]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
Add a couple -new certs
authorPeter Palfrader <peter@palfrader.org>
Wed, 9 Apr 2014 19:57:01 +0000 (21:57 +0200)
committerPeter Palfrader <peter@palfrader.org>
Wed, 9 Apr 2014 19:57:01 +0000 (21:57 +0200)
22 files changed:
modules/ssl/files/servicecerts/bugs.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/buildd.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/contributors.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/db.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/dsa.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/ftp-master.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/lists.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/munin.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/nagios.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/nm.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/packages.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/piuparts.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/release.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/rt.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/rtc.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/security-tracker.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/sip-ws.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/sso.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/udd.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/vote.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/wiki.debian.org-new.crt [new file with mode: 0644]
modules/ssl/files/servicecerts/www.debian.org-new.crt [new file with mode: 0644]

diff --git a/modules/ssl/files/servicecerts/bugs.debian.org-new.crt b/modules/ssl/files/servicecerts/bugs.debian.org-new.crt
new file mode 100644 (file)
index 0000000..4b31a0a
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            97:39:9f:11:db:27:d0:a4:d2:2b:c6:21:20:2d:85:3e
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  7 00:00:00 2014 GMT
+            Not After : Jan  7 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=bugs.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:ab:cb:85:28:c6:97:5e:2e:68:5b:ee:be:4d:2b:
+                    fb:c4:c6:fc:53:94:3d:91:e5:e6:fe:68:29:9b:fb:
+                    e6:71:03:37:07:23:39:9f:96:ee:a1:15:bb:8e:da:
+                    57:6b:45:e8:14:1f:cf:ed:a6:42:62:f0:9a:96:d4:
+                    85:98:8f:fd:6a:21:9f:d4:4b:d9:67:97:b7:57:13:
+                    db:7f:e0:28:80:53:47:01:7c:56:e9:71:34:19:54:
+                    cf:7a:51:be:3a:c1:fd:b3:db:e1:b5:a4:ab:66:db:
+                    9e:bb:58:63:00:ad:bc:ac:ce:1f:c1:87:a6:ef:3d:
+                    3b:08:fd:6b:c7:bf:94:b1:02:11:27:ca:ea:f4:d9:
+                    90:47:c2:da:c7:9b:c0:72:0d:01:2c:e2:59:d6:13:
+                    d4:e3:b7:03:06:f3:2d:06:ca:7f:40:4a:56:73:68:
+                    5c:2e:3a:03:50:70:e9:99:79:de:94:1f:bb:1f:79:
+                    9c:4d:d5:bc:ab:5e:a7:c5:5a:db:76:76:b4:18:8d:
+                    ac:f8:64:b5:fa:e1:2d:9d:47:68:19:47:00:85:4e:
+                    d2:81:e5:f4:70:d4:98:e1:63:15:12:84:2a:59:ef:
+                    bf:8d:57:33:31:67:de:4b:c9:54:1e:d4:02:67:b6:
+                    2e:88:df:e4:9a:2b:b2:0e:49:ed:7e:74:60:34:b4:
+                    f9:35:a4:e4:00:76:13:b1:c7:cf:a3:a6:40:e1:f8:
+                    81:11:d0:a3:3e:05:b5:a0:77:f0:3d:0e:63:c9:8d:
+                    d6:62:a5:cb:97:65:27:a6:63:97:01:84:80:7f:c7:
+                    1b:e2:53:3e:b4:fc:0b:6a:0d:e6:83:4c:a1:79:a9:
+                    ec:d8:63:b5:dc:00:1f:c5:44:31:bc:e2:13:34:b6:
+                    3c:08:fe:17:9d:0c:aa:98:d0:eb:62:e4:14:93:4b:
+                    e8:54:59:38:e2:a6:e0:a1:c7:3d:2f:13:44:be:31:
+                    71:da:4f:b0:54:95:df:69:c4:74:5a:e8:0c:c8:31:
+                    bb:8d:52:c7:7c:e3:ba:51:7b:a7
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                DF:CB:C3:B0:AF:7B:CE:34:89:32:55:AC:97:2C:0B:B2:EE:7D:20:E2
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:bugs.debian.org, DNS:www.bugs.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         58:67:eb:b1:a3:af:df:76:97:9f:bc:36:2b:a8:23:30:88:00:
+         b6:d7:a6:69:fa:3b:45:87:58:d9:6d:82:ea:ae:de:45:b1:15:
+         92:0c:79:60:0b:3e:44:49:cb:ae:c9:0b:ac:31:5f:ee:e7:67:
+         a2:74:ae:6f:37:46:db:74:da:07:28:66:d6:1a:6f:65:fc:ef:
+         00:60:dc:c6:23:6a:b1:12:da:b8:8d:e7:aa:f6:64:cf:55:6a:
+         bd:66:2f:80:e6:9c:21:d3:7c:1d:73:a9:c9:99:59:d9:40:6a:
+         2a:f0:df:2d:99:d1:64:91:57:52:3f:31:7a:3b:ad:b4:57:ef:
+         a4:8e:be:5d:71:15:c4:d8:a7:76:42:f0:3b:ea:4a:13:b9:3a:
+         ad:2c:37:32:b9:ce:bb:08:a1:4a:e7:4b:d4:66:fe:24:7e:57:
+         89:2c:0f:7f:ac:84:c7:56:7b:f8:a5:2d:05:9e:09:73:5c:f6:
+         c0:b1:91:be:74:0e:93:e6:b3:97:b8:2b:4c:5a:81:c0:90:72:
+         e4:5b:56:76:84:41:32:4c:1e:6d:06:66:e9:59:26:ab:35:02:
+         e8:fb:e9:f8:77:25:9f:28:57:59:8d:75:8c:f3:a7:aa:79:1a:
+         43:b9:b7:45:98:26:0e:09:8b:85:d7:e3:a2:b7:10:5f:c9:c1:
+         d7:b3:5e:d0
+-----BEGIN CERTIFICATE-----
+MIIFZjCCBE6gAwIBAgIRAJc5nxHbJ9Ck0ivGISAthT4wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDEwNzAwMDAwMFoXDTE1MDEwNzIzNTk1
+OVowWjEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGDAWBgNVBAMTD2J1Z3MuZGViaWFuLm9yZzCC
+AaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAKvLhSjGl14uaFvuvk0r+8TG
+/FOUPZHl5v5oKZv75nEDNwcjOZ+W7qEVu47aV2tF6BQfz+2mQmLwmpbUhZiP/Woh
+n9RL2WeXt1cT23/gKIBTRwF8VulxNBlUz3pRvjrB/bPb4bWkq2bbnrtYYwCtvKzO
+H8GHpu89Owj9a8e/lLECESfK6vTZkEfC2sebwHINASziWdYT1OO3AwbzLQbKf0BK
+VnNoXC46A1Bw6Zl53pQfux95nE3VvKtep8Va23Z2tBiNrPhktfrhLZ1HaBlHAIVO
+0oHl9HDUmOFjFRKEKlnvv41XMzFn3kvJVB7UAme2Lojf5Jorsg5J7X50YDS0+TWk
+5AB2E7HHz6OmQOH4gRHQoz4FtaB38D0OY8mN1mKly5dlJ6ZjlwGEgH/HG+JTPrT8
+C2oN5oNMoXmp7NhjtdwAH8VEMbziEzS2PAj+F50MqpjQ62LkFJNL6FRZOOKm4KHH
+PS8TRL4xcdpPsFSV32nEdFroDMgxu41Sx3zjulF7pwIDAQABo4IBvjCCAbowHwYD
+VR0jBBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFN/Lw7Cve840
+iTJVrJcsC7LufSDiMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1Ud
+JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQBsjEB
+AgIaMDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRyYWN0
+cy9mci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2GK2h0
+dHA6Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYIKwYB
+BQUHAQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9HYW5k
+aVN0YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5nYW5k
+aS5uZXQwLwYDVR0RBCgwJoIPYnVncy5kZWJpYW4ub3JnghN3d3cuYnVncy5kZWJp
+YW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQBYZ+uxo6/fdpefvDYrqCMwiAC216Zp
++jtFh1jZbYLqrt5FsRWSDHlgCz5EScuuyQusMV/u52eidK5vN0bbdNoHKGbWGm9l
+/O8AYNzGI2qxEtq4jeeq9mTPVWq9Zi+A5pwh03wdc6nJmVnZQGoq8N8tmdFkkVdS
+PzF6O620V++kjr5dcRXE2Kd2QvA76koTuTqtLDcyuc67CKFK50vUZv4kfleJLA9/
+rITHVnv4pS0FnglzXPbAsZG+dA6T5rOXuCtMWoHAkHLkW1Z2hEEyTB5tBmbpWSar
+NQLo++n4dyWfKFdZjXWM86eqeRpDubdFmCYOCYuF1+OitxBfycHXs17Q
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/buildd.debian.org-new.crt b/modules/ssl/files/servicecerts/buildd.debian.org-new.crt
new file mode 100644 (file)
index 0000000..9ae2d9a
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            69:6d:1a:3d:3b:1f:57:29:33:b5:e0:e9:d1:90:ae:f3
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=buildd.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d4:e0:c1:e7:6f:e0:ce:ee:71:cd:7e:b3:1d:88:
+                    50:3b:4b:44:7b:04:cf:0c:9f:9e:37:31:a6:9b:45:
+                    4d:f0:c8:6b:ba:4d:99:98:e1:c1:d1:6d:3b:7b:52:
+                    76:c2:4c:20:11:3e:19:1d:29:6f:46:9b:aa:02:05:
+                    40:a2:9b:7b:4a:17:27:0d:ff:2e:d1:17:dd:b3:d2:
+                    0d:28:f4:b0:0f:2f:8b:e2:9b:94:8e:f7:42:57:4b:
+                    55:43:8a:ee:5e:bc:5e:ae:fb:d7:ef:ce:ae:c3:88:
+                    a5:2a:ec:af:95:a9:e5:e0:d7:a6:6b:31:98:36:8b:
+                    ac:da:cd:2b:10:44:bd:be:eb:55:22:83:35:98:e8:
+                    7f:f3:38:30:6e:84:0b:17:09:64:9f:09:f5:5f:c6:
+                    98:03:6d:1e:61:85:5e:bf:6f:47:be:ae:42:c6:83:
+                    6a:94:42:2f:1a:42:9e:37:5e:33:bb:14:87:20:dc:
+                    e1:eb:33:20:65:db:94:57:21:9c:17:f2:37:83:4d:
+                    6f:e0:54:c1:23:4b:56:83:4c:81:05:e9:65:ea:37:
+                    98:db:2d:c5:3a:13:c9:5d:e5:4a:99:3a:b2:2a:0b:
+                    b5:25:42:6e:9d:45:95:8f:8f:d0:86:d5:46:7f:6b:
+                    a8:04:10:5c:3a:46:96:b6:de:94:44:e1:cd:e3:92:
+                    d6:cf:fa:4e:ea:c7:da:64:25:67:92:ed:2b:5d:42:
+                    cd:3c:2c:0c:74:8d:2e:53:6a:e0:61:6c:46:fc:be:
+                    16:e4:6f:7d:e9:6a:01:10:08:6b:4b:f0:f6:e6:d1:
+                    83:72:08:9f:df:56:e1:86:ba:27:cc:e4:75:8b:2e:
+                    a7:a7:46:ad:db:25:5e:a3:35:b0:62:14:9e:10:5f:
+                    ff:da:1f:cf:f4:01:17:12:9e:ef:81:5c:9d:51:02:
+                    46:08:f2:4a:d0:4e:7e:24:ef:d4:79:97:b8:35:9e:
+                    4f:57:59:fd:3d:b3:1f:94:79:2c:d5:ee:85:4d:07:
+                    e3:84:c3:01:6a:3c:f8:17:e1:cd
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                3A:84:A3:24:6A:49:E9:C8:E1:60:F8:13:73:06:49:2F:24:A3:C0:F6
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:buildd.debian.org, DNS:www.buildd.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         0d:56:6e:f3:f8:58:96:99:e1:79:e4:55:f7:32:d9:be:90:a4:
+         39:82:50:47:06:cb:1c:49:af:42:ae:4c:2b:bf:42:8d:6f:d2:
+         cf:76:ed:e4:71:8f:2a:35:9f:bd:b4:c1:5b:3d:f4:dd:5b:20:
+         4a:cd:89:d5:9b:3a:15:fe:c0:e9:87:ae:de:3e:8c:20:26:c8:
+         0a:4b:1f:58:8a:8c:87:e8:5f:f0:6b:5b:96:cf:6c:01:b1:d0:
+         9a:47:ab:87:a3:fe:3d:90:a1:3f:9c:ba:7d:29:0c:ff:01:76:
+         ba:9e:36:5f:c9:dd:a9:e8:be:39:5d:96:fa:0c:75:c7:78:48:
+         56:50:0d:f1:af:ae:ad:e9:d3:10:6c:79:85:d5:5d:75:4c:36:
+         c0:48:ca:89:94:5e:f4:af:f9:e1:aa:84:43:84:15:50:d5:3e:
+         2e:84:b5:95:b3:9f:c2:b2:83:a0:2c:9c:93:9b:32:27:40:d6:
+         4a:0f:1c:80:f8:c6:36:ad:dc:34:de:1e:a5:f1:98:9b:cd:31:
+         2b:1c:52:92:4f:2b:82:15:48:b4:8e:a3:04:49:de:31:89:bf:
+         5a:52:79:33:ff:62:83:42:8b:4b:ba:b7:1f:7e:b1:72:70:7b:
+         20:35:79:87:9b:f4:0e:b1:0f:5f:19:57:b3:2e:a1:d3:37:18:
+         9a:b0:08:0e
+-----BEGIN CERTIFICATE-----
+MIIFazCCBFOgAwIBAgIQaW0aPTsfVykzteDp0ZCu8zANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTMxMjMxMDAwMDAwWhcNMTQxMjMxMjM1OTU5
+WjBcMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEaMBgGA1UEAxMRYnVpbGRkLmRlYmlhbi5vcmcw
+ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDU4MHnb+DO7nHNfrMdiFA7
+S0R7BM8Mn543MaabRU3wyGu6TZmY4cHRbTt7UnbCTCARPhkdKW9Gm6oCBUCim3tK
+FycN/y7RF92z0g0o9LAPL4vim5SO90JXS1VDiu5evF6u+9fvzq7DiKUq7K+VqeXg
+16ZrMZg2i6zazSsQRL2+61UigzWY6H/zODBuhAsXCWSfCfVfxpgDbR5hhV6/b0e+
+rkLGg2qUQi8aQp43XjO7FIcg3OHrMyBl25RXIZwX8jeDTW/gVMEjS1aDTIEF6WXq
+N5jbLcU6E8ld5UqZOrIqC7UlQm6dRZWPj9CG1UZ/a6gEEFw6Rpa23pRE4c3jktbP
++k7qx9pkJWeS7StdQs08LAx0jS5TauBhbEb8vhbkb33pagEQCGtL8Pbm0YNyCJ/f
+VuGGuifM5HWLLqenRq3bJV6jNbBiFJ4QX//aH8/0ARcSnu+BXJ1RAkYI8krQTn4k
+79R5l7g1nk9XWf09sx+UeSzV7oVNB+OEwwFqPPgX4c0CAwEAAaOCAcIwggG+MB8G
+A1UdIwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBQ6hKMkaknp
+yOFg+BNzBkkvJKPA9jAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNV
+HSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIx
+AQICGjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFj
+dHMvZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6Athito
+dHRwOi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsG
+AQUFBwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2Fu
+ZGlTdGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2Fu
+ZGkubmV0MDMGA1UdEQQsMCqCEWJ1aWxkZC5kZWJpYW4ub3JnghV3d3cuYnVpbGRk
+LmRlYmlhbi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAA1WbvP4WJaZ4XnkVfcy2b6Q
