-ca-certificates (20111022.1) UNRELEASED; urgency=low
+ca-certificates (20120112) unstable; urgency=low
- TODO: set version to release date
- s/UNRELEASED/unstable/
- dch --news with CA adds/removes list
- ? #643667 Broken symlinks on upgrade due to plain c_rehash call
+ * Update mozilla/certdata.txt to version 1.81
+ Certificates added (+) and removed (-):
+ + "Security Communication RootCA2"
+ + "EC-ACC"
+ + "Hellenic Academic and Research Institutions RootCA 2011"
+ - "Verisign Class 2 Public Primary Certification Authority"
+ - "Verisign Class 4 Public Primary Certification Authority - G2"
+ - "TC TrustCenter, Germany, Class 2 CA"
+ - "TC TrustCenter, Germany, Class 3 CA"
+ * Add notice to README.Debian deprecating CA inclusions and refer to
+ #647848 for Debian CA Certificate Policy discussion.
+
+ -- Michael Shuler <michael@pbandjelly.org> Sun, 12 Feb 2012 14:02:02 -0600
+
+ca-certificates (20111211) unstable; urgency=low
+
+ * Clarify CA audit note in package description and README.debian. Thanks
+ to C.J. Adams-Collier for the patch. Closes: #594383
+ * Remove French Government IGC/A CA certificates. The RSA certificate is
+ included in the Mozilla bundle and the DSA certificate is not in use.
+ Closes: #646767
+ * Remove expired signet.pl CAs. Closes: #647849
+ * Remove expired brasil.gov.br CA.
+ * Edit 20111025 changelog/NEWS entries to correctly list installed CAs
+ * Use 'set -e' in body of debian/postinst
+ * Update mozilla/certdata.txt to version 1.80
+ (no added/removed CAs)
+ * Update mozilla/certdata2pem.py to parse NETSCAPE or NSS data
+
+ -- Michael Shuler <michael@pbandjelly.org> Sun, 11 Dec 2011 19:05:32 -0600
+
+ca-certificates (20111025) unstable; urgency=low
[ Michael Shuler ]
* Add 3.0 (native) source format
+ "AffirmTrust Premium"
+ "AffirmTrust Premium ECC"
+ "A-Trust-nQual-03"
- + "Bogus Global Trustee"
- + "Bogus GMail"
- + "Bogus Google"
- + "Bogus kuix.de"
- + "Bogus live.com"
- + "Bogus Mozilla Addons"
- + "Bogus Skype"
- + "Bogus Yahoo 1"
- + "Bogus Yahoo 2"
- + "Bogus Yahoo 3"
+ "Certinomis - Autorité Racine"
+ "Certum Trusted Network CA"
- + "Explicitly Distrust DigiNotar Cyber CA"
- + "Explicitly Distrust DigiNotar Cyber CA 2nd"
- + "Explicitly Distrust DigiNotar Root CA"
- + "Explicitly Distrust DigiNotar Services 1024 CA"
- + "Explicitly Distrusted DigiNotar PKIoverheid"
- + "Explicitly Distrusted DigiNotar PKIoverheid G2"
+ "Go Daddy Root Certificate Authority - G2"
+ "Root CA Generalitat Valenciana"
+ "Starfield Root Certificate Authority - G2"
- "IPS Timestamping root"
- "Thawte Personal Freemail CA"
- "Thawte Time Stamping CA"
- * "Bogus *" CAs above address Comodo MITM 03/11 Closes: #619587
* Update CAcert-Class 3-Subroot-certificate Closes: #630232
- -- Michael Shuler <michael@pbandjelly.org> Sun, 23 Oct 2011 21:37:30 -0500
+ [ Steve Langasek ]
+ * sbin/update-ca-certificates: move the ca-certificates.crt bundle out of
+ the way before calling c_rehash, so that symlinks don't accidentally get
+ pointed here, breaking openssl certificate verification LP: #854927
+
+ [ Loïc Minier ]
+ * Drop bogus c_rehash on upgrades, which caused issue when
+ ca-certificates.crt was still in place; instead, call
+ update-ca-certificates --fresh on upgrades to this version, and
+ the usual update-ca-certificates otherwise Closes: #643667, #537382
+
+ -- Michael Shuler <michael@pbandjelly.org> Tue, 25 Oct 2011 09:12:10 -0500
ca-certificates (20111022) unstable; urgency=low