154\001\250\254\245\024\332\202\260\137 +\037\154\274\211\032\300\022\052\313\173\227\037\050\056\061\026 +\212\123\114\165\146\371\175\001\326\302\140\252\145\217\061\236 +\162\313\314\233\055\345\104\031\223\127\253\156\216\302\331\056 +\145\260\162\055\347\241\303\241\176\111\035\131\147\326\011\324 +\030\022\155\300\225\105\170\311\361\140\152\344\366\356\006\044 +\073\163\112\132\021\302\076\227\141\300\170\356\357\023\247\060 +\342\112\070\055\356\130\027\023\040\267\066\052\337\013\062\264 +\302\070\261\221\335\022\260\105\266\174\300\261\035\142\241\235 +\335\161\022\025\226\001\235\012\011\365\261\335\263\331\340\070 +\102\064\366\151\266\303\257\026\163\376\324\103\370\103\344\130 +\371\117\263\363\354\326\075\224\072\100\070\025\253\014\206\320 +\144\316\032\143\350\204\224\125\011\132\266\004\266\321\076\232 +\025\307\144\021\200\320\033\202\016\115\377\105\236\262\145\007 +\045\037\333\232\310\306\354\326\133\205\120\004\237\034\313\135 +\040\202\147\236\171\342\337\350\362\350\157\304\040\162\060\206 +\345\235\165\047\065\002\003\001\000\001\243\202\001\113\060\202 +\001\107\060\017\006\003\125\035\023\001\001\377\004\005\060\003 +\001\001\377\060\035\006\003\125\035\016\004\026\004\024\336\221 +\206\110\267\241\061\131\061\361\113\137\007\251\334\210\171\332 +\250\166\060\037\006\003\125\035\043\004\030\060\026\200\024\116 +\042\124\040\030\225\346\343\156\346\017\372\372\271\022\355\006 +\027\217\071\060\016\006\003\125\035\017\001\001\377\004\004\003 +\002\001\206\060\023\006\003\125\035\045\004\014\060\012\006\010 +\053\006\001\005\005\007\003\001\060\166\006\010\053\006\001\005 +\005\007\001\001\004\152\060\150\060\044\006\010\053\006\001\005 +\005\007\060\001\206\030\150\164\164\160\072\057\057\157\143\163 +\160\056\144\151\147\151\143\145\162\164\056\143\157\155\060\100 +\006\010\053\006\001\005\005\007\060\002\206\064\150\164\164\160 +\072\057\057\143\141\143\145\162\164\163\056\144\151\147\151\143 +\145\162\164\056\143\157\155\057\104\151\147\151\103\145\162\164 +\107\154\157\142\141\154\122\157\157\164\107\062\056\143\162\164 +\060\102\006\003\125\035\037\004\073\060\071\060\067\240\065\240 +\063\206\061\150\164\164\160\072\057\057\143\162\154\063\056\144 +\151\147\151\143\145\162\164\056\143\157\155\057\104\151\147\151 +\103\145\162\164\107\154\157\142\141\154\122\157\157\164\107\062 +\056\143\162\154\060\023\006\003\125\035\040\004\014\060\012\060 +\010\006\006\147\201\014\001\002\002\060\015\006\011\052\206\110 +\206\367\015\001\001\014\005\000\003\202\001\001\000\013\274\264 +\053\067\164\305\113\247\066\002\066\306\257\341\023\314\212\232 +\227\033\374\343\104\214\356\124\000\345\344\101\032\106\360\013 +\166\064\377\231\125\142\065\252\255\212\234\014\132\142\314\103 +\300\313\352\112\035\275\153\035\257\261\031\045\146\234\367\171 +\156\133\045\200\044\201\205\307\171\055\065\137\102\011\170\355 +\237\342\145\325\304\040\120\202\020\217\152\072\355\030\216\110 +\211\253\246\011\370\341\200\374\006\165\026\047\045\132\217\270 +\072\160\154\030\107\360\143\364\123\016\331\025\065\040\363\221 +\075\023\001\240\342\372\044\010\105\126\167\321\147\251\061\102 +\320\127\377\032\046\276\305\103\330\127\251\143\377\257\363\072 +\330\366\173\113\020\242\227\241\317\146\276\147\147\011\371\265 +\114\347\253\031\053\277\042\075\175\336\306\367\357\143\070\054 +\335\126\304\371\011\122\332\337\343\210\157\325\155\153\367\010 +\101\057\216\076\206\061\237\361\174\112\365\326\141\244\106\106 +\050\357\127\272\260\157\222\330\322\167\045\355\173\246\051\316 +\073\162\171\021\324\340\247\124\155\065\053\244\172 +END +CKA_NSS_MOZILLA_CA_POLICY CK_BBOOL CK_TRUE +CKA_NSS_SERVER_DISTRUST_AFTER CK_BBOOL CK_FALSE +CKA_NSS_EMAIL_DISTRUST_AFTER CK_BBOOL CK_FALSE + +# Trust for "Microsoft TLS RSA Root G2" +# Issuer: CN=DigiCert Global Root G2,OU=www.digicert.com,O=DigiCert Inc,C=US +# Serial Number:0b:0c:6b:2c:46:69:17:b0:47:73:c6:47:d4:af:c0:c8 +# Subject: CN=Microsoft TLS RSA Root G2,O=Microsoft Corporation,C=US +# Not Valid Before: Wed May 21 00:00:00 2025 +# Not Valid After : Tue Jun 19 23:59:59 2029 +# Fingerprint (SHA-256): DD:CD:1E:8A:20:63:8D:4A:AF:F7:20:1B:B1:D5:64:52:AC:D2:C7:59:F1:68:6B:DC:38:F7:3D:D1:57:32:BD:C2 +# Fingerprint (SHA1): B5:EE:89:E7:73:26:AB:2B:F1:77:5B:D9:9C:19:A2:89:47:FF:81:84 +CKA_CLASS CK_OBJECT_CLASS CKO_NSS_TRUST +CKA_TOKEN CK_BBOOL CK_TRUE +CKA_PRIVATE CK_BBOOL CK_FALSE +CKA_MODIFIABLE CK_BBOOL CK_FALSE +CKA_LABEL UTF8 "Microsoft TLS RSA Root G2" +CKA_CERT_SHA1_HASH MULTILINE_OCTAL +\265\356\211\347\163\046\253\053\361\167\133\331\234\031\242\211 +\107\377\201\204 +END +CKA_CERT_MD5_HASH MULTILINE_OCTAL +\100\114\354\003\371\117\312\335\114\243\004\216\170\176\242\151 +END +CKA_ISSUER MULTILINE_OCTAL +\060\141\061\013\060\011\006\003\125\004\006\023\002\125\123\061 +\025\060\023\006\003\125\004\012\023\014\104\151\147\151\103\145 +\162\164\040\111\156\143\061\031\060\027\006\003\125\004\013\023 +\020\167\167\167\056\144\151\147\151\143\145\162\164\056\143\157 +\155\061\040\060\036\006\003\125\004\003\023\027\104\151\147\151 +\103\145\162\164\040\107\154\157\142\141\154\040\122\157\157\164 +\040\107\062 +END +CKA_SERIAL_NUMBER MULTILINE_OCTAL +\002\020\013\014\153\054\106\151\027\260\107\163\306\107\324\257 +\300\310 +END +CKA_TRUST_SERVER_AUTH CK_TRUST CKT_NSS_TRUSTED_DELEGATOR +CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_MUST_VERIFY_TRUST +CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_MUST_VERIFY_TRUST +CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE diff --git a/SPECS/prebuilt-ca-certificates-base/prebuilt-ca-certificates-base.spec b/SPECS/prebuilt-ca-certificates-base/prebuilt-ca-certificates-base.spec index 0684e5c52a3..2de43f2d6ae 100644 --- a/SPECS/prebuilt-ca-certificates-base/prebuilt-ca-certificates-base.spec +++ b/SPECS/prebuilt-ca-certificates-base/prebuilt-ca-certificates-base.spec @@ -3,7 +3,7 @@ Name: prebuilt-ca-certificates-base # When updating, "Epoch, "Version", AND "Release" tags must be updated in the "ca-certificates" package as well. Epoch: 1 Version: 2.0.0 -Release: 24%{?dist} +Release: 25%{?dist} License: MIT Vendor: Microsoft Corporation Distribution: Mariner @@ -46,6 +46,9 @@ find %{buildroot} -name README -delete %{_sysconfdir}/pki/java/cacerts %changelog +* Mon Nov 24 2025 Pawel Winogrodzki - 1:2.0.0-25 +- Making 'Release' match with 'ca-certificates' + * Thu Oct 30 2025 Andrew Phelps - 1:2.0.0-24 - Making 'Release' match with 'ca-certificates' diff --git a/SPECS/prebuilt-ca-certificates/prebuilt-ca-certificates.spec b/SPECS/prebuilt-ca-certificates/prebuilt-ca-certificates.spec index 21cd23f6d88..ada0843297d 100644 --- a/SPECS/prebuilt-ca-certificates/prebuilt-ca-certificates.spec +++ b/SPECS/prebuilt-ca-certificates/prebuilt-ca-certificates.spec @@ -3,7 +3,7 @@ Name: prebuilt-ca-certificates # When updating, "Epoch, "Version", AND "Release" tags must be updated in the "ca-certificates" package as well. Epoch: 1 Version: 2.0.0 -Release: 24%{?dist} +Release: 25%{?dist} License: MIT Vendor: Microsoft Corporation Distribution: Mariner @@ -49,6 +49,9 @@ find %{buildroot} -name README -delete %{_sysconfdir}/pki/java/cacerts %changelog +* Mon Nov 24 2025 Pawel Winogrodzki - 1:2.0.0-25 +- Making 'Release' match with 'ca-certificates' + * Thu Oct 30 2025 