+pDmCUEcGyxxJr0KuTCu/Qo1v0s927eRxjyo1n720wVs99N1bIErNidWbOhX+wOmH
+rt4+jCAmyApLH1iKjIfoX/BrW5bPbAGx0JpHq4ej/j2QoT+cun0pDP8BdrqeNl/J
+3anovjldlvoMdcd4SFZQDfGvrq3p0xBseYXVXXVMNsBIyomUXvSv+eGqhEOEFVDV
+Pi6EtZWzn8Kyg6AsnJObMidA1koPHID4xjat3DTeHqXxmJvNMSscUpJPK4IVSLSO
+owRJ3jGJv1pSeTP/YoNCi0u6tx9+sXJweyA1eYeb9A6xD18ZV7MuodM3GJqwCA4=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/contributors.debian.org-new.crt b/modules/ssl/files/servicecerts/contributors.debian.org-new.crt
new file mode 100644 (file)
index 0000000..249dc65
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            c1:ab:b8:fb:22:42:f5:b8:e5:b2:09:c9:d5:2b:4c:3c
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=contributors.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d3:51:7a:8f:18:0c:fe:c0:df:82:fe:e1:81:a6:
+                    c2:68:18:5d:7a:fd:f1:6e:7d:83:12:04:9a:75:cf:
+                    ac:3c:72:06:0f:e8:a2:de:0c:b3:be:02:95:84:ca:
+                    f0:14:25:70:ab:cc:6c:7a:33:01:99:0c:1b:6d:31:
+                    06:f8:c3:8f:f8:86:a0:18:02:9c:b0:6d:25:32:74:
+                    fa:99:9f:1d:16:ef:ff:e4:23:f1:1e:8c:11:bf:d8:
+                    d2:0d:f1:cc:b8:c5:50:7b:0f:89:bc:4b:74:59:68:
+                    5d:52:48:40:ef:72:87:c4:d6:78:92:5d:b2:23:40:
+                    6b:52:bb:a2:a8:64:d3:df:8a:ee:22:57:54:4e:2f:
+                    1e:39:8e:66:cc:62:98:44:51:cf:71:c4:3d:d2:9c:
+                    36:17:0c:a7:01:2d:dd:32:df:b0:1e:3f:b0:fc:ef:
+                    c7:6a:6b:ea:d9:e0:7f:ab:b4:0a:3d:89:a6:b3:c9:
+                    01:02:1c:d5:1e:20:4f:18:e4:04:a7:82:ca:71:02:
+                    bb:5f:51:1c:90:b3:04:77:ea:9e:6e:01:1c:23:3e:
+                    d8:14:b5:86:eb:03:7e:4a:32:25:20:1e:01:52:56:
+                    2a:1c:b8:cb:47:29:6e:77:40:95:2a:4e:f1:eb:e8:
+                    ab:4b:4a:22:fb:27:dc:92:c7:5d:83:18:16:bd:ec:
+                    b8:f4:89:5e:73:cb:2a:b8:b9:13:f4:87:5a:b2:ac:
+                    e8:86:9f:18:86:78:a7:fe:f6:c4:66:fa:46:4a:3b:
+                    6f:f5:b6:33:5c:f6:6f:41:0c:f2:7d:b4:7f:9c:0f:
+                    56:e4:5b:e6:51:57:37:bf:1c:f1:ec:9f:31:55:1f:
+                    ce:26:8d:82:88:99:2b:e1:f4:fb:69:b7:6f:36:5b:
+                    55:cf:a0:71:8f:82:0f:96:5f:84:39:6f:77:26:2f:
+                    34:2c:8a:f8:ad:8d:eb:d7:a7:d7:9a:1f:48:f8:40:
+                    03:1a:f0:da:1a:18:5e:f6:65:cb:43:65:c5:d7:42:
+                    3b:97:9c:34:88:f6:4f:20:eb:49
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                AE:F2:2B:58:B1:9F:1C:19:38:F2:6B:89:59:C4:F1:AB:E3:09:62:75
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:contributors.debian.org, DNS:www.contributors.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         5b:5d:10:32:5b:3a:ff:7e:13:e8:66:62:93:bf:e2:bd:8e:a5:
+         bd:dd:89:ef:f8:fa:b6:43:65:5d:0e:ed:9e:12:7a:df:0a:a3:
+         bb:45:a7:0c:2c:94:09:87:cd:a0:32:56:9f:2f:2c:89:ad:8d:
+         30:8b:56:28:17:fd:47:90:29:56:18:30:93:ea:76:59:31:4a:
+         46:0d:94:d0:54:8a:40:49:92:cb:26:9b:55:69:c2:72:91:d0:
+         81:79:a9:9b:9b:72:d8:24:fb:bd:5f:43:aa:d5:e3:af:71:cb:
+         ea:f5:be:3d:bb:55:e6:1e:6a:f3:f5:51:f9:43:34:1b:fa:88:
+         02:b2:f3:4e:74:20:af:93:a6:bc:48:3a:be:99:05:ad:c7:5c:
+         57:3b:7a:12:5d:04:22:ec:fa:fb:e8:a1:b8:f1:26:4e:ff:55:
+         d9:15:d7:f2:b2:d1:56:66:b2:ad:1d:12:8e:1a:f6:dc:04:a7:
+         de:fb:71:4f:0f:82:96:26:bd:0b:eb:68:30:fd:10:c6:4d:27:
+         79:ee:ee:4d:44:4d:8e:9a:2a:04:36:db:6c:e0:75:cb:36:93:
+         a5:2e:a3:bc:ba:19:0a:25:e7:f5:6d:90:5e:c6:76:15:fb:9d:
+         bf:ba:e7:71:2c:6d:02:34:c7:01:83:95:01:d2:41:ee:0c:7d:
+         f4:52:57:ef
+-----BEGIN CERTIFICATE-----
+MIIFfjCCBGagAwIBAgIRAMGruPsiQvW45bIJydUrTDwwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMTAwMDAwMFoXDTE0MTIzMTIzNTk1
+OVowYjEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxIDAeBgNVBAMTF2NvbnRyaWJ1dG9ycy5kZWJp
+YW4ub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEA01F6jxgM/sDf
+gv7hgabCaBhdev3xbn2DEgSadc+sPHIGD+ii3gyzvgKVhMrwFCVwq8xsejMBmQwb
+bTEG+MOP+IagGAKcsG0lMnT6mZ8dFu//5CPxHowRv9jSDfHMuMVQew+JvEt0WWhd
+UkhA73KHxNZ4kl2yI0BrUruiqGTT34ruIldUTi8eOY5mzGKYRFHPccQ90pw2Fwyn
+AS3dMt+wHj+w/O/Hamvq2eB/q7QKPYmms8kBAhzVHiBPGOQEp4LKcQK7X1EckLME
+d+qebgEcIz7YFLWG6wN+SjIlIB4BUlYqHLjLRylud0CVKk7x6+irS0oi+yfcksdd
+gxgWvey49Ilec8squLkT9Idasqzohp8Yhnin/vbEZvpGSjtv9bYzXPZvQQzyfbR/
+nA9W5FvmUVc3vxzx7J8xVR/OJo2CiJkr4fT7abdvNltVz6Bxj4IPll+EOW93Ji80
+LIr4rY3r16fXmh9I+EADGvDaGhhe9mXLQ2XF10I7l5w0iPZPIOtJAgMBAAGjggHO
+MIIByjAfBgNVHSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQU
+rvIrWLGfHBk48muJWcTxq+MJYnUwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQC
+MAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYL
+KwYBBAGyMQECAhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQv
+Y29udHJhY3RzL2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAx
+oC+gLYYraHR0cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNy
+bDBqBggrBgEFBQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGku
+bmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9v
+Y3NwLmdhbmRpLm5ldDA/BgNVHREEODA2ghdjb250cmlidXRvcnMuZGViaWFuLm9y
+Z4Ibd3d3LmNvbnRyaWJ1dG9ycy5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IB
+AQBbXRAyWzr/fhPoZmKTv+K9jqW93Ynv+Pq2Q2VdDu2eEnrfCqO7RacMLJQJh82g
+MlafLyyJrY0wi1YoF/1HkClWGDCT6nZZMUpGDZTQVIpASZLLJptVacJykdCBeamb
+m3LYJPu9X0Oq1eOvccvq9b49u1XmHmrz9VH5QzQb+ogCsvNOdCCvk6a8SDq+mQWt
+x1xXO3oSXQQi7Pr76KG48SZO/1XZFdfystFWZrKtHRKOGvbcBKfe+3FPD4KWJr0L
+62gw/RDGTSd57u5NRE2OmioENtts4HXLNpOlLqO8uhkKJef1bZBexnYV+52/uudx
+LG0CNMcBg5UB0kHuDH30Ulfv
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/db.debian.org-new.crt b/modules/ssl/files/servicecerts/db.debian.org-new.crt
new file mode 100644 (file)
index 0000000..0b81a4c
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            35:d0:d1:17:98:48:34:58:bb:90:07:8a:d1:f3:f9:16
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=db.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:df:fb:0e:56:59:29:1e:52:10:bc:c5:ee:b7:67:
+                    e8:b5:b1:b9:e6:e9:57:21:6e:d5:e5:e5:b7:3c:62:
+                    f8:c8:a0:f5:c4:74:65:90:f7:86:9d:09:71:4a:de:
+                    b0:00:4e:cc:4e:ba:02:e8:46:b5:c1:6e:b3:f2:7f:
+                    f3:c0:86:33:6a:f7:f6:ed:e7:e5:a7:39:3b:fe:18:
+                    a6:9e:7b:f7:de:d8:25:15:7b:db:97:4b:e2:85:fb:
+                    e5:5a:5c:e2:9f:23:10:8f:cb:c8:81:6d:79:93:76:
+                    db:38:af:f7:35:bb:a8:22:8a:6a:19:ea:d6:db:aa:
+                    0e:45:7e:f3:80:44:01:1a:55:74:86:9a:5a:69:ff:
+                    2a:ab:04:83:17:8d:2a:89:b2:38:bb:e7:f7:a2:15:
+                    09:30:05:ef:ca:ee:74:f9:89:1d:f4:82:97:ef:8d:
+                    16:68:34:ca:ee:c3:3f:2b:97:7f:c6:09:7c:0e:a3:
+                    f3:f9:05:b9:e6:a7:2b:60:75:cb:fc:30:f0:c4:9b:
+                    2f:78:80:76:02:f0:56:d4:49:93:04:58:c8:a9:fc:
+                    a7:9f:b2:6f:0c:d7:f4:bd:fa:19:68:18:b3:d3:97:
+                    52:7f:31:e3:de:13:e4:68:db:19:05:71:50:db:7b:
+                    a8:99:d1:b6:25:30:61:5a:22:38:04:6b:bf:51:08:
+                    d0:2a:b8:00:d5:d5:68:b0:dc:91:ce:72:d1:ad:8f:
+                    63:77:38:35:65:65:28:66:1b:77:17:50:0b:59:fa:
+                    9c:7f:77:99:60:c8:af:ab:ee:ec:95:f7:0a:a0:c3:
+                    af:c1:41:94:d5:55:b6:20:62:bf:4a:bf:7a:25:5b:
+                    f5:dc:c1:cc:e9:ed:b7:78:40:e8:63:89:14:0b:b0:
+                    0c:37:fb:83:b9:ea:1a:af:2a:a9:ca:fb:10:8c:95:
+                    07:cc:ad:43:95:cc:82:d2:c2:a6:62:64:2f:32:1d:
+                    45:87:dd:b1:03:1a:ed:c0:1b:97:44:c7:03:0c:17:
+                    8a:07:28:b4:50:34:69:82:0f:05
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                32:46:59:7C:E7:0A:EF:FE:AB:21:4B:0A:65:08:E1:C9:97:CB:50:C2
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:db.debian.org, DNS:www.db.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         af:a2:c7:b1:10:34:f8:14:a8:3c:78:ea:00:0f:89:f7:26:e9:
+         bd:85:bd:7a:be:82:d9:41:f6:1e:94:68:30:ce:ed:fc:43:ce:
+         6a:14:e5:5e:16:b5:d0:4c:e6:eb:c8:7c:e9:a9:78:db:82:c4:
+         f6:a3:d7:c7:14:96:3f:4f:3e:32:f7:78:ae:37:50:25:6e:eb:
+         0e:61:37:7a:76:ff:60:4f:bc:58:d0:46:1b:41:70:87:04:5a:
+         c3:1a:97:50:c2:b5:2f:ef:08:19:10:b7:59:52:81:de:3f:c6:
+         23:1f:2b:87:10:62:dc:11:bb:8e:e0:07:41:ee:33:69:5e:71:
+         81:c0:e3:61:02:e6:1a:ae:a5:8f:f6:b4:7a:39:e0:07:72:53:
+         8e:93:c6:05:10:72:6d:1e:89:c2:ed:62:e4:e3:21:84:16:75:
+         48:0c:f7:68:5e:0f:0f:1c:69:ec:b9:18:a2:f6:fd:39:98:33:
+         68:96:cb:f7:2c:14:b9:b8:b4:90:30:3c:cb:6f:cb:52:96:74:
+         94:04:8a:a6:08:b8:8f:4b:6f:8f:f1:3b:28:d2:c1:53:4b:20:
+         99:9b:13:31:3a:49:db:3d:b2:3c:6a:11:c5:38:09:ca:27:4d:
+         52:5a:ce:f1:d9:b6:70:51:57:c1:a2:45:82:9a:77:fc:60:43:
+         a2:7e:fd:9d
+-----BEGIN CERTIFICATE-----
+MIIFXzCCBEegAwIBAgIQNdDRF5hINFi7kAeK0fP5FjANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTMxMjMxMDAwMDAwWhcNMTQxMjMxMjM1OTU5
+WjBYMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEWMBQGA1UEAxMNZGIuZGViaWFuLm9yZzCCAaIw
+DQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAN/7DlZZKR5SELzF7rdn6LWxuebp
+VyFu1eXltzxi+Mig9cR0ZZD3hp0JcUresABOzE66AuhGtcFus/J/88CGM2r39u3n
+5ac5O/4Ypp57997YJRV725dL4oX75Vpc4p8jEI/LyIFteZN22ziv9zW7qCKKahnq
+1tuqDkV+84BEARpVdIaaWmn/KqsEgxeNKomyOLvn96IVCTAF78rudPmJHfSCl++N
+Fmg0yu7DPyuXf8YJfA6j8/kFueanK2B1y/ww8MSbL3iAdgLwVtRJkwRYyKn8p5+y
+bwzX9L36GWgYs9OXUn8x494T5GjbGQVxUNt7qJnRtiUwYVoiOARrv1EI0Cq4ANXV
+aLDckc5y0a2PY3c4NWVlKGYbdxdQC1n6nH93mWDIr6vu7JX3CqDDr8FBlNVVtiBi
+v0q/eiVb9dzBzOntt3hA6GOJFAuwDDf7g7nqGq8qqcr7EIyVB8ytQ5XMgtLCpmJk
+LzIdRYfdsQMa7cAbl0THAwwXigcotFA0aYIPBQIDAQABo4IBujCCAbYwHwYDVR0j
+BBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFDJGWXznCu/+qyFL
+CmUI4cmXy1DCMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQW
+MBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQBsjEBAgIa
+MDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRyYWN0cy9m
+ci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6
+Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYIKwYBBQUH
+AQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9HYW5kaVN0
+YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5nYW5kaS5u
+ZXQwKwYDVR0RBCQwIoINZGIuZGViaWFuLm9yZ4IRd3d3LmRiLmRlYmlhbi5vcmcw
+DQYJKoZIhvcNAQEFBQADggEBAK+ix7EQNPgUqDx46gAPifcm6b2FvXq+gtlB9h6U
+aDDO7fxDzmoU5V4WtdBM5uvIfOmpeNuCxPaj18cUlj9PPjL3eK43UCVu6w5hN3p2
+/2BPvFjQRhtBcIcEWsMal1DCtS/vCBkQt1lSgd4/xiMfK4cQYtwRu47gB0HuM2le
+cYHA42EC5hqupY/2tHo54AdyU46TxgUQcm0eicLtYuTjIYQWdUgM92heDw8caey5
+GKL2/TmYM2iWy/csFLm4tJAwPMtvy1KWdJQEiqYIuI9Lb4/xOyjSwVNLIJmbEzE6
+Sds9sjxqEcU4CconTVJazvHZtnBRV8GiRYKad/xgQ6J+/Z0=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/dsa.debian.org-new.crt b/modules/ssl/files/servicecerts/dsa.debian.org-new.crt
new file mode 100644 (file)
index 0000000..2228e45
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            63:97:d4:fe:d6:83:57:fe:e9:ca:da:cc:a5:50:d7:24
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=dsa.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:dd:23:62:3b:ff:51:5a:be:e6:16:a5:ea:21:f7:
+                    0d:d2:bb:9a:7a:53:f1:07:f1:45:37:4a:75:d3:72:
+                    07:d4:97:72:d1:fa:8d:17:db:d1:76:c1:68:bc:cd:
+                    be:b6:d8:80:84:6e:8e:0e:51:7a:3c:6f:20:0b:d5:
+                    b6:f6:f6:fd:f8:11:cd:af:38:5e:65:3c:94:f0:7f:
+                    26:62:aa:3d:84:84:70:2f:b6:7c:f1:ed:bd:c5:ff:
+                    03:51:ed:60:47:2f:4a:14:de:ef:22:c5:cc:a7:17:
+                    7e:39:80:4a:11:2d:61:3c:1b:d0:5e:c2:28:89:3a:
+                    a5:17:fd:21:a8:20:42:15:6e:78:72:27:b4:4f:0e:
+                    62:5c:0d:63:68:65:55:f2:fd:1a:dc:8d:56:3c:3d:
+                    00:6c:d3:fa:d3:b7:95:fe:cd:7d:48:1b:98:07:e6:
+                    0b:a8:7b:94:ea:67:47:51:cc:fa:cc:44:80:d3:12:
+                    58:ac:29:86:55:bf:35:30:6f:41:59:4f:3d:ee:b8:
+                    86:de:59:28:5b:81:79:f1:da:e4:75:f0:47:dd:e5:
+                    f0:fb:9c:03:11:85:88:ca:d0:5a:2f:68:5e:de:c3:
+                    f2:82:14:5e:f3:1f:83:a9:0e:c9:c6:10:54:94:21:
+                    8d:10:e5:58:51:e6:fd:61:08:e7:76:24:29:39:0f:
+                    7e:80:b7:69:3b:ed:62:39:5d:6b:91:e9:e4:7b:cb:
+                    f3:22:df:4f:3b:bc:26:4d:0f:bd:bd:77:c5:d2:55:
+                    62:4f:cb:4c:6b:70:d6:76:b9:f6:fd:be:2c:b3:31:
+                    fc:d9:39:58:36:1a:2d:e3:dc:04:5b:d8:b4:8c:ad:
+                    8d:03:16:08:a6:7c:7a:6c:04:a4:52:47:c7:c5:c0:
+                    b3:c2:d7:46:f6:57:61:bc:73:cd:90:bb:ee:1d:f2:
+                    8c:a5:25:cc:0d:91:bb:26:a0:46:f4:ca:6e:3b:0f:
+                    7e:af:7b:20:cf:78:bb:f4:10:6c:bb:0d:bb:8e:86:
+                    f9:cb:cd:b8:94:9f:f3:af:8a:85
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                1B:D8:A4:5A:A9:00:E8:FF:79:88:1D:38:C8:71:9D:35:D3:BB:98:E7
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:dsa.debian.org, DNS:www.dsa.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         7b:15:d3:17:b0:d0:53:fd:75:dd:d3:b5:01:e5:69:14:82:02:
+         99:f8:8a:d2:b3:d9:e6:fb:96:31:a2:29:5f:6e:d7:63:cd:21:
+         66:bf:73:5b:20:30:b6:8a:ac:6f:7c:63:f5:ed:9d:b7:5d:ed:
+         ac:cc:2d:65:5b:ac:ba:86:9e:90:51:21:ed:c8:05:52:37:fe:
+         fe:d3:bb:38:17:98:d5:90:4d:64:08:95:72:44:dd:e4:e7:fd:
+         53:9c:cf:09:0a:1c:4a:7e:55:14:f8:aa:71:ad:56:86:68:cd:
+         3c:be:38:85:72:fd:0a:20:99:e1:2e:3c:c0:51:ff:69:ba:66:
+         02:7e:6e:44:3f:c0:ed:33:4d:c1:0e:d5:aa:a1:b0:ea:39:72:
+         01:dc:c6:86:52:0d:74:38:0c:2f:41:2d:8e:af:60:9f:b7:a6:
+         29:ea:9c:8f:aa:32:22:95:74:13:98:5a:88:d8:ca:3d:d0:03:
+         55:be:9e:8b:fd:85:c3:d9:80:cc:d2:f9:d1:c1:9f:7d:2d:5e:
+         12:de:6b:e7:40:b7:50:eb:de:6c:a6:84:23:3f:a2:58:ee:db:
+         0d:4b:e7:d4:01:d0:5a:89:17:c5:96:67:bd:5b:fb:a0:30:58:
+         d6:2f:56:8b:fd:b2:00:be:b8:04:74:3b:33:17:cb:eb:06:05:
+         67:7b:c4:08
+-----BEGIN CERTIFICATE-----
+MIIFYjCCBEqgAwIBAgIQY5fU/taDV/7pytrMpVDXJDANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTQwMTAxMDAwMDAwWhcNMTUwMTAxMjM1OTU5
+WjBZMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEXMBUGA1UEAxMOZHNhLmRlYmlhbi5vcmcwggGi
+MA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDdI2I7/1FavuYWpeoh9w3Su5p6
+U/EH8UU3SnXTcgfUl3LR+o0X29F2wWi8zb622ICEbo4OUXo8byAL1bb29v34Ec2v
+OF5lPJTwfyZiqj2EhHAvtnzx7b3F/wNR7WBHL0oU3u8ixcynF345gEoRLWE8G9Be
+wiiJOqUX/SGoIEIVbnhyJ7RPDmJcDWNoZVXy/RrcjVY8PQBs0/rTt5X+zX1IG5gH
+5guoe5TqZ0dRzPrMRIDTElisKYZVvzUwb0FZTz3uuIbeWShbgXnx2uR18Efd5fD7
+nAMRhYjK0FovaF7ew/KCFF7zH4OpDsnGEFSUIY0Q5VhR5v1hCOd2JCk5D36At2k7
+7WI5XWuR6eR7y/Mi3087vCZND729d8XSVWJPy0xrcNZ2ufb9viyzMfzZOVg2Gi3j
+3ARb2LSMrY0DFgimfHpsBKRSR8fFwLPC10b2V2G8c82Qu+4d8oylJcwNkbsmoEb0
+ym47D36veyDPeLv0EGy7DbuOhvnLzbiUn/OvioUCAwEAAaOCAbwwggG4MB8GA1Ud
+IwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBQb2KRaqQDo/3mI
+HTjIcZ0107uY5zAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUE
+FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIxAQIC
+GjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFjdHMv
+ZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6AthitodHRw
+Oi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsGAQUF
+BwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2FuZGlT
+dGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2FuZGku
+bmV0MC0GA1UdEQQmMCSCDmRzYS5kZWJpYW4ub3JnghJ3d3cuZHNhLmRlYmlhbi5v
+cmcwDQYJKoZIhvcNAQEFBQADggEBAHsV0xew0FP9dd3TtQHlaRSCApn4itKz2eb7
+ljGiKV9u12PNIWa/c1sgMLaKrG98Y/Xtnbdd7azMLWVbrLqGnpBRIe3IBVI3/v7T
+uzgXmNWQTWQIlXJE3eTn/VOczwkKHEp+VRT4qnGtVoZozTy+OIVy/QogmeEuPMBR
+/2m6ZgJ+bkQ/wO0zTcEO1aqhsOo5cgHcxoZSDXQ4DC9BLY6vYJ+3pinqnI+qMiKV
+dBOYWojYyj3QA1W+nov9hcPZgMzS+dHBn30tXhLea+dAt1Dr3mymhCM/olju2w1L
+59QB0FqJF8WWZ71b+6AwWNYvVov9sgC+uAR0OzMXy+sGBWd7xAg=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/ftp-master.debian.org-new.crt b/modules/ssl/files/servicecerts/ftp-master.debian.org-new.crt
new file mode 100644 (file)
index 0000000..b37a267
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            b6:92:cd:35:fc:67:48:97:cc:f6:65:5a:05:74:71:a5
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=ftp-master.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:9c:19:aa:17:5d:3f:1a:9f:83:3e:3d:e8:ae:5d:
+                    cc:89:fa:53:1c:1d:8f:9f:1a:9d:14:51:6c:18:41:
+                    44:80:d3:aa:44:2b:0f:f4:5f:50:5a:46:c7:21:9d:
+                    55:8c:90:74:4b:62:e3:6e:40:75:fd:32:60:74:53:
+                    98:7a:3f:dc:af:6f:68:f8:b9:a7:02:72:f3:f7:be:
+                    fb:de:a0:d6:e9:e0:53:02:3d:8b:3a:bd:e2:b6:c6:
+                    eb:58:3d:a9:52:8e:4e:66:d8:13:3c:4d:72:09:61:
+                    1c:23:88:40:ca:c8:68:db:16:c6:d2:57:24:ff:0d:
+                    f3:24:56:c6:6b:0d:83:e7:19:60:c3:bc:0a:bb:8d:
+                    b8:a2:b1:5d:77:16:24:5e:69:51:85:38:c5:5f:8b:
+                    34:29:02:bc:bc:31:d3:06:24:74:8e:ec:18:d8:86:
+                    b1:41:a9:c6:ea:d2:3e:5a:8e:94:e4:5d:b9:b6:72:
+                    04:1d:ac:40:c2:24:c3:2c:68:da:84:c3:99:e7:76:
+                    c4:c7:75:7a:0d:a5:5c:43:83:3d:b7:78:e7:20:e3:
+                    cc:d0:1e:24:b9:cc:2f:6a:d4:8e:f7:97:a1:1e:8e:
+                    61:30:87:f5:71:82:1f:ae:9b:78:83:ad:73:6a:90:
+                    e1:52:9d:0d:be:39:e9:9d:3c:64:5a:64:de:a1:64:
+                    1d:ad:e4:90:13:40:b2:af:9d:37:8d:f5:b2:c1:27:
+                    94:1d:da:52:e3:ac:5c:03:af:2c:ce:3f:7a:87:d1:
+                    4c:d9:54:e4:77:2c:5b:1a:ff:66:39:d2:ba:93:93:
+                    ff:bc:8e:8b:c5:f2:f6:18:59:a5:bd:73:d2:e8:b4:
+                    7f:77:16:65:17:3c:df:32:60:c0:c8:83:ba:de:27:
+                    c7:f4:3a:2b:6b:c9:ff:d9:60:39:d2:b3:20:f7:47:
+                    8d:1e:fd:e3:97:49:af:c5:f9:15:07:01:02:c5:71:
+                    40:14:18:76:96:24:81:9c:1e:45:1a:c4:a0:c0:06:
+                    8d:f8:83:45:ac:9e:6e:97:5e:23
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                C8:6D:7F:2E:48:0D:5C:A1:DB:6F:71:E7:34:F3:C1:E4:17:BE:DE:72
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:ftp-master.debian.org, DNS:www.ftp-master.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         9c:a9:46:37:fe:c0:bd:cf:6a:db:70:4b:43:f1:94:72:6f:b2:
+         8e:c6:2a:7a:c4:42:7e:39:30:53:9c:8d:25:e4:fe:c1:10:15:
+         36:69:db:4f:2c:21:5a:69:9c:e0:14:1a:2d:ed:c3:4b:6f:b0:
+         17:ab:da:69:6d:6d:4f:e8:3f:4e:e6:67:01:bc:0c:03:86:b6:
+         cc:50:97:02:36:c0:ae:6a:62:9c:bf:2b:31:db:7f:83:76:1c:
+         52:c4:6b:0e:06:ef:f6:e7:a1:fb:6a:c5:8f:21:5c:13:61:7a:
+         4f:fe:e5:59:c5:16:30:3c:cc:10:96:c6:f7:2f:f1:77:87:27:
+         ce:3b:9d:8a:78:39:0b:65:a5:87:56:5b:ce:23:ef:4d:ea:b7:
+         e5:6f:bb:d3:83:e7:5f:6f:92:a9:23:e8:b8:8a:a0:8d:73:89:
+         55:0d:a3:80:b4:26:d2:c9:70:14:80:cd:68:a3:96:c6:17:d2:
+         b9:12:78:23:f0:a1:35:f0:95:a3:48:97:8a:45:8c:e6:ca:0a:
+         f4:a8:8a:0d:a4:c9:80:98:ed:91:77:45:3c:74:e3:b5:9e:39:
+         63:d7:08:74:71:7b:12:cf:c4:34:1e:47:2b:a1:a3:2c:eb:21:
+         4e:8e:41:5d:7b:5a:a9:79:8e:1d:09:15:a8:b4:d0:f6:73:c8:
+         90:cd:8c:3c
+-----BEGIN CERTIFICATE-----
+MIIFeDCCBGCgAwIBAgIRALaSzTX8Z0iXzPZlWgV0caUwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDEwMTAwMDAwMFoXDTE1MDEwMTIzNTk1
+OVowYDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxHjAcBgNVBAMTFWZ0cC1tYXN0ZXIuZGViaWFu
+Lm9yZzCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAJwZqhddPxqfgz49
+6K5dzIn6Uxwdj58anRRRbBhBRIDTqkQrD/RfUFpGxyGdVYyQdEti425Adf0yYHRT
+mHo/3K9vaPi5pwJy8/e++96g1ungUwI9izq94rbG61g9qVKOTmbYEzxNcglhHCOI
+QMrIaNsWxtJXJP8N8yRWxmsNg+cZYMO8CruNuKKxXXcWJF5pUYU4xV+LNCkCvLwx
+0wYkdI7sGNiGsUGpxurSPlqOlORdubZyBB2sQMIkwyxo2oTDmed2xMd1eg2lXEOD
+Pbd45yDjzNAeJLnML2rUjveXoR6OYTCH9XGCH66beIOtc2qQ4VKdDb456Z08ZFpk
+3qFkHa3kkBNAsq+dN431ssEnlB3aUuOsXAOvLM4/eofRTNlU5HcsWxr/ZjnSupOT
+/7yOi8Xy9hhZpb1z0ui0f3cWZRc83zJgwMiDut4nx/Q6K2vJ/9lgOdKzIPdHjR79
+45dJr8X5FQcBAsVxQBQYdpYkgZweRRrEoMAGjfiDRayebpdeIwIDAQABo4IByjCC
+AcYwHwYDVR0jBBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFMht
+fy5IDVyh229x5zTzweQXvt5yMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAA
+MB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysG
+AQQBsjEBAgIaMDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2Nv
+bnRyYWN0cy9mci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAv
+oC2GK2h0dHA6Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmww
+agYIKwYBBQUHAQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5l
+dC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2Nz
+cC5nYW5kaS5uZXQwOwYDVR0RBDQwMoIVZnRwLW1hc3Rlci5kZWJpYW4ub3Jnghl3
+d3cuZnRwLW1hc3Rlci5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCcqUY3
+/sC9z2rbcEtD8ZRyb7KOxip6xEJ+OTBTnI0l5P7BEBU2adtPLCFaaZzgFBot7cNL
+b7AXq9ppbW1P6D9O5mcBvAwDhrbMUJcCNsCuamKcvysx23+DdhxSxGsOBu/256H7
+asWPIVwTYXpP/uVZxRYwPMwQlsb3L/F3hyfOO52KeDkLZaWHVlvOI+9N6rflb7vT
+g+dfb5KpI+i4iqCNc4lVDaOAtCbSyXAUgM1oo5bGF9K5Engj8KE18JWjSJeKRYzm
+ygr0qIoNpMmAmO2Rd0U8dOO1njlj1wh0cXsSz8Q0HkcroaMs6yFOjkFde1qpeY4d
+CRWotND2c8iQzYw8
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/lists.debian.org-new.crt b/modules/ssl/files/servicecerts/lists.debian.org-new.crt
new file mode 100644 (file)
index 0000000..05551cf
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            b6:06:f4:9b:df:6d:e1:8e:38:5d:5d:00:6c:10:97:7d
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 30 00:00:00 2013 GMT
+            Not After : Dec 30 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=lists.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:c5:79:01:0f:20:72:4e:cb:76:ea:bb:65:d9:98:
+                    6c:4d:cb:2f:73:51:d8:a5:f6:ad:f3:2f:a1:24:5d:
+                    50:3b:f8:61:31:46:a1:19:ab:8e:b9:e6:34:19:48:
+                    ea:72:d8:9f:69:8a:fe:e9:5e:90:6b:49:ac:88:16:
+                    19:d0:75:3c:86:56:3c:a3:c8:51:03:e5:74:1d:71:
+                    b7:4a:b5:a4:ca:ff:29:b0:18:4e:34:21:5b:57:20:
+                    e3:0c:78:2d:61:d1:b2:f1:4a:d2:7f:6c:37:59:c1:
+                    6e:15:2a:f8:69:50:29:e6:5d:b2:22:1c:96:08:1f:
+                    01:d5:8a:b3:53:ae:e4:3b:1e:d4:31:33:44:c5:d3:
+                    a9:b1:f2:1c:10:26:3c:ed:e8:6d:2d:85:ad:06:2c:
+                    f7:4d:b4:82:a4:c4:c5:5c:4e:bb:08:ba:a6:c1:42:
+                    e0:c3:e6:e8:de:42:43:d7:dd:e8:ae:e9:c9:bd:56:
+                    db:d8:21:a5:f1:c8:2d:35:99:15:6a:cc:a7:7c:35:
+                    d8:fe:25:41:78:40:a4:b6:b0:55:ae:a9:53:8e:5c:
+                    51:21:23:41:89:d6:f2:61:e8:0e:34:89:7d:72:0d:
+                    26:3a:f1:1c:9d:27:09:cc:f6:89:7d:15:3c:27:84:
+                    eb:d8:01:5c:35:a8:ad:fa:54:c9:7f:ef:42:b0:bc:
+                    ff:7a:20:f4:0b:00:84:48:50:c4:fe:53:ae:bd:d9:
+                    da:e8:da:c4:81:e4:a7:2b:8d:16:5a:9f:92:39:c6:
+                    67:bd:b8:a0:10:02:e7:eb:9c:db:67:20:76:3b:6d:
+                    ec:d1:59:d1:33:f8:4a:dc:a2:31:0e:99:d4:ac:fd:
+                    d2:b7:40:a2:11:26:0a:12:08:4a:33:ad:0b:a8:e8:
+                    87:63:53:9d:9d:89:0f:66:da:6c:a2:a7:bf:40:d4:
+                    5b:b3:f5:2d:b9:73:cd:c7:3a:2f:41:94:58:92:a8:
+                    6c:23:bf:85:44:de:1c:c1:62:69:0b:ab:4f:8c:b5:
+                    86:98:7a:2f:42:fd:d7:09:57:bd
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                D3:88:E4:8A:C4:E7:38:88:4F:8A:64:35:DD:6B:48:01:77:FC:D4:29
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:lists.debian.org, DNS:www.lists.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         18:f8:a4:da:b9:79:12:e3:b7:b9:cb:6f:0b:a7:f8:ca:6d:d9:
+         77:fe:a0:0d:ef:f1:c7:93:b1:8b:15:8d:d3:d1:21:b5:0c:67:
+         f8:ab:17:47:66:95:01:03:16:17:a0:2d:20:7c:98:64:15:cd:
+         f1:d0:9b:0b:1d:f2:10:50:a2:e4:4b:5e:26:0b:c3:bb:3b:cf:
+         0a:c2:5c:bc:4b:65:64:9f:03:50:f8:e1:ad:22:79:0b:a1:a5:
+         df:67:53:c0:89:ec:f7:48:11:5e:bb:29:d4:90:65:11:9c:c1:
+         51:09:ad:64:6f:dd:dc:16:e6:b2:0c:41:ab:86:2e:a5:52:98:
+         e4:31:27:1e:68:a3:59:2f:b3:59:cc:2b:bb:b1:b1:ea:a7:69:
+         f9:3f:0d:ac:8a:45:1e:09:4d:67:14:b2:33:34:74:39:db:33:
+         b7:9d:55:2e:df:28:44:6f:be:fe:7a:ae:21:9c:f3:0b:5d:2a:
+         8e:6d:98:62:a0:16:4b:b2:d8:1f:59:7a:08:80:26:62:f1:af:
+         b9:84:31:f8:81:62:50:55:43:a6:4e:e5:db:90:29:ec:36:f8:
+         19:7f:f0:5c:66:f5:0c:12:ec:3b:e7:9e:4e:51:41:14:1b:84:
+         bb:32:a7:00:a7:82:9b:42:35:c7:e3:2f:bc:a9:b6:86:8d:65:
+         89:d6:70:f0
+-----BEGIN CERTIFICATE-----
+MIIFaTCCBFGgAwIBAgIRALYG9JvfbeGOOF1dAGwQl30wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMDAwMDAwMFoXDTE0MTIzMDIzNTk1
+OVowWzEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGTAXBgNVBAMTEGxpc3RzLmRlYmlhbi5vcmcw
+ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDFeQEPIHJOy3bqu2XZmGxN
+yy9zUdil9q3zL6EkXVA7+GExRqEZq4655jQZSOpy2J9piv7pXpBrSayIFhnQdTyG
+VjyjyFED5XQdcbdKtaTK/ymwGE40IVtXIOMMeC1h0bLxStJ/bDdZwW4VKvhpUCnm
+XbIiHJYIHwHVirNTruQ7HtQxM0TF06mx8hwQJjzt6G0tha0GLPdNtIKkxMVcTrsI
+uqbBQuDD5ujeQkPX3eiu6cm9VtvYIaXxyC01mRVqzKd8Ndj+JUF4QKS2sFWuqVOO
+XFEhI0GJ1vJh6A40iX1yDSY68RydJwnM9ol9FTwnhOvYAVw1qK36VMl/70KwvP96
+IPQLAIRIUMT+U6692dro2sSB5KcrjRZan5I5xme9uKAQAufrnNtnIHY7bezRWdEz
++ErcojEOmdSs/dK3QKIRJgoSCEozrQuo6IdjU52diQ9m2myip79A1Fuz9S25c83H
+Oi9BlFiSqGwjv4VE3hzBYmkLq0+MtYaYei9C/dcJV70CAwEAAaOCAcAwggG8MB8G
+A1UdIwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBTTiOSKxOc4
+iE+KZDXda0gBd/zUKTAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNV
+HSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIx
+AQICGjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFj
+dHMvZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6Athito
+dHRwOi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsG
+AQUFBwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2Fu
+ZGlTdGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2Fu
+ZGkubmV0MDEGA1UdEQQqMCiCEGxpc3RzLmRlYmlhbi5vcmeCFHd3dy5saXN0cy5k
+ZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQAY+KTauXkS47e5y28Lp/jKbdl3
+/qAN7/HHk7GLFY3T0SG1DGf4qxdHZpUBAxYXoC0gfJhkFc3x0JsLHfIQUKLkS14m
+C8O7O88Kwly8S2VknwNQ+OGtInkLoaXfZ1PAiez3SBFeuynUkGURnMFRCa1kb93c
+FuayDEGrhi6lUpjkMSceaKNZL7NZzCu7sbHqp2n5Pw2sikUeCU1nFLIzNHQ52zO3
+nVUu3yhEb77+eq4hnPMLXSqObZhioBZLstgfWXoIgCZi8a+5hDH4gWJQVUOmTuXb
+kCnsNvgZf/BcZvUMEuw7555OUUEUG4S7MqcAp4KbQjXH4y+8qbaGjWWJ1nDw
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/munin.debian.org-new.crt b/modules/ssl/files/servicecerts/munin.debian.org-new.crt
new file mode 100644 (file)
index 0000000..51df0f9
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            a7:2b:fb:dc:8c:c1:63:7f:43:b9:32:c0:51:bd:3c:27
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=munin.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:ad:44:54:d7:90:e4:eb:64:c4:27:3c:b1:8f:ef:
+                    2f:28:3e:c5:07:b9:48:36:72:d4:1e:76:3e:81:e3:
+                    6a:74:2a:fa:e9:e3:c6:0d:5b:46:7a:dd:a8:9b:31:
+                    5a:38:e4:fa:72:52:10:29:04:9f:b9:ae:53:38:95:
+                    0e:70:3b:12:09:2c:ec:b9:e1:d0:b8:2b:07:84:4d:
+                    62:27:f2:13:24:9f:10:38:73:98:7b:ee:74:77:ea:
+                    86:2d:98:99:e5:2f:ad:9e:d1:a7:b3:9c:ce:de:a6:
+                    36:28:a3:6b:f5:16:60:52:f2:af:7a:ec:55:04:8c:
+                    bb:13:80:d8:2a:ca:41:40:8e:26:8b:85:56:25:97:
+                    eb:d0:83:68:f6:3d:f8:f2:03:e2:bc:5a:25:cf:ac:
+                    eb:1a:6b:98:46:25:b3:ec:f0:2d:05:67:07:de:89:
+                    62:2d:22:7d:e8:65:d8:2b:ec:63:20:06:9f:3d:bb:
+                    fe:8b:7a:99:c9:eb:69:1e:e1:dc:31:54:b0:8c:50:
+                    3e:9b:aa:f7:a7:52:f5:37:0d:be:8a:e3:11:41:9d:
+                    4b:05:7d:63:a6:bd:fd:90:9b:63:be:45:56:8b:11:
+                    79:c4:3b:82:43:49:54:d1:cd:f1:fe:92:bd:f7:83:
+                    90:3e:7b:3c:3b:46:7f:70:cf:e0:5b:b3:c0:3d:3f:
+                    41:32:6a:5b:48:47:52:89:c7:a1:8d:00:cc:ad:8b:
+                    e7:fb:97:36:d4:96:0f:31:66:44:b8:fc:67:b4:e3:
+                    30:64:37:b1:9b:ec:81:b0:a9:25:79:12:0e:d8:ec:
+                    5d:04:9a:6b:91:ef:d6:7a:07:f7:fd:94:fa:83:9b:
+                    d6:1a:e9:50:6f:38:08:ab:f3:06:df:e9:d3:15:42:
+                    e6:8f:e2:6d:54:9f:c7:dd:d4:2d:70:39:b9:b2:29:
+                    fd:a5:0e:aa:ae:5c:ea:a9:fd:95:73:27:5a:00:08:
+                    12:d0:c0:94:50:4a:f8:0b:f5:7d:cb:d6:9a:90:00:
+                    01:75:63:53:81:b4:f8:25:5e:45
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                F2:10:87:60:72:B8:D3:A5:A1:69:80:47:EE:52:B2:3B:18:4D:89:DC
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:munin.debian.org, DNS:www.munin.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         38:60:c3:ed:44:39:40:92:ec:c2:62:39:cf:8e:ea:38:d9:e7:
+         18:4f:c8:ba:4a:09:1d:cb:69:0a:cc:ec:e4:e4:de:e5:4d:85:
+         6e:1c:a1:d8:4e:69:4c:a4:66:58:b5:70:b1:21:5b:a4:c2:05:
+         86:c4:bc:ec:df:5c:02:32:ef:a5:40:25:ec:72:30:26:1f:c0:
+         d0:ec:81:95:b9:4b:d0:c5:51:d4:b4:3a:a3:27:df:8f:50:c6:
+         85:45:cb:ad:d9:42:0d:7c:9e:6a:c9:95:1e:42:0c:d5:b6:bb:
+         43:9d:da:ec:80:8a:42:9c:6d:76:2e:04:e8:5f:8e:6c:bd:51:
+         06:7d:2f:a2:fd:83:9f:77:f7:4a:54:15:d8:3a:f7:7a:b5:c5:
+         1b:13:0d:d4:be:90:eb:4d:e9:5f:d3:b1:ef:bb:e8:b4:eb:d0:
+         d3:52:2d:91:2d:44:e5:13:fc:49:cc:98:19:08:79:0d:4e:f2:
+         be:c2:fe:02:84:e8:2d:ed:61:ba:61:70:1f:4f:6d:5a:44:3a:
+         55:7b:ab:fd:17:8b:96:c1:a4:0f:33:fb:b9:43:78:ab:b6:f7:
+         9f:95:a0:9b:e6:83:6f:8b:23:bb:6b:48:8b:fb:7a:3e:d0:cc:
+         f2:87:e1:e7:5e:71:b5:d0:6a:51:77:c6:91:a5:23:14:7c:92:
+         7c:1d:43:a8
+-----BEGIN CERTIFICATE-----
+MIIFaTCCBFGgAwIBAgIRAKcr+9yMwWN/Q7kywFG9PCcwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDEwMTAwMDAwMFoXDTE1MDEwMTIzNTk1
+OVowWzEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGTAXBgNVBAMTEG11bmluLmRlYmlhbi5vcmcw
+ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCtRFTXkOTrZMQnPLGP7y8o
+PsUHuUg2ctQedj6B42p0Kvrp48YNW0Z63aibMVo45PpyUhApBJ+5rlM4lQ5wOxIJ
+LOy54dC4KweETWIn8hMknxA4c5h77nR36oYtmJnlL62e0aeznM7epjYoo2v1FmBS
+8q967FUEjLsTgNgqykFAjiaLhVYll+vQg2j2PfjyA+K8WiXPrOsaa5hGJbPs8C0F
+ZwfeiWItIn3oZdgr7GMgBp89u/6LepnJ62ke4dwxVLCMUD6bqvenUvU3Db6K4xFB
+nUsFfWOmvf2Qm2O+RVaLEXnEO4JDSVTRzfH+kr33g5A+ezw7Rn9wz+Bbs8A9P0Ey
+altIR1KJx6GNAMyti+f7lzbUlg8xZkS4/Ge04zBkN7Gb7IGwqSV5Eg7Y7F0EmmuR
+79Z6B/f9lPqDm9Ya6VBvOAir8wbf6dMVQuaP4m1Un8fd1C1wObmyKf2lDqquXOqp
+/ZVzJ1oACBLQwJRQSvgL9X3L1pqQAAF1Y1OBtPglXkUCAwEAAaOCAcAwggG8MB8G
+A1UdIwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBTyEIdgcrjT
+paFpgEfuUrI7GE2J3DAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNV
+HSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIx
+AQICGjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFj
+dHMvZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6Athito
+dHRwOi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsG
+AQUFBwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2Fu
+ZGlTdGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2Fu
+ZGkubmV0MDEGA1UdEQQqMCiCEG11bmluLmRlYmlhbi5vcmeCFHd3dy5tdW5pbi5k
+ZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQA4YMPtRDlAkuzCYjnPjuo42ecY
+T8i6Sgkdy2kKzOzk5N7lTYVuHKHYTmlMpGZYtXCxIVukwgWGxLzs31wCMu+lQCXs
+cjAmH8DQ7IGVuUvQxVHUtDqjJ9+PUMaFRcut2UINfJ5qyZUeQgzVtrtDndrsgIpC
+nG12LgToX45svVEGfS+i/YOfd/dKVBXYOvd6tcUbEw3UvpDrTelf07Hvu+i069DT
+Ui2RLUTlE/xJzJgZCHkNTvK+wv4ChOgt7WG6YXAfT21aRDpVe6v9F4uWwaQPM/u5
+Q3irtveflaCb5oNviyO7a0iL+3o+0Mzyh+HnXnG10GpRd8aRpSMUfJJ8HUOo
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/nagios.debian.org-new.crt b/modules/ssl/files/servicecerts/nagios.debian.org-new.crt
new file mode 100644 (file)
index 0000000..d858bcc
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            c1:ed:2e:02:fe:e4:b0:81:f2:85:8b:f8:a1:19:7b:6d
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=nagios.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:f6:87:c1:2b:63:cf:7f:a2:2e:5e:2e:6e:61:c5:
+                    93:a4:ac:b3:49:82:be:78:f7:8a:bf:3f:58:fd:c6:
+                    7d:65:58:9b:b5:53:90:57:f1:3d:40:27:b5:ad:0a:
+                    6e:ec:b0:96:7e:cd:ce:8e:86:f0:19:62:15:60:df:
+                    d4:68:38:f6:92:25:43:36:1d:f5:9d:4b:20:04:52:
+                    0b:3a:1e:d3:ef:29:fc:97:d6:e8:5d:98:62:0c:4a:
+                    8d:74:d9:33:4c:6f:0c:43:95:ed:bb:90:88:ea:e1:
+                    99:76:8f:a1:00:41:62:01:78:60:a5:69:65:4b:a9:
+                    e3:a1:c8:b7:fc:c5:6c:c5:a7:f5:31:df:62:aa:ab:
+                    52:eb:17:ad:d1:38:66:54:fd:ee:56:6e:0e:7e:bb:
+                    5e:5b:94:78:e1:dc:70:fa:6e:3b:cc:92:f2:fd:4e:
+                    2d:08:4a:d8:9f:5b:3c:58:54:a6:ac:fb:ef:52:8a:
+                    e5:3d:9a:72:28:2d:9e:92:df:29:f0:be:79:b4:d2:
+                    89:7c:73:2d:33:57:74:66:0d:35:df:93:1a:7e:f2:
+                    59:ad:8b:81:b4:fb:5e:a1:f2:b8:8c:1b:86:99:00:
+                    3a:e0:43:7c:41:11:18:ff:34:40:f1:14:c0:cf:31:
+                    8b:5a:6b:5f:44:9e:8b:9a:d1:cf:50:1c:18:61:b2:
+                    cd:1f:5e:a2:f5:83:44:7d:4c:2a:b4:1d:cb:4c:28:
+                    37:f2:c1:d0:3a:12:67:85:58:0f:d8:70:0c:e5:99:
+                    07:81:75:4a:8c:24:17:93:a0:6b:08:eb:26:7c:5c:
+                    41:a3:50:91:b5:79:53:63:c3:3f:b9:6f:d1:36:45:
+                    b6:8a:e9:2a:ea:5f:d7:2f:37:0f:2d:dd:bd:1f:b0:
+                    e6:5e:c9:0c:b2:57:fe:42:f8:c2:17:6c:12:a4:ec:
+                    b5:e2:60:db:ca:c7:82:e7:3c:38:1d:d3:e0:e2:0f:
+                    b0:dc:1f:4b:73:e7:1c:88:b7:fe:9b:f0:14:f6:34:
+                    10:18:50:8c:54:5f:f6:04:6f:19
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                E7:37:33:C0:4E:90:E6:DB:38:C3:85:47:49:5A:66:75:07:87:07:E0
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:nagios.debian.org, DNS:www.nagios.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         aa:df:01:0e:da:20:0d:25:8f:b2:40:48:de:7a:f1:4d:21:34:
+         24:93:5d:b8:fc:c7:ff:e1:d4:7b:8d:e8:04:56:9a:78:4d:71:
+         8d:a2:de:b5:a5:95:98:6d:0c:c9:2d:0c:5f:0b:58:f3:21:83:
+         9d:26:04:ca:1b:78:fe:2e:25:e0:6a:47:84:16:99:20:3e:5e:
+         91:3c:f0:f6:45:51:c4:d6:20:e2:94:a3:57:7c:3e:51:94:64:
+         1f:6d:eb:f0:a4:45:9c:88:cf:c1:0a:ff:a8:36:a4:56:20:2b:
+         f1:b3:b3:22:b2:1d:97:59:e2:04:e8:aa:02:a4:62:16:26:a3:
+         55:d7:cb:35:e0:d2:1d:1a:80:e0:03:f3:3c:88:54:c0:0d:2f:
+         b5:49:e7:0c:84:cf:52:a3:f0:92:e9:ad:86:36:17:85:5f:03:
+         c2:58:aa:61:9e:88:66:37:8a:69:ea:80:d3:22:84:f8:8c:93:
+         60:67:47:98:ca:25:a0:b4:e3:ea:93:57:7c:38:7a:77:bd:fa:
+         f5:87:c9:78:69:e4:b7:05:2d:78:bc:6e:87:4c:28:8a:86:fd:
+         27:f1:95:c9:43:92:4b:d7:fd:c7:b9:4d:9b:eb:ba:ba:39:ed:
+         bf:e7:b5:5b:fb:4b:c0:2b:88:20:a4:e0:db:75:67:2a:94:94:
+         d1:82:a8:19
+-----BEGIN CERTIFICATE-----
+MIIFbDCCBFSgAwIBAgIRAMHtLgL+5LCB8oWL+KEZe20wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDEwMTAwMDAwMFoXDTE1MDEwMTIzNTk1
+OVowXDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGjAYBgNVBAMTEW5hZ2lvcy5kZWJpYW4ub3Jn
+MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEA9ofBK2PPf6IuXi5uYcWT
+pKyzSYK+ePeKvz9Y/cZ9ZVibtVOQV/E9QCe1rQpu7LCWfs3OjobwGWIVYN/UaDj2
+kiVDNh31nUsgBFILOh7T7yn8l9boXZhiDEqNdNkzTG8MQ5Xtu5CI6uGZdo+hAEFi
+AXhgpWllS6njoci3/MVsxaf1Md9iqqtS6xet0ThmVP3uVm4OfrteW5R44dxw+m47
+zJLy/U4tCErYn1s8WFSmrPvvUorlPZpyKC2ekt8p8L55tNKJfHMtM1d0Zg0135Ma