Andrew Phelps - 1:2.0.0-24 - Making 'Release' match with 'ca-certificates' diff --git a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt index 1e2b501c30c..be3b1cd4f06 100644 --- a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt @@ -231,10 +231,10 @@ libffi-devel-3.4.2-3.cm2.aarch64.rpm libtasn1-4.19.0-2.cm2.aarch64.rpm p11-kit-0.24.1-1.cm2.aarch64.rpm p11-kit-trust-0.24.1-1.cm2.aarch64.rpm -ca-certificates-shared-2.0.0-24.cm2.noarch.rpm -ca-certificates-tools-2.0.0-24.cm2.noarch.rpm -ca-certificates-base-2.0.0-24.cm2.noarch.rpm -ca-certificates-2.0.0-24.cm2.noarch.rpm +ca-certificates-shared-2.0.0-25.cm2.noarch.rpm +ca-certificates-tools-2.0.0-25.cm2.noarch.rpm +ca-certificates-base-2.0.0-25.cm2.noarch.rpm +ca-certificates-2.0.0-25.cm2.noarch.rpm dwz-0.14-2.cm2.aarch64.rpm unzip-6.0-22.cm2.aarch64.rpm python3-3.9.19-16.cm2.aarch64.rpm diff --git a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt index 020078b0e5e..9dace02fde9 100644 --- a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt @@ -231,10 +231,10 @@ libffi-devel-3.4.2-3.cm2.x86_64.rpm libtasn1-4.19.0-2.cm2.x86_64.rpm p11-kit-0.24.1-1.cm2.x86_64.rpm p11-kit-trust-0.24.1-1.cm2.x86_64.rpm -ca-certificates-shared-2.0.0-24.cm2.noarch.rpm -ca-certificates-tools-2.0.0-24.cm2.noarch.rpm -ca-certificates-base-2.0.0-24.cm2.noarch.rpm -ca-certificates-2.0.0-24.cm2.noarch.rpm +ca-certificates-shared-2.0.0-25.cm2.noarch.rpm +ca-certificates-tools-2.0.0-25.cm2.noarch.rpm +ca-certificates-base-2.0.0-25.cm2.noarch.rpm +ca-certificates-2.0.0-25.cm2.noarch.rpm dwz-0.14-2.cm2.x86_64.rpm unzip-6.0-22.cm2.x86_64.rpm python3-3.9.19-16.cm2.x86_64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_aarch64.txt b/toolkit/resources/manifests/package/toolchain_aarch64.txt index a70362fa129..71c55b0e8fb 100644 --- a/toolkit/resources/manifests/package/toolchain_aarch64.txt +++ b/toolkit/resources/manifests/package/toolchain_aarch64.txt @@ -18,11 +18,11 @@ bzip2-1.0.8-1.cm2.aarch64.rpm bzip2-debuginfo-1.0.8-1.cm2.aarch64.rpm bzip2-devel-1.0.8-1.cm2.aarch64.rpm bzip2-libs-1.0.8-1.cm2.aarch64.rpm -ca-certificates-2.0.0-24.cm2.noarch.rpm -ca-certificates-base-2.0.0-24.cm2.noarch.rpm -ca-certificates-legacy-2.0.0-24.cm2.noarch.rpm -ca-certificates-shared-2.0.0-24.cm2.noarch.rpm -ca-certificates-tools-2.0.0-24.cm2.noarch.rpm +ca-certificates-2.0.0-25.cm2.noarch.rpm +ca-certificates-base-2.0.0-25.cm2.noarch.rpm +ca-certificates-legacy-2.0.0-25.cm2.noarch.rpm +ca-certificates-shared-2.0.0-25.cm2.noarch.rpm +ca-certificates-tools-2.0.0-25.cm2.noarch.rpm ccache-4.8-1.cm2.aarch64.rpm ccache-debuginfo-4.8-1.cm2.aarch64.rpm check-0.15.2-1.cm2.aarch64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_x86_64.txt b/toolkit/resources/manifests/package/toolchain_x86_64.txt index 543aa88cdb8..92a1963509f 100644 --- a/toolkit/resources/manifests/package/toolchain_x86_64.txt +++ b/toolkit/resources/manifests/package/toolchain_x86_64.txt @@ -19,11 +19,11 @@ bzip2-1.0.8-1.cm2.x86_64.rpm bzip2-debuginfo-1.0.8-1.cm2.x86_64.rpm bzip2-devel-1.0.8-1.cm2.x86_64.rpm bzip2-libs-1.0.8-1.cm2.x86_64.rpm -ca-certificates-2.0.0-24.cm2.noarch.rpm -ca-certificates-base-2.0.0-24.cm2.noarch.rpm -ca-certificates-legacy-2.0.0-24.cm2.noarch.rpm -ca-certificates-shared-2.0.0-24.cm2.noarch.rpm -ca-certificates-tools-2.0.0-24.cm2.noarch.rpm +ca-certificates-2.0.0-25.cm2.noarch.rpm +ca-certificates-base-2.0.0-25.cm2.noarch.rpm +ca-certificates-legacy-2.0.0-25.cm2.noarch.rpm +ca-certificates-shared-2.0.0-25.cm2.noarch.rpm +ca-certificates-tools-2.0.0-25.cm2.noarch.rpm ccache-4.8-1.cm2.x86_64.rpm ccache-debuginfo-4.8-1.cm2.x86_64.rpm check-0.15.2-1.cm2.x86_64.rpm