+fvJZrYuBtPteofK4jBuGmQA64EN8QREY/zRA8RTAzzGLWmtfRJ6LmtHPUBwYYbLN
+H16i9YNEfUwqtB3LTCg38sHQOhJnhVgP2HAM5ZkHgXVKjCQXk6BrCOsmfFxBo1CR
+tXlTY8M/uW/RNkW2iukq6l/XLzcPLd29H7DmXskMslf+QvjCF2wSpOy14mDbyseC
+5zw4HdPg4g+w3B9Lc+cciLf+m/AU9jQQGFCMVF/2BG8ZAgMBAAGjggHCMIIBvjAf
+BgNVHSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQU5zczwE6Q
+5ts4w4VHSVpmdQeHB+AwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYD
+VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGy
+MQECAhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJh
+Y3RzL2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYr
+aHR0cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggr
+BgEFBQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dh
+bmRpU3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdh
+bmRpLm5ldDAzBgNVHREELDAqghFuYWdpb3MuZGViaWFuLm9yZ4IVd3d3Lm5hZ2lv
+cy5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCq3wEO2iANJY+yQEjeevFN
+ITQkk124/Mf/4dR7jegEVpp4TXGNot61pZWYbQzJLQxfC1jzIYOdJgTKG3j+LiXg
+akeEFpkgPl6RPPD2RVHE1iDilKNXfD5RlGQfbevwpEWciM/BCv+oNqRWICvxs7Mi
+sh2XWeIE6KoCpGIWJqNV18s14NIdGoDgA/M8iFTADS+1SecMhM9So/CS6a2GNheF
+XwPCWKphnohmN4pp6oDTIoT4jJNgZ0eYyiWgtOPqk1d8OHp3vfr1h8l4aeS3BS14
+vG6HTCiKhv0n8ZXJQ5JL1/3HuU2b67q6Oe2/57Vb+0vAK4ggpODbdWcqlJTRgqgZ
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/nm.debian.org-new.crt b/modules/ssl/files/servicecerts/nm.debian.org-new.crt
new file mode 100644 (file)
index 0000000..dca6275
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            89:0f:32:6e:3a:6e:39:fd:83:37:bb:4e:e1:54:0b:91
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=nm.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:ac:af:9a:d3:85:e3:d3:d6:9e:d4:41:d3:ee:46:
+                    d8:0b:94:73:41:7a:43:82:0d:7b:ed:f1:d9:51:42:
+                    dd:e3:91:c2:28:25:d0:e1:6c:ed:91:95:0a:36:a4:
+                    09:f2:9b:c6:0d:14:c3:c5:f7:72:30:1e:4f:4c:97:
+                    7b:31:81:a1:5d:80:24:76:20:2b:81:79:d4:d0:51:
+                    95:10:f4:24:a8:1c:d9:08:76:1e:9e:a6:db:51:c2:
+                    c4:66:27:45:64:7e:28:e0:8b:d2:e0:96:7c:08:da:
+                    47:c2:7f:d9:49:7f:33:39:80:c8:0c:c0:4e:d3:68:
+                    ec:7f:44:0a:a2:15:92:80:6b:3c:da:38:c0:e0:1a:
+                    86:b8:7b:7a:86:84:43:55:68:fa:32:af:60:0a:01:
+                    09:d4:07:47:f3:0c:90:85:f4:95:72:42:5c:7d:a7:
+                    c4:3f:06:a2:44:80:d0:d1:24:0a:b8:c3:81:5a:1b:
+                    25:fb:e1:55:6b:43:c6:3e:16:b5:de:dc:4e:98:f2:
+                    1c:a4:0c:7a:51:6d:7f:76:99:c6:70:90:53:33:6e:
+                    09:80:bd:f3:0d:e4:ce:2c:25:e5:5f:34:48:ed:64:
+                    e6:fd:25:f2:ba:15:1c:f0:e6:12:b2:ef:31:fd:0d:
+                    bd:ee:d8:1b:ef:d4:8f:1d:c6:2a:73:0d:77:30:8f:
+                    9e:dc:52:6d:85:c0:c9:6f:ec:ef:d1:fe:54:54:1d:
+                    69:3b:51:95:2c:d3:f2:db:66:80:73:7d:0d:b9:ec:
+                    4b:45:db:41:d3:d2:a1:90:35:e9:50:20:40:84:b2:
+                    a8:6b:94:1a:9e:70:8f:14:2c:96:32:c4:d3:07:61:
+                    10:89:82:b1:34:00:0d:33:ae:d3:a3:74:10:86:87:
+                    4b:ab:bc:a3:16:46:3d:64:83:38:aa:66:02:07:a6:
+                    87:1b:f0:28:7b:aa:79:a0:14:3f:5a:90:91:54:ed:
+                    f5:48:07:bb:3e:38:36:31:59:17:d7:25:dd:67:b1:
+                    a1:97:d3:33:41:c1:c0:40:c5:71
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                A3:2A:D5:D0:07:FA:55:4D:59:5B:DB:95:C5:42:B2:44:FC:20:2C:A5
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:nm.debian.org, DNS:www.nm.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         b5:e6:83:24:d8:b7:59:7d:be:7f:5d:a2:de:a1:da:9a:9e:50:
+         e4:a5:8d:87:36:b8:0c:44:5f:0e:1d:d0:ad:00:e5:df:a8:2b:
+         51:d6:dd:69:8b:8a:45:86:16:6b:57:c4:9e:91:44:0c:84:48:
+         71:b2:fb:fc:a7:ab:23:08:6e:4a:1c:30:88:56:5a:83:60:af:
+         71:97:a9:97:78:82:4f:d0:14:8f:39:6a:24:f2:81:68:e4:6d:
+         f1:14:65:0e:39:05:25:88:40:10:b2:d5:88:fd:65:d7:50:98:
+         17:0d:60:3b:c5:c1:ad:3b:ac:95:ca:06:28:dd:95:22:2e:67:
+         8d:38:52:79:b5:51:60:8d:db:11:fc:86:ba:70:b3:a7:5f:ae:
+         ff:00:c9:80:52:ca:7e:89:f5:71:c0:b3:c4:4e:fc:bf:92:80:
+         e1:51:d4:7c:9c:e1:2e:71:80:c9:27:13:45:e3:17:b8:22:3e:
+         2a:8e:c8:88:ea:3d:02:89:56:5e:8e:7c:04:a2:53:9d:48:79:
+         46:78:ea:14:8d:b2:0e:fc:70:1e:a7:29:49:d7:82:a6:69:6a:
+         53:af:1f:43:8d:1b:bc:1d:7c:aa:13:16:39:6e:43:0d:ab:ac:
+         9b:c4:f6:62:a3:f6:28:15:a4:c6:01:dc:bc:25:b5:b3:c7:ff:
+         49:94:dc:0d
+-----BEGIN CERTIFICATE-----
+MIIFYDCCBEigAwIBAgIRAIkPMm46bjn9gze7TuFUC5EwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMTAwMDAwMFoXDTE0MTIzMTIzNTk1
+OVowWDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxFjAUBgNVBAMTDW5tLmRlYmlhbi5vcmcwggGi
+MA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCsr5rThePT1p7UQdPuRtgLlHNB
+ekOCDXvt8dlRQt3jkcIoJdDhbO2RlQo2pAnym8YNFMPF93IwHk9Ml3sxgaFdgCR2
+ICuBedTQUZUQ9CSoHNkIdh6epttRwsRmJ0Vkfijgi9LglnwI2kfCf9lJfzM5gMgM
+wE7TaOx/RAqiFZKAazzaOMDgGoa4e3qGhENVaPoyr2AKAQnUB0fzDJCF9JVyQlx9
+p8Q/BqJEgNDRJAq4w4FaGyX74VVrQ8Y+FrXe3E6Y8hykDHpRbX92mcZwkFMzbgmA
+vfMN5M4sJeVfNEjtZOb9JfK6FRzw5hKy7zH9Db3u2Bvv1I8dxipzDXcwj57cUm2F
+wMlv7O/R/lRUHWk7UZUs0/LbZoBzfQ257EtF20HT0qGQNelQIECEsqhrlBqecI8U
+LJYyxNMHYRCJgrE0AA0zrtOjdBCGh0urvKMWRj1kgziqZgIHpocb8Ch7qnmgFD9a
+kJFU7fVIB7s+ODYxWRfXJd1nsaGX0zNBwcBAxXECAwEAAaOCAbowggG2MB8GA1Ud
+IwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBSjKtXQB/pVTVlb
+25XFQrJE/CAspTAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUE
+FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIxAQIC
+GjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFjdHMv
+ZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6AthitodHRw
+Oi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsGAQUF
+BwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2FuZGlT
+dGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2FuZGku
+bmV0MCsGA1UdEQQkMCKCDW5tLmRlYmlhbi5vcmeCEXd3dy5ubS5kZWJpYW4ub3Jn
+MA0GCSqGSIb3DQEBBQUAA4IBAQC15oMk2LdZfb5/XaLeodqanlDkpY2HNrgMRF8O
+HdCtAOXfqCtR1t1pi4pFhhZrV8SekUQMhEhxsvv8p6sjCG5KHDCIVlqDYK9xl6mX
+eIJP0BSPOWok8oFo5G3xFGUOOQUliEAQstWI/WXXUJgXDWA7xcGtO6yVygYo3ZUi
+LmeNOFJ5tVFgjdsR/Ia6cLOnX67/AMmAUsp+ifVxwLPETvy/koDhUdR8nOEucYDJ
+JxNF4xe4Ij4qjsiI6j0CiVZejnwEolOdSHlGeOoUjbIO/HAepylJ14KmaWpTrx9D
+jRu8HXyqExY5bkMNq6ybxPZio/YoFaTGAdy8JbWzx/9JlNwN
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/packages.debian.org-new.crt b/modules/ssl/files/servicecerts/packages.debian.org-new.crt
new file mode 100644 (file)
index 0000000..c15dd0e
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            db:a9:f0:68:bb:df:c8:82:9c:0b:bc:ea:b5:4a:8c:5e
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Feb 10 00:00:00 2014 GMT
+            Not After : Feb 10 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=packages.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:a2:fa:c4:d8:b0:0a:61:bf:f4:88:ba:c5:8a:c8:
+                    07:b6:cb:62:92:a1:ae:68:c9:f5:c5:a8:01:34:e3:
+                    97:db:f8:50:87:a9:e9:03:ec:6c:57:be:ad:eb:57:
+                    8e:7d:c1:07:cc:e4:6a:6e:6e:83:5b:d9:03:11:2d:
+                    2c:f7:a4:e4:3b:e2:97:65:c5:a2:13:65:81:6f:15:
+                    b1:ca:b2:a0:20:c0:b5:d8:c9:49:2c:30:74:14:21:
+                    1a:99:ef:6e:5d:99:64:75:e5:aa:69:7c:7a:08:81:
+                    7a:ed:d0:1a:47:28:74:d3:fd:45:60:6c:0e:7e:24:
+                    4b:48:0a:52:39:27:c0:23:3f:54:2f:b9:b8:dc:09:
+                    06:ce:bd:bf:a0:bc:82:26:28:c6:73:01:f9:aa:d9:
+                    ca:4a:35:4d:3a:54:14:43:b8:53:ec:f3:ce:cd:b3:
+                    6c:df:9b:69:59:30:a3:b9:f3:d0:51:6e:8c:9a:60:
+                    e8:07:82:64:04:7f:16:64:fe:8c:aa:59:d2:65:e2:
+                    4a:39:97:e4:ee:8f:d1:f9:36:5c:75:32:13:4d:9d:
+                    a1:c9:77:3b:8f:96:1e:77:38:39:90:18:c0:5f:80:
+                    b4:ac:9d:90:61:19:f6:06:f6:96:ec:34:63:5b:df:
+                    1f:4a:5a:54:63:c8:8a:60:3b:15:b3:a9:ae:bf:de:
+                    97:5e:ad:67:99:13:82:b3:39:df:ba:f5:86:43:c1:
+                    e1:32:68:2e:90:a2:d8:74:d7:ae:39:ab:ad:4a:06:
+                    34:ac:ea:a9:3c:a4:07:5d:c9:21:e6:6b:f0:a6:1e:
+                    1b:ce:f3:20:81:0c:32:e1:ac:11:8f:3e:65:ae:f2:
+                    cd:c5:02:50:6e:39:69:9c:13:99:bd:c2:69:5b:4b:
+                    f9:fd:9b:92:cf:99:61:57:d5:ae:b3:ad:f6:9f:ef:
+                    f4:71:16:61:25:ac:48:35:32:c0:81:ec:c2:b6:e2:
+                    25:e5:d8:94:a6:ec:cc:8c:12:be:f8:5f:34:11:89:
+                    41:58:cd:59:c8:4d:ef:7c:5e:09
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                7E:60:78:43:69:9A:AE:C0:6E:74:4D:AA:7B:E8:9B:E1:49:AC:8B:7C
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:packages.debian.org, DNS:www.packages.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         2d:ab:0f:66:67:c1:1a:24:23:d8:92:8a:86:82:9e:be:57:63:
+         44:14:10:7a:69:33:74:71:48:ef:37:57:25:4f:20:bb:ff:93:
+         60:bb:b7:f1:88:33:ff:b2:2f:0f:26:c8:59:aa:b5:3a:87:12:
+         aa:f1:ee:90:2e:45:f2:1d:f7:d7:4c:59:02:37:81:76:33:a2:
+         5c:54:71:1d:97:bb:26:79:c9:64:84:3e:4d:8d:70:d1:9c:ec:
+         0c:01:2a:97:af:dd:45:cb:2b:69:c1:e1:33:97:84:e1:c9:e2:
+         46:13:a6:06:f8:22:58:29:90:7b:9b:7f:ce:f7:bd:a6:2f:c2:
+         86:e6:0d:38:78:9b:9e:20:10:e8:96:ad:77:a4:4c:a3:1b:59:
+         5c:ef:c9:99:5c:a0:5a:9a:88:25:c2:a0:1d:f8:1f:ee:c1:d4:
+         18:e1:1e:9b:15:01:f3:17:0f:63:fc:ec:d9:7f:28:73:94:a2:
+         c1:46:9f:3a:5a:bd:ea:0b:e9:9e:6d:22:2e:74:cc:43:85:ec:
+         61:30:d9:f4:45:38:12:36:56:6c:99:a2:b9:6a:15:a9:22:a6:
+         2d:de:ab:49:05:eb:66:e9:57:99:32:90:70:49:04:f3:5f:85:
+         08:5f:4e:93:d3:67:fd:87:7c:02:fc:2a:57:2d:a7:b5:23:16:
+         a1:61:cc:2d
+-----BEGIN CERTIFICATE-----
+MIIFcjCCBFqgAwIBAgIRANup8Gi738iCnAu86rVKjF4wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDIxMDAwMDAwMFoXDTE1MDIxMDIzNTk1
+OVowXjEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxHDAaBgNVBAMTE3BhY2thZ2VzLmRlYmlhbi5v
+cmcwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCi+sTYsAphv/SIusWK
+yAe2y2KSoa5oyfXFqAE045fb+FCHqekD7GxXvq3rV459wQfM5GpuboNb2QMRLSz3
+pOQ74pdlxaITZYFvFbHKsqAgwLXYyUksMHQUIRqZ725dmWR15appfHoIgXrt0BpH
+KHTT/UVgbA5+JEtIClI5J8AjP1QvubjcCQbOvb+gvIImKMZzAfmq2cpKNU06VBRD
+uFPs887Ns2zfm2lZMKO589BRboyaYOgHgmQEfxZk/oyqWdJl4ko5l+Tuj9H5Nlx1
+MhNNnaHJdzuPlh53ODmQGMBfgLSsnZBhGfYG9pbsNGNb3x9KWlRjyIpgOxWzqa6/
+3pderWeZE4KzOd+69YZDweEyaC6Qoth01645q61KBjSs6qk8pAddySHma/CmHhvO
+8yCBDDLhrBGPPmWu8s3FAlBuOWmcE5m9wmlbS/n9m5LPmWFX1a6zrfaf7/RxFmEl
+rEg1MsCB7MK24iXl2JSm7MyMEr74XzQRiUFYzVnITe98XgkCAwEAAaOCAcYwggHC
+MB8GA1UdIwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBR+YHhD
+aZquwG50Tap76JvhSayLfDAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAd
+BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEE
+AbIxAQICGjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250
+cmFjdHMvZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6At
+hitodHRwOi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoG
+CCsGAQUFBwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQv
+R2FuZGlTdGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3Au
+Z2FuZGkubmV0MDcGA1UdEQQwMC6CE3BhY2thZ2VzLmRlYmlhbi5vcmeCF3d3dy5w
+YWNrYWdlcy5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQAtqw9mZ8EaJCPY
+koqGgp6+V2NEFBB6aTN0cUjvN1clTyC7/5Ngu7fxiDP/si8PJshZqrU6hxKq8e6Q
+LkXyHffXTFkCN4F2M6JcVHEdl7smeclkhD5NjXDRnOwMASqXr91FyytpweEzl4Th
+yeJGE6YG+CJYKZB7m3/O972mL8KG5g04eJueIBDolq13pEyjG1lc78mZXKBamogl
+wqAd+B/uwdQY4R6bFQHzFw9j/OzZfyhzlKLBRp86Wr3qC+mebSIudMxDhexhMNn0
+RTgSNlZsmaK5ahWpIqYt3qtJBetm6VeZMpBwSQTzX4UIX06T02f9h3wC/CpXLae1
+IxahYcwt
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/piuparts.debian.org-new.crt b/modules/ssl/files/servicecerts/piuparts.debian.org-new.crt
new file mode 100644 (file)
index 0000000..e1c4572
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            dd:94:31:6e:38:70:6a:29:4f:7a:61:0c:7a:c7:26:37
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Feb 14 00:00:00 2014 GMT
+            Not After : Feb 14 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=piuparts.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:ba:8c:a3:23:3c:be:33:25:5b:b0:0f:99:fc:34:
+                    ed:21:b4:1a:9e:24:34:e4:3e:5b:54:cf:3f:51:13:
+                    8a:b3:68:4c:2f:74:e4:ec:17:32:46:0e:83:5d:a2:
+                    f4:82:52:e9:7f:32:e9:d0:a7:ca:6e:1c:1c:53:cd:
+                    05:9b:3c:f5:2f:81:b3:c6:d3:ef:c4:a7:e3:16:35:
+                    96:23:76:32:86:a8:11:f6:2e:c0:30:54:ec:48:a2:
+                    95:c1:52:47:be:f2:2c:10:16:76:99:e3:66:90:90:
+                    ac:1c:f2:b3:31:be:21:eb:9c:53:e2:b4:aa:b7:72:
+                    1d:cd:4d:e5:76:f4:19:8a:71:e9:99:52:f6:c8:bd:
+                    87:72:ed:04:5a:9c:af:e7:3d:46:4a:8a:e1:bb:f3:
+                    6c:1d:d7:27:a7:ff:2d:8f:8b:ab:ef:69:6c:be:60:
+                    ef:c5:fe:1d:ae:fd:03:c7:81:d3:c8:e1:be:c8:50:
+                    95:b1:dc:cd:15:f4:2d:39:3d:ec:20:9e:44:33:1d:
+                    90:73:2b:14:0a:69:a1:66:d3:41:2c:75:69:3e:f3:
+                    93:52:0f:b2:53:46:eb:7a:03:85:00:de:8a:65:7f:
+                    dc:7a:8c:f4:fd:2a:8f:66:d6:ad:78:d3:6e:0a:77:
+                    37:7e:84:bf:63:40:1e:c3:0c:37:73:bb:e5:e8:06:
+                    da:ba:fe:52:1b:5e:c2:62:af:a6:35:ea:75:1b:d6:
+                    df:d5:22:67:5f:81:64:46:27:1e:c2:e9:a1:6c:ea:
+                    af:19:80:16:3e:ca:1a:bd:a4:d9:89:ac:ee:42:e3:
+                    2a:ea:55:eb:fb:a2:8d:92:ee:64:8f:9b:b8:fa:6e:
+                    a6:e0:ba:f4:b1:c9:98:bf:0a:6f:6a:05:84:cc:a7:
+                    ba:2e:be:2a:24:4a:78:08:2d:09:d3:85:e0:dc:6f:
+                    43:96:11:82:5a:c4:a1:d3:8c:12:f8:06:79:66:0b:
+                    5e:4f:24:06:35:3a:1f:c6:66:9c:15:c2:ab:fb:f5:
+                    09:b4:68:4c:b6:87:af:8d:11:eb
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                8E:CB:0F:25:4A:9D:0E:C0:3B:87:7F:FD:D5:80:EC:7E:36:52:E0:86
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:piuparts.debian.org, DNS:www.piuparts.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         29:cc:82:3d:08:ac:90:2c:e5:a5:a1:b7:39:72:bc:bd:10:76:
+         9d:12:c8:08:f1:f2:ba:48:d5:d8:7b:4b:04:a1:bb:14:18:11:
+         c0:c9:0f:f5:d2:eb:8a:d6:54:3e:f2:cf:b3:29:0f:2b:9c:09:
+         d6:2b:89:0d:9d:e2:1f:c6:e2:1c:df:ca:d6:3d:63:fa:36:b5:
+         68:d8:c5:57:d1:81:3d:ca:5b:9b:18:af:9a:b0:3e:53:f3:62:
+         c4:4d:d6:c1:1c:5e:a0:4d:79:ac:eb:d1:3c:88:d0:35:3b:1a:
+         41:ac:da:96:e5:00:37:ba:33:b1:f3:ba:11:bc:25:23:ab:67:
+         66:14:03:8f:b4:d9:01:05:f4:ce:30:97:6c:c9:b8:f7:93:7c:
+         9d:3f:b3:74:34:d1:6b:41:e4:f1:96:0c:b6:02:a5:12:e3:52:
+         eb:65:11:ba:d9:42:dc:b4:f8:b9:fe:12:0d:a1:b6:84:2e:9d:
+         83:8b:31:d2:b4:e3:8a:c2:bf:b0:ae:40:d3:98:ab:c5:c5:af:
+         51:6f:a2:e9:60:d9:78:be:82:dd:53:33:fe:94:c7:55:0e:e3:
+         b2:a6:35:54:cc:40:b6:4e:45:6f:09:8d:f2:50:e7:f0:f7:98:
+         b1:37:31:f7:aa:22:44:19:0c:e4:f0:21:d5:bb:fe:2a:a5:1d:
+         92:e7:66:85
+-----BEGIN CERTIFICATE-----
+MIIFcjCCBFqgAwIBAgIRAN2UMW44cGopT3phDHrHJjcwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDIxNDAwMDAwMFoXDTE1MDIxNDIzNTk1
+OVowXjEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxHDAaBgNVBAMTE3BpdXBhcnRzLmRlYmlhbi5v
+cmcwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC6jKMjPL4zJVuwD5n8
+NO0htBqeJDTkPltUzz9RE4qzaEwvdOTsFzJGDoNdovSCUul/MunQp8puHBxTzQWb
+PPUvgbPG0+/Ep+MWNZYjdjKGqBH2LsAwVOxIopXBUke+8iwQFnaZ42aQkKwc8rMx
+viHrnFPitKq3ch3NTeV29BmKcemZUvbIvYdy7QRanK/nPUZKiuG782wd1yen/y2P
+i6vvaWy+YO/F/h2u/QPHgdPI4b7IUJWx3M0V9C05PewgnkQzHZBzKxQKaaFm00Es
+dWk+85NSD7JTRut6A4UA3oplf9x6jPT9Ko9m1q14024Kdzd+hL9jQB7DDDdzu+Xo
+Btq6/lIbXsJir6Y16nUb1t/VImdfgWRGJx7C6aFs6q8ZgBY+yhq9pNmJrO5C4yrq
+Vev7oo2S7mSPm7j6bqbguvSxyZi/Cm9qBYTMp7ouviokSngILQnTheDcb0OWEYJa
+xKHTjBL4BnlmC15PJAY1Oh/GZpwVwqv79Qm0aEy2h6+NEesCAwEAAaOCAcYwggHC
+MB8GA1UdIwQYMBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBSOyw8l
+Sp0OwDuHf/3VgOx+NlLghjAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAd
+BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEE
+AbIxAQICGjA8MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250
+cmFjdHMvZnIvc3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6At
+hitodHRwOi8vY3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoG
+CCsGAQUFBwEBBF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQv
+R2FuZGlTdGFuZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3Au
+Z2FuZGkubmV0MDcGA1UdEQQwMC6CE3BpdXBhcnRzLmRlYmlhbi5vcmeCF3d3dy5w
+aXVwYXJ0cy5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQApzII9CKyQLOWl
+obc5cry9EHadEsgI8fK6SNXYe0sEobsUGBHAyQ/10uuK1lQ+8s+zKQ8rnAnWK4kN
+neIfxuIc38rWPWP6NrVo2MVX0YE9ylubGK+asD5T82LETdbBHF6gTXms69E8iNA1
+OxpBrNqW5QA3ujOx87oRvCUjq2dmFAOPtNkBBfTOMJdsybj3k3ydP7N0NNFrQeTx
+lgy2AqUS41LrZRG62ULctPi5/hINobaELp2DizHStOOKwr+wrkDTmKvFxa9Rb6Lp
+YNl4voLdUzP+lMdVDuOypjVUzEC2TkVvCY3yUOfw95ixNzH3qiJEGQzk8CHVu/4q
+pR2S52aF
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/release.debian.org-new.crt b/modules/ssl/files/servicecerts/release.debian.org-new.crt
new file mode 100644 (file)
index 0000000..d805f07
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            89:35:ea:05:e1:13:6b:0f:1e:d2:3d:c6:fd:e9:77:1d
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=release.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d0:01:5d:db:bf:ec:18:6d:35:94:3d:7b:20:4b:
+                    e7:70:a2:11:2d:f1:ac:31:6f:fc:52:f0:06:7e:fe:
+                    de:a6:6d:5c:ff:0a:08:a3:d5:eb:7b:ae:09:b8:ce:
+                    cd:41:50:d0:bf:9f:ae:ca:4d:2b:e5:fe:2d:c0:c0:
+                    f3:44:eb:5a:00:46:d0:f4:92:70:10:dc:b4:d8:60:
+                    2b:91:9f:b5:cc:ac:77:6b:ca:3a:44:9e:60:7d:bf:
+                    b4:6c:7a:46:8c:b0:11:ab:54:52:19:84:04:59:83:
+                    d9:9d:fd:76:08:82:64:73:9b:ce:e6:e1:7e:33:ef:
+                    ed:64:3d:05:cb:51:ba:03:e0:2d:0c:56:7b:70:8c:
+                    d4:c3:cc:ff:f7:58:d6:3f:39:1e:8d:9e:67:99:30:
+                    d5:a7:05:02:70:8d:0c:54:4f:4e:fd:e3:89:76:61:
+                    21:16:6b:51:f6:8a:f0:e5:f0:2a:dd:0e:e4:70:e7:
+                    52:2b:30:cc:32:82:ec:51:b3:8d:46:fd:24:37:6e:
+                    74:95:36:49:80:b0:ea:d4:bc:8e:a1:59:ed:0f:3a:
+                    66:67:c8:32:6e:08:b2:0e:a0:d6:10:6c:eb:2e:cb:
+                    a1:f9:5f:aa:27:73:e1:9f:bc:c2:98:bb:1d:97:4f:
+                    8a:45:7f:d5:a4:1f:7e:4c:fe:db:ae:25:75:69:71:
+                    bb:ce:d2:a3:d1:29:f9:a3:ed:33:c7:e2:c3:3c:47:
+                    91:43:0a:0c:66:dd:57:05:64:cf:4a:ba:ec:61:b0:
+                    29:99:77:ab:d5:ff:89:fe:69:3c:96:5a:a6:18:89:
+                    b3:0c:25:3b:ab:7a:bf:1f:e1:8b:64:67:bb:94:2c:
+                    43:e4:a7:f0:d9:3a:66:09:17:78:28:1f:07:0c:65:
+                    9c:fc:f1:ab:4e:a1:61:91:7e:07:78:25:48:7c:f1:
+                    c5:ea:e3:13:63:db:87:33:9e:41:84:6b:d2:4f:fd:
+                    0f:67:88:09:3d:f3:68:d6:41:00:5e:4f:f1:e4:d3:
+                    ec:b4:46:b2:ef:50:a3:87:34:8b
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                54:27:64:9E:DE:45:13:69:13:18:87:0D:67:2F:B0:8D:82:29:91:DA
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:release.debian.org, DNS:www.release.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         ac:e5:82:0b:af:13:56:0b:d3:e7:22:4c:e4:b7:9e:b5:f4:58:
+         0e:1b:b8:9a:c2:e1:6b:ef:99:7f:1e:9b:58:ac:65:77:4e:cc:
+         e5:24:80:8a:ba:fa:20:8e:3c:bb:89:c3:02:98:59:82:4b:33:
+         9e:86:31:95:3a:af:3d:0b:b7:ef:f1:e5:ae:80:d3:99:4d:81:
+         8e:c3:08:35:45:44:40:6c:9e:cb:d6:f9:39:a2:bb:f7:b8:13:
+         44:c8:62:6d:5c:d8:18:61:e4:ae:dc:1b:60:d0:8b:6b:48:c0:
+         44:03:76:51:c9:3f:ea:88:e4:23:e7:42:b0:8d:5a:96:8d:b2:
+         a4:0f:cb:23:a1:de:1e:6e:d1:70:e8:f1:5e:79:95:c9:d4:51:
+         e1:db:20:af:b3:02:cd:77:62:20:d7:c2:fa:6a:39:21:ba:62:
+         5a:df:39:eb:03:a3:8c:c0:da:d9:f2:33:1e:1f:2a:0c:80:aa:
+         a3:97:c0:af:2a:54:2e:ce:ab:23:e1:34:8a:a1:5b:40:a5:bf:
+         37:57:04:af:78:b9:d9:79:45:fc:e0:0e:fb:75:68:a9:a2:bd:
+         fb:00:b8:9e:2d:4e:52:aa:ef:6a:ed:d6:2f:fa:b8:07:ca:92:
+         c1:e7:76:84:9c:58:0c:5f:07:54:61:f8:e4:7a:48:02:b7:1c:
+         c0:78:65:75
+-----BEGIN CERTIFICATE-----
+MIIFbzCCBFegAwIBAgIRAIk16gXhE2sPHtI9xv3pdx0wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDEwMTAwMDAwMFoXDTE1MDEwMTIzNTk1
+OVowXTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGzAZBgNVBAMTEnJlbGVhc2UuZGViaWFuLm9y
+ZzCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBANABXdu/7BhtNZQ9eyBL
+53CiES3xrDFv/FLwBn7+3qZtXP8KCKPV63uuCbjOzUFQ0L+frspNK+X+LcDA80Tr
+WgBG0PSScBDctNhgK5Gftcysd2vKOkSeYH2/tGx6RoywEatUUhmEBFmD2Z39dgiC
+ZHObzubhfjPv7WQ9BctRugPgLQxWe3CM1MPM//dY1j85Ho2eZ5kw1acFAnCNDFRP
+Tv3jiXZhIRZrUfaK8OXwKt0O5HDnUiswzDKC7FGzjUb9JDdudJU2SYCw6tS8jqFZ
+7Q86ZmfIMm4Isg6g1hBs6y7Loflfqidz4Z+8wpi7HZdPikV/1aQffkz+264ldWlx
+u87So9Ep+aPtM8fiwzxHkUMKDGbdVwVkz0q67GGwKZl3q9X/if5pPJZaphiJswwl
+O6t6vx/hi2Rnu5QsQ+Sn8Nk6ZgkXeCgfBwxlnPzxq06hYZF+B3glSHzxxerjE2Pb
+hzOeQYRr0k/9D2eICT3zaNZBAF5P8eTT7LRGsu9Qo4c0iwIDAQABo4IBxDCCAcAw
+HwYDVR0jBBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFFQnZJ7e
+RRNpExiHDWcvsI2CKZHaMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0G
+A1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQB
+sjEBAgIaMDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRy
+YWN0cy9mci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2G
+K2h0dHA6Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYI
+KwYBBQUHAQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9H
+YW5kaVN0YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5n
+YW5kaS5uZXQwNQYDVR0RBC4wLIIScmVsZWFzZS5kZWJpYW4ub3JnghZ3d3cucmVs
+ZWFzZS5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCs5YILrxNWC9PnIkzk
+t5619FgOG7iawuFr75l/HptYrGV3TszlJICKuvogjjy7icMCmFmCSzOehjGVOq89
+C7fv8eWugNOZTYGOwwg1RURAbJ7L1vk5orv3uBNEyGJtXNgYYeSu3Btg0ItrSMBE
+A3ZRyT/qiOQj50KwjVqWjbKkD8sjod4ebtFw6PFeeZXJ1FHh2yCvswLNd2Ig18L6
+ajkhumJa3znrA6OMwNrZ8jMeHyoMgKqjl8CvKlQuzqsj4TSKoVtApb83VwSveLnZ
+eUX84A77dWipor37ALieLU5Squ9q7dYv+rgHypLB53aEnFgMXwdUYfjkekgCtxzA
+eGV1
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/rt.debian.org-new.crt b/modules/ssl/files/servicecerts/rt.debian.org-new.crt
new file mode 100644 (file)
index 0000000..1e8c6c6
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            17:be:fa:45:c3:36:97:26:5f:00:d7:01:bb:be:ce:d4
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=rt.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:c6:af:a6:23:dc:3a:de:ff:c7:e0:54:0b:73:b9:
+                    a4:75:e5:aa:ca:0f:60:69:f9:46:5d:89:5f:74:51:
+                    0c:63:ea:9e:64:eb:35:94:9a:82:f4:11:64:48:4d:
+                    db:3d:5f:2a:4a:32:0d:1f:01:e1:94:9e:db:26:8d:
+                    4f:d0:2e:34:a3:b1:62:fa:e9:75:00:be:01:bc:9c:
+                    e7:4e:1c:1f:9d:c3:40:43:f5:9d:bf:db:37:9f:b2:
+                    ba:fb:1e:5e:3c:b1:4c:57:cd:8b:0c:6a:1b:b0:27:
+                    a0:22:bf:a8:8a:8c:dc:25:10:e6:2e:4c:6c:65:fb:
+                    f7:3b:35:9c:e2:6e:5f:3e:d9:00:0a:3a:7c:7d:10:
+                    4d:0e:0b:b7:4d:5c:b3:84:df:8d:c6:a3:84:2c:86:
+                    dc:cb:6a:68:90:5a:16:53:73:79:eb:df:eb:97:b9:
+                    c9:de:fc:5a:81:0a:64:7c:ee:07:93:1f:13:48:90:
+                    0d:d0:fd:3d:25:ba:f2:b7:92:11:fa:67:71:f9:9e:
+                    f6:8d:ce:53:da:ad:d7:16:fe:3b:ff:9e:71:7e:f0:
+                    64:17:e6:33:50:22:b5:37:40:26:0f:39:bb:c5:28:
+                    d8:3c:dc:55:0e:56:a7:6c:bf:a7:c3:db:47:1f:d9:
+                    c0:01:a1:f7:c6:e6:ba:64:ea:ce:5d:9c:ea:1a:e2:
+                    06:33:2c:19:36:a3:a0:43:e5:0a:2e:70:39:31:d4:
+                    1d:68:16:64:6d:a7:e8:28:79:65:9b:4f:64:79:43:
+                    60:69:2c:86:54:9e:fb:a9:48:78:57:ae:1c:0e:75:
+                    50:c6:00:48:50:4d:c1:fb:b3:a1:31:1c:c4:73:f8:
+                    ba:cf:2a:a5:ee:d4:35:d7:8f:a6:fe:6f:84:0f:e8:
+                    b4:e9:b0:41:79:cd:e4:85:3b:fb:86:01:8b:dc:74:
+                    39:f8:30:d5:30:21:00:f2:cb:80:70:20:0e:04:4c:
+                    fe:bd:a2:64:8b:e7:9f:d3:81:5a:dc:ef:09:8c:4f:
+                    71:1b:75:55:a1:4f:c5:6e:32:8f
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                5A:6A:1D:2C:6A:A5:A4:E9:08:71:54:FC:67:53:FC:5F:12:DA:04:0B
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:rt.debian.org, DNS:www.rt.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         16:f3:16:5e:4b:8e:4a:14:d1:06:f8:c1:bd:71:49:c0:ae:b4:
+         79:e9:49:0a:aa:a8:76:45:64:f7:02:d5:51:66:0f:23:c4:ad:
+         31:4a:26:1d:17:90:30:7d:a4:06:36:e9:a2:45:52:4d:e9:1a:
+         c4:c8:3e:02:81:5f:e5:03:08:76:03:4d:33:5b:ec:cc:7f:5a:
+         b5:fb:d7:bc:35:61:89:ff:5f:f9:c2:5a:f4:e8:2d:4c:86:d0:
+         05:66:43:ca:9a:e6:57:cb:09:62:1f:00:cd:76:13:8c:0b:38:
+         f2:6b:37:b2:4c:07:47:50:38:7c:90:80:e7:27:fe:bd:9d:ec:
+         cb:59:ff:bf:30:86:19:13:34:f3:36:da:d5:d4:4a:3b:db:28:
+         ad:19:53:8b:7f:a8:6f:c9:66:1b:e7:0d:a7:41:d0:1a:7d:47:
+         18:dd:1f:81:71:4d:bc:3d:11:94:73:26:60:e5:c9:5c:e6:89:
+         a0:a6:0e:f5:7e:69:ae:b9:cc:de:e6:4e:3e:4c:b5:94:b9:9a:
+         32:44:15:8f:51:1c:87:86:e4:06:d0:df:e5:e9:d0:b7:67:fc:
+         af:3c:53:99:ef:1b:3e:d3:77:c2:e7:45:ff:78:90:ff:7a:be:
+         ff:9e:89:9e:36:34:aa:a9:d4:8a:2e:1f:c5:78:0c:8b:97:de:
+         dd:92:de:56
+-----BEGIN CERTIFICATE-----
+MIIFXzCCBEegAwIBAgIQF776RcM2lyZfANcBu77O1DANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTMxMjMxMDAwMDAwWhcNMTQxMjMxMjM1OTU5
+WjBYMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEWMBQGA1UEAxMNcnQuZGViaWFuLm9yZzCCAaIw
+DQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMavpiPcOt7/x+BUC3O5pHXlqsoP
+YGn5Rl2JX3RRDGPqnmTrNZSagvQRZEhN2z1fKkoyDR8B4ZSe2yaNT9AuNKOxYvrp
+dQC+Abyc504cH53DQEP1nb/bN5+yuvseXjyxTFfNiwxqG7AnoCK/qIqM3CUQ5i5M
+bGX79zs1nOJuXz7ZAAo6fH0QTQ4Lt01cs4TfjcajhCyG3MtqaJBaFlNzeevf65e5
+yd78WoEKZHzuB5MfE0iQDdD9PSW68reSEfpncfme9o3OU9qt1xb+O/+ecX7wZBfm
+M1AitTdAJg85u8Uo2DzcVQ5Wp2y/p8PbRx/ZwAGh98bmumTqzl2c6hriBjMsGTaj
+oEPlCi5wOTHUHWgWZG2n6Ch5ZZtPZHlDYGkshlSe+6lIeFeuHA51UMYASFBNwfuz
+oTEcxHP4us8qpe7UNdePpv5vhA/otOmwQXnN5IU7+4YBi9x0Ofgw1TAhAPLLgHAg
+DgRM/r2iZIvnn9OBWtzvCYxPcRt1VaFPxW4yjwIDAQABo4IBujCCAbYwHwYDVR0j
+BBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFFpqHSxqpaTpCHFU
+/GdT/F8S2gQLMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQW
+MBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQBsjEBAgIa
+MDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRyYWN0cy9m
+ci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6
+Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYIKwYBBQUH
+AQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9HYW5kaVN0
+YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5nYW5kaS5u
+ZXQwKwYDVR0RBCQwIoINcnQuZGViaWFuLm9yZ4IRd3d3LnJ0LmRlYmlhbi5vcmcw
+DQYJKoZIhvcNAQEFBQADggEBABbzFl5LjkoU0Qb4wb1xScCutHnpSQqqqHZFZPcC
+1VFmDyPErTFKJh0XkDB9pAY26aJFUk3pGsTIPgKBX+UDCHYDTTNb7Mx/WrX717w1
+YYn/X/nCWvToLUyG0AVmQ8qa5lfLCWIfAM12E4wLOPJrN7JMB0dQOHyQgOcn/r2d
+7MtZ/78whhkTNPM22tXUSjvbKK0ZU4t/qG/JZhvnDadB0Bp9RxjdH4FxTbw9EZRz
+JmDlyVzmiaCmDvV+aa65zN7mTj5MtZS5mjJEFY9RHIeG5AbQ3+Xp0Ldn/K88U5nv
+Gz7Td8LnRf94kP96vv+eiZ42NKqp1IouH8V4DIuX3t2S3lY=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/rtc.debian.org-new.crt b/modules/ssl/files/servicecerts/rtc.debian.org-new.crt
new file mode 100644 (file)
index 0000000..34bdfa8
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            9b:f2:f8:d3:a5:a3:e9:47:bb:d3:fb:22:fc:2c:2f:4e
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan 17 00:00:00 2014 GMT
+            Not After : Jan 17 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=rtc.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d7:a6:30:7f:fe:e4:65:ed:51:78:e2:2a:0c:a2:
+                    ce:ea:b0:76:68:1b:88:17:b4:6b:50:91:9b:2a:21:
+                    e3:40:9c:1b:de:60:27:ff:29:80:d2:47:fb:d7:ae:
+                    6b:1f:0a:88:1f:62:bb:d9:9a:d6:97:05:f5:42:d1:
+                    19:e7:7d:2c:2c:e2:e2:d5:da:c3:a1:81:49:bc:a4:
+                    41:e5:24:03:1b:ff:93:66:26:97:77:b9:36:fd:27:
+                    a0:e2:52:f6:a6:64:fb:95:9a:a8:63:a6:6b:45:b6:
+                    64:9c:04:e6:64:71:8f:b2:ae:bb:72:a1:92:70:7d:
+                    b3:78:25:05:67:52:9c:a9:93:53:40:e9:6b:ef:63:
+                    49:df:e2:18:7b:64:a3:c8:f7:a7:10:cb:c6:30:2e:
+                    aa:68:3a:ec:94:61:ba:09:3b:1b:6f:a7:8e:f9:6b:
+                    4a:b6:99:53:f3:9d:92:54:4d:f9:2b:df:47:43:f7:
+                    c6:54:3a:39:b2:b9:7f:2e:3d:cf:49:c9:90:0a:38:
+                    09:23:14:a4:4c:03:06:c0:cc:9a:58:6e:eb:50:c3:
+                    b1:c0:99:8c:69:fd:34:37:34:fa:fd:e0:87:6e:9b:
+                    1f:38:54:49:af:0b:59:33:e8:23:13:2a:c8:b1:d9:
+                    5a:a6:78:9d:80:0e:49:2a:9b:d3:59:7e:30:9a:6b:
+                    69:41:81:34:3b:0c:c4:0b:f2:77:66:fb:89:d8:41:
+                    99:bc:67:88:67:64:1b:2d:79:e0:d3:3d:d3:e0:0c:
+                    7e:4b:b0:81:77:5d:46:47:f7:52:17:ea:30:47:bc:
+                    59:e8:f0:73:98:aa:d5:60:42:c6:11:cc:4d:6b:a9:
+                    94:bf:0c:47:c8:61:9c:d2:36:0c:a2:0d:0e:9d:58:
+                    8c:89:c5:b2:fc:cc:64:fc:fb:10:26:04:87:ee:80:
+                    57:bb:94:2e:01:37:56:27:48:4e:e0:23:15:20:7f:
+                    8c:06:06:f6:ea:e8:94:a8:66:de:25:6c:9a:08:7f:
+                    7b:7c:eb:d5:bd:dc:b4:79:3a:89
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                9C:DA:DE:21:0D:57:97:60:40:42:7A:9A:25:12:29:F7:D5:16:DC:54
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:rtc.debian.org, DNS:www.rtc.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         6a:22:87:3d:27:70:a2:1f:66:92:1f:49:82:27:f2:cd:3c:64:
+         07:f1:bb:21:4f:2c:d4:72:70:cc:2d:ca:ab:3a:0a:99:39:0a:
+         04:ff:db:78:61:b7:f5:02:5d:c5:83:53:56:e7:7a:38:0c:69:
+         62:54:94:4f:85:a6:05:9c:d3:84:51:1c:0a:fd:0a:42:2b:d1:
+         67:3c:c5:79:1f:93:e3:5a:b2:08:c1:cb:f4:a5:48:0f:80:cd:
+         91:ab:e8:d6:d0:b9:8e:b8:e7:8b:eb:53:85:f7:7e:a5:69:6f:
+         4a:4a:83:c6:d8:12:51:5f:74:2c:74:df:2c:02:0c:fe:1a:0f:
+         a4:ac:17:31:5f:63:a5:26:a3:b1:ae:3c:05:f6:cb:a0:f6:18:
+         70:94:7c:48:9f:ce:8f:72:42:11:e2:67:4f:47:94:10:29:21:
+         a5:f0:dc:5b:0c:7d:eb:64:04:d2:51:82:c2:28:90:97:33:67:
+         11:57:fc:a6:b7:9b:d6:8b:24:53:50:f2:65:d1:1d:5e:13:b3:
+         46:30:c7:86:a2:fa:53:ca:e4:5e:04:8a:fd:ad:80:99:2d:53:
+         26:94:51:30:25:1c:9d:80:e6:a4:e3:45:dd:b3:d2:1b:d3:f4:
+         a5:55:50:87:84:4e:27:d0:a2:bb:25:e0:d9:5f:07:ba:89:cc:
+         5d:6f:a0:09
+-----BEGIN CERTIFICATE-----
+MIIFYzCCBEugAwIBAgIRAJvy+NOlo+lHu9P7IvwsL04wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDExNzAwMDAwMFoXDTE1MDExNzIzNTk1
+OVowWTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxFzAVBgNVBAMTDnJ0Yy5kZWJpYW4ub3JnMIIB
+ojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEA16Ywf/7kZe1ReOIqDKLO6rB2
+aBuIF7RrUJGbKiHjQJwb3mAn/ymA0kf7165rHwqIH2K72ZrWlwX1QtEZ530sLOLi
+1drDoYFJvKRB5SQDG/+TZiaXd7k2/Seg4lL2pmT7lZqoY6ZrRbZknATmZHGPsq67
+cqGScH2zeCUFZ1KcqZNTQOlr72NJ3+IYe2SjyPenEMvGMC6qaDrslGG6CTsbb6eO
++WtKtplT852SVE35K99HQ/fGVDo5srl/Lj3PScmQCjgJIxSkTAMGwMyaWG7rUMOx
+wJmMaf00NzT6/eCHbpsfOFRJrwtZM+gjEyrIsdlapnidgA5JKpvTWX4wmmtpQYE0
+OwzEC/J3ZvuJ2EGZvGeIZ2QbLXng0z3T4Ax+S7CBd11GR/dSF+owR7xZ6PBzmKrV
+YELGEcxNa6mUvwxHyGGc0jYMog0OnViMicWy/Mxk/PsQJgSH7oBXu5QuATdWJ0hO
+4CMVIH+MBgb26uiUqGbeJWyaCH97fOvVvdy0eTqJAgMBAAGjggG8MIIBuDAfBgNV
+HSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQUnNreIQ1Xl2BA
+QnqaJRIp99UW3FQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0l
+BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGyMQEC
+AhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJhY3Rz
+L2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYraHR0
+cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggrBgEF
+BQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dhbmRp
+U3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdhbmRp
+Lm5ldDAtBgNVHREEJjAkgg5ydGMuZGViaWFuLm9yZ4ISd3d3LnJ0Yy5kZWJpYW4u
+b3JnMA0GCSqGSIb3DQEBBQUAA4IBAQBqIoc9J3CiH2aSH0mCJ/LNPGQH8bshTyzU
+cnDMLcqrOgqZOQoE/9t4Ybf1Al3Fg1NW53o4DGliVJRPhaYFnNOEURwK/QpCK9Fn
+PMV5H5PjWrIIwcv0pUgPgM2Rq+jW0LmOuOeL61OF936laW9KSoPG2BJRX3QsdN8s
+Agz+Gg+krBcxX2OlJqOxrjwF9sug9hhwlHxIn86PckIR4mdPR5QQKSGl8NxbDH3r
+ZATSUYLCKJCXM2cRV/ymt5vWiyRTUPJl0R1eE7NGMMeGovpTyuReBIr9rYCZLVMm
+lFEwJRydgOak40Xds9Ib0/SlVVCHhE4n0KK7JeDZXwe6icxdb6AJ
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/security-tracker.debian.org-new.crt b/modules/ssl/files/servicecerts/security-tracker.debian.org-new.crt
new file mode 100644 (file)
index 0000000..2f9b799
--- /dev/null
@@ -0,0 +1,118 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            2d:71:6f:44:fa:dc:f1:c9:08:26:1a:ab:8f:29:16:f8
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=security-tracker.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:cf:fd:ef:f2:c5:2a:7a:da:d2:07:2c:21:c9:89:
+                    e4:21:0e:f6:c8:72:b2:15:90:fe:5c:d9:b7:1a:5b:
+                    83:f4:84:e7:a3:d6:95:cf:c5:d1:57:dd:a9:ac:67:
+                    23:27:c8:a6:1a:73:20:f4:c9:a2:23:67:50:e7:df:
+                    49:20:3f:01:3d:2c:3a:95:50:a3:98:80:e8:c5:81:
+                    54:de:74:e9:99:24:0a:33:63:e2:5f:13:16:63:27:
+                    45:bc:e8:2a:5a:2e:40:d2:85:99:dd:54:ff:07:53:
+                    90:f6:02:83:e1:5d:23:79:14:1c:14:7f:64:09:be:
+                    92:66:8c:7f:4c:3d:a9:c6:57:b9:70:a0:83:b3:e8:
+                    f3:ec:cc:2a:e3:7b:4d:7c:fd:c5:c5:ca:7b:c5:99:
+                    0d:39:b2:a1:05:49:6e:38:57:4c:4b:9b:e0:36:a4:
+                    bf:cb:2e:b5:76:bd:c5:c3:11:48:a0:06:38:e2:a4:
+                    ed:47:92:2c:72:4c:ce:c9:12:39:94:c7:bc:7e:7f:
+                    82:bb:72:e8:f4:50:57:8f:a7:5a:ab:40:b0:7b:79:
+                    b9:50:28:7a:ce:be:96:38:79:e3:ce:25:6e:c9:dd:
+                    c4:15:22:cd:9b:77:97:cb:54:9d:46:9c:50:a8:c2:
+                    4b:c9:62:c1:42:d4:b2:7f:0d:54:31:85:51:e3:ca:
+                    5d:f1:9a:1f:68:ef:12:08:94:40:40:b0:1b:05:35:
+                    75:f3:e2:d5:ff:c3:46:3c:54:4e:2b:c3:2c:8e:e6:
+                    5b:78:de:36:ee:4c:83:c1:75:5d:06:0b:ff:8c:80:
+                    ac:a7:fe:f6:21:9c:94:ca:f9:13:02:cb:31:4a:2b:
+                    49:26:fd:f1:3c:ad:bd:c6:b6:93:c5:6a:e6:6f:bb:
+                    e4:88:5e:8c:0d:bf:4f:2a:12:59:9b:ae:2d:36:f1:
+                    31:db:e5:0f:25:05:99:2e:ad:ba:76:19:2b:49:e3:
+                    76:81:b8:91:f8:89:b8:92:db:7c:8f:3f:15:d3:eb:
+                    b8:e3:19:58:6b:c5:8f:a8:51:d1
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                EE:8D:2D:52:28:5E:D4:85:53:F2:6C:13:2A:72:6D:21:07:4D:B7:F5
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:security-tracker.debian.org, DNS:www.security-tracker.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         83:c5:3d:47:b8:af:9a:70:6c:c4:30:a4:e4:6a:85:c1:f2:ce:
+         ba:40:a5:34:99:9a:35:93:2a:8b:c0:26:dd:56:eb:e4:6b:35:
+         3b:f2:9e:1d:3c:39:d5:88:ce:f9:89:a8:7b:68:1a:71:f0:66:
+         8c:54:1e:b5:37:80:8b:fa:8b:45:17:a6:7c:15:8a:7e:37:a9:
+         29:fd:85:cd:4c:fe:ed:f3:ad:25:c1:5d:67:a1:96:02:d6:d0:
+         0e:a9:e2:29:81:8d:20:8a:f6:d7:ab:c1:fb:a4:45:0c:d3:bb:
+         99:7a:11:43:c4:e1:b4:9c:2e:0c:3f:f6:e0:53:2a:07:b7:3c:
+         9a:76:57:65:a9:07:4c:a0:16:56:45:b7:69:cb:97:83:bf:bf:
+         49:13:8a:db:ae:32:61:49:1a:ed:5a:9c:b1:50:a0:37:c2:82:
+         6e:5f:5a:2e:31:1f:29:6c:7b:20:34:41:9f:69:83:45:c4:0c:
+         2b:39:fa:dd:9c:22:69:2d:a0:eb:ab:ae:2a:c2:c5:57:a8:a4:
+         b8:fa:ea:b0:27:77:38:9c:45:ee:3c:77:e1:0e:bf:30:e3:24:
+         8a:6a:c6:c7:dc:58:cc:93:a3:c4:3f:54:b7:c9:2e:89:49:a5:
+         43:1d:8e:f4:06:c9:c3:ef:04:d3:50:ff:8d:e7:58:4f:25:17:
+         f9:10:b5:c9
+-----BEGIN CERTIFICATE-----
+MIIFiTCCBHGgAwIBAgIQLXFvRPrc8ckIJhqrjykW+DANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTMxMjMxMDAwMDAwWhcNMTQxMjMxMjM1OTU5
+WjBmMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEkMCIGA1UEAxMbc2VjdXJpdHktdHJhY2tlci5k
+ZWJpYW4ub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAz/3v8sUq
+etrSBywhyYnkIQ72yHKyFZD+XNm3GluD9ITno9aVz8XRV92prGcjJ8imGnMg9Mmi
+I2dQ599JID8BPSw6lVCjmIDoxYFU3nTpmSQKM2PiXxMWYydFvOgqWi5A0oWZ3VT/
+B1OQ9gKD4V0jeRQcFH9kCb6SZox/TD2pxle5cKCDs+jz7Mwq43tNfP3Fxcp7xZkN
+ObKhBUluOFdMS5vgNqS/yy61dr3FwxFIoAY44qTtR5IsckzOyRI5lMe8fn+Cu3Lo
+9FBXj6daq0Cwe3m5UCh6zr6WOHnjziVuyd3EFSLNm3eXy1SdRpxQqMJLyWLBQtSy
+fw1UMYVR48pd8ZofaO8SCJRAQLAbBTV18+LV/8NGPFROK8MsjuZbeN427kyDwXVd
+Bgv/jICsp/72IZyUyvkTAssxSitJJv3xPK29xraTxWrmb7vkiF6MDb9PKhJZm64t
+NvEx2+UPJQWZLq26dhkrSeN2gbiR+Im4ktt8jz8V0+u44xlYa8WPqFHRAgMBAAGj
+ggHWMIIB0jAfBgNVHSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4E
+FgQU7o0tUihe1IVT8mwTKnJtIQdNt/UwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
+/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcw
+SwYLKwYBBAGyMQECAhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5u
+ZXQvY29udHJhY3RzL2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUw
+MzAxoC+gLYYraHR0cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENB
+LmNybDBqBggrBgEFBQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2Fu
+ZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6
+Ly9vY3NwLmdhbmRpLm5ldDBHBgNVHREEQDA+ghtzZWN1cml0eS10cmFja2VyLmRl
+Ymlhbi5vcmeCH3d3dy5zZWN1cml0eS10cmFja2VyLmRlYmlhbi5vcmcwDQYJKoZI
+hvcNAQEFBQADggEBAIPFPUe4r5pwbMQwpORqhcHyzrpApTSZmjWTKovAJt1W6+Rr
+NTvynh08OdWIzvmJqHtoGnHwZoxUHrU3gIv6i0UXpnwVin43qSn9hc1M/u3zrSXB
+XWehlgLW0A6p4imBjSCK9terwfukRQzTu5l6EUPE4bScLgw/9uBTKge3PJp2V2Wp
+B0ygFlZFt2nLl4O/v0kTituuMmFJGu1anLFQoDfCgm5fWi4xHylseyA0QZ9pg0XE
+DCs5+t2cImktoOurrirCxVeopLj66rAndzicRe48d+EOvzDjJIpqxsfcWMyTo8Q/
+VLfJLolJpUMdjvQGycPvBNNQ/43nWE8lF/kQtck=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/sip-ws.debian.org-new.crt b/modules/ssl/files/servicecerts/sip-ws.debian.org-new.crt
new file mode 100644 (file)
index 0000000..ede142f
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            e7:a4:71:bc:fc:5f:7d:9e:e2:06:00:b6:3f:d9:29:7b
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan 13 00:00:00 2014 GMT
+            Not After : Jan 13 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=sip-ws.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:ba:a6:d2:26:06:bc:41:7e:32:0d:ba:e4:0a:66:
+                    6e:3a:60:9f:d5:f8:53:3b:fe:44:9e:14:32:4b:b9:
+                    5b:a9:6c:68:c3:a8:ff:10:a8:39:be:a0:74:dd:45:
+                    18:d2:e6:26:04:52:c3:bc:47:d4:7e:85:ea:64:e6:
+                    dd:aa:eb:ef:8c:fa:02:6a:86:6f:2b:c3:67:98:a9:
+                    01:16:2d:f1:9a:b7:99:32:08:a5:2c:c0:4a:71:9b:
+                    7d:8a:3f:b0:52:62:32:8f:5f:51:fb:2d:3d:9a:b3:
+                    43:b5:ed:ee:13:ab:5a:7b:b1:aa:d9:63:ca:a7:25:
+                    79:b8:d1:1b:e6:9f:7f:9d:ac:27:2b:d4:f2:b9:7e:
+                    56:ac:c0:e0:dd:a0:2f:a6:06:67:51:d6:b7:65:11:
+                    7c:0f:09:c2:16:cb:7f:78:c2:f4:7d:d8:8f:c0:c5:
+                    98:74:7b:d8:af:f6:b7:19:ec:19:fb:47:5a:d3:86:
+                    5b:20:4d:e2:da:1c:77:6d:61:2d:65:8e:64:ae:0d:
+                    00:ba:8c:c3:49:57:5f:95:6f:5c:21:c6:ed:67:40:
+                    67:39:c8:43:0c:bc:61:f6:c1:f9:27:bf:5d:d9:47:
+                    9a:05:a0:ff:ad:d3:e5:0a:48:09:68:d5:d1:92:b9:
+                    26:50:b8:1b:a4:7b:a9:3b:f0:0f:b3:ff:f8:02:74:
+                    47:f0:3b:6f:80:d4:57:e4:93:7e:81:04:14:29:1e:
+                    84:63:d8:70:0d:3f:5c:53:d3:e7:b0:36:b2:21:2a:
+                    2a:2f:bc:ad:a1:c9:71:b6:c2:43:d3:dd:23:70:65:
+                    ce:c9:a4:55:58:95:f0:66:81:3d:5f:65:b3:35:67:
+                    b1:0c:82:86:84:4b:f9:0a:fa:75:7f:99:8b:8c:da:
+                    91:7a:db:85:53:1d:e4:12:81:74:be:6b:c0:d0:3c:
+                    fa:88:35:74:55:6a:d7:85:26:fa:6a:d8:c2:a6:ce:
+                    75:17:a2:0c:23:b8:a0:a1:c3:9d:ab:8b:51:67:4a:
+                    1e:a3:21:58:06:1f:de:37:bd:4f
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                E9:DC:7B:40:D6:C8:59:1D:4D:65:BE:00:B4:96:8F:DF:6B:F9:F4:FE
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:sip-ws.debian.org, DNS:www.sip-ws.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         af:2b:cd:c1:23:e9:86:b5:2e:3b:cc:7e:3d:7e:e2:12:14:f3:
+         02:fc:c7:f0:60:1e:05:84:1f:2f:55:df:3b:e2:1e:00:5a:43:
+         fe:85:01:4d:ff:45:50:5f:17:0a:c7:ae:88:83:dc:32:82:ea:
+         95:b0:fa:5c:39:dd:aa:b5:5c:8c:67:a1:40:7a:85:c7:2f:7b:
+         3e:95:b7:06:f0:f5:63:9e:37:49:f1:74:64:ad:38:d0:da:c6:
+         dc:be:ea:32:c6:16:bd:22:14:b1:89:6b:b2:f1:39:c7:29:fc:
+         14:dc:b2:b9:cc:55:f1:a5:81:d7:e8:ef:b2:58:63:f4:2c:de:
+         fc:f2:4a:9b:d4:2c:e3:4c:6b:c2:92:04:e0:af:bc:0d:38:36:
+         57:ef:f1:f0:c6:d6:b3:cf:89:d0:8a:e0:35:62:c8:27:e0:7c:
+         61:71:2c:a1:cb:db:d8:2b:e6:c2:d0:ec:e5:da:2d:47:a2:1b:
+         da:58:d8:09:3f:39:49:d0:0b:96:ff:f8:8a:25:5f:e3:48:b0:
+         06:cf:5a:a5:40:94:6d:4b:0e:8d:31:fd:66:76:16:18:ee:98:
+         0f:b3:01:24:44:bf:ce:4b:0b:0f:46:54:56:b6:9b:98:18:90:
+         bc:04:7e:41:e1:3f:7e:74:38:7d:fd:03:78:37:0c:a6:44:36:
+         54:28:22:c9
+-----BEGIN CERTIFICATE-----
+MIIFbDCCBFSgAwIBAgIRAOekcbz8X32e4gYAtj/ZKXswDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTE0MDExMzAwMDAwMFoXDTE1MDExMzIzNTk1
+OVowXDEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGjAYBgNVBAMTEXNpcC13cy5kZWJpYW4ub3Jn
+MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuqbSJga8QX4yDbrkCmZu
+OmCf1fhTO/5EnhQyS7lbqWxow6j/EKg5vqB03UUY0uYmBFLDvEfUfoXqZObdquvv
+jPoCaoZvK8NnmKkBFi3xmreZMgilLMBKcZt9ij+wUmIyj19R+y09mrNDte3uE6ta
+e7Gq2WPKpyV5uNEb5p9/nawnK9TyuX5WrMDg3aAvpgZnUda3ZRF8DwnCFst/eML0
+fdiPwMWYdHvYr/a3GewZ+0da04ZbIE3i2hx3bWEtZY5krg0AuozDSVdflW9cIcbt
+Z0BnOchDDLxh9sH5J79d2UeaBaD/rdPlCkgJaNXRkrkmULgbpHupO/APs//4AnRH
+8DtvgNRX5JN+gQQUKR6EY9hwDT9cU9PnsDayISoqL7ytoclxtsJD090jcGXOyaRV
+WJXwZoE9X2WzNWexDIKGhEv5Cvp1f5mLjNqRetuFUx3kEoF0vmvA0Dz6iDV0VWrX
+hSb6atjCps51F6IMI7igocOdq4tRZ0oeoyFYBh/eN71PAgMBAAGjggHCMIIBvjAf
+BgNVHSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQU6dx7QNbI
+WR1NZb4AtJaP32v59P4wDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYD
+VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGy
+MQECAhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJh
+Y3RzL2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYr
+aHR0cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggr
+BgEFBQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dh
+bmRpU3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdh
+bmRpLm5ldDAzBgNVHREELDAqghFzaXAtd3MuZGViaWFuLm9yZ4IVd3d3LnNpcC13
+cy5kZWJpYW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCvK83BI+mGtS47zH49fuIS
+FPMC/MfwYB4FhB8vVd874h4AWkP+hQFN/0VQXxcKx66Ig9wyguqVsPpcOd2qtVyM
+Z6FAeoXHL3s+lbcG8PVjnjdJ8XRkrTjQ2sbcvuoyxha9IhSxiWuy8TnHKfwU3LK5
+zFXxpYHX6O+yWGP0LN788kqb1CzjTGvCkgTgr7wNODZX7/Hwxtazz4nQiuA1Ysgn
+4HxhcSyhy9vYK+bC0Ozl2i1HohvaWNgJPzlJ0AuW//iKJV/jSLAGz1qlQJRtSw6N
+Mf1mdhYY7pgPswEkRL/OSwsPRlRWtpuYGJC8BH5B4T9+dDh9/QN4NwymRDZUKCLJ
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/sso.debian.org-new.crt b/modules/ssl/files/servicecerts/sso.debian.org-new.crt
new file mode 100644 (file)
index 0000000..47f696d
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            f8:a1:1f:86:3c:00:85:63:a7:d7:17:35:26:92:a1:e6
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=sso.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d0:5e:97:e4:17:d9:42:32:91:b8:e7:33:32:fd:
+                    23:60:e3:95:60:fb:f8:f4:bd:20:47:81:65:18:95:
+                    d6:42:98:b8:ba:3f:2d:be:ab:b9:df:fb:91:51:fc:
+                    50:67:7a:a8:00:f9:97:bc:6e:d4:0d:36:05:12:b6:
+                    54:48:f1:14:71:54:9d:92:71:27:7b:ad:2f:70:4e:
+                    44:0a:e3:96:7f:60:b8:78:90:d7:9c:15:48:c5:ce:
+                    ce:8c:49:3d:9c:f9:8b:5c:3f:47:74:a7:3d:14:4b:
+                    c9:7f:ca:f5:be:17:1c:c5:f7:63:a1:5c:47:b8:d6:
+                    04:1b:dc:e8:55:f5:ce:7c:f7:9f:40:b5:4c:be:f9:
+                    a3:a7:c7:01:7d:b4:b2:20:c6:f1:5a:bc:98:04:2b:
+                    07:bf:37:20:0f:c7:7d:26:5f:7b:38:1f:f0:fd:b0:
+                    4d:00:5d:4d:4b:c0:03:1e:a2:4b:bb:db:fa:de:35:
+                    68:7c:c8:7f:4b:6a:5a:0e:1b:bf:23:ac:eb:f4:60:
+                    35:27:04:f7:97:3d:e5:c0:e5:c3:1a:d8:c5:47:8d:
+                    2b:df:5f:f0:e7:9b:53:9f:8a:2f:3f:a7:74:9d:4b:
+                    06:14:4d:d8:c7:e0:81:a8:4f:40:3a:78:fe:6e:3b:
+                    3a:a3:dd:23:48:fe:c8:87:9f:eb:a5:12:79:e9:b2:
+                    a7:a9:4f:63:37:44:7f:1a:90:55:38:02:eb:85:1e:
+                    2e:c7:a7:f9:02:a7:c7:7f:40:fd:72:bc:b3:79:50:
+                    39:0f:03:a6:5c:9a:d2:1a:3d:1d:56:80:61:54:9e:
+                    c9:a3:f9:9e:cb:49:d1:0e:f2:31:21:a9:79:0a:24:
+                    63:e7:6e:69:31:a6:6a:5f:1c:7c:77:67:e5:69:a1:
+                    d9:3f:65:9f:8f:66:9f:54:8a:e4:1c:1b:6e:01:aa:
+                    8c:e1:74:31:4d:90:92:67:ff:0e:1a:32:18:05:0c:
+                    8c:2a:92:f5:44:0f:a6:72:2c:6d:2f:ec:8d:77:ca:
+                    43:40:ce:75:2f:ab:76:43:cc:89
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                5B:38:D5:BA:26:5F:C3:DE:B2:10:57:54:E7:B0:4F:1C:39:FD:12:9B
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:sso.debian.org, DNS:www.sso.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         ad:cd:63:32:e7:0c:f4:1c:16:2d:84:ec:66:68:d9:23:14:aa:
+         a3:e6:7e:8b:e5:85:ec:78:2a:ee:0a:c6:b4:3d:dc:15:24:fc:
+         e8:14:67:1a:79:f7:cf:b3:43:e4:12:75:80:61:80:f8:c0:09:
+         6b:7e:5f:d9:95:f5:cc:6e:e4:4d:c7:f4:67:44:a1:83:fe:58:
+         8a:89:7c:35:92:fe:48:36:8d:90:98:7b:89:98:41:f8:20:14:
+         d9:d5:27:87:40:9e:54:be:1c:98:b1:5f:24:91:b3:b8:ec:8c:
+         0b:31:17:59:e1:4e:be:b9:28:4c:ed:8c:6b:56:34:4e:8b:0d:
+         50:17:19:e7:74:d2:83:4e:2c:c4:4b:40:b7:5b:45:f0:f4:f0:
+         5e:9b:79:85:f5:6f:f4:df:65:e2:18:98:68:55:60:27:59:7e:
+         c0:84:e0:3e:b2:44:42:b6:6c:bb:08:bf:88:12:e5:48:3e:40:
+         60:3e:db:19:bc:bd:94:33:b7:be:1f:cc:60:c1:76:6e:cb:62:
+         52:33:34:10:cf:2a:58:7d:5e:39:9c:ac:e2:1b:27:d4:dc:5b:
+         10:f7:6c:c2:d8:13:d4:ad:bf:80:09:53:1e:05:35:94:2d:fb:
+         98:4b:e2:f0:0d:42:8c:8c:1c:3e:c3:71:b2:d5:76:63:5e:87:
+         93:12:c8:14
+-----BEGIN CERTIFICATE-----
+MIIFYzCCBEugAwIBAgIRAPihH4Y8AIVjp9cXNSaSoeYwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMTAwMDAwMFoXDTE0MTIzMTIzNTk1
+OVowWTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxFzAVBgNVBAMTDnNzby5kZWJpYW4ub3JnMIIB
+ojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEA0F6X5BfZQjKRuOczMv0jYOOV
+YPv49L0gR4FlGJXWQpi4uj8tvqu53/uRUfxQZ3qoAPmXvG7UDTYFErZUSPEUcVSd
+knEne60vcE5ECuOWf2C4eJDXnBVIxc7OjEk9nPmLXD9HdKc9FEvJf8r1vhccxfdj
+oVxHuNYEG9zoVfXOfPefQLVMvvmjp8cBfbSyIMbxWryYBCsHvzcgD8d9Jl97OB/w
+/bBNAF1NS8ADHqJLu9v63jVofMh/S2paDhu/I6zr9GA1JwT3lz3lwOXDGtjFR40r
+31/w55tTn4ovP6d0nUsGFE3Yx+CBqE9AOnj+bjs6o90jSP7Ih5/rpRJ56bKnqU9j
+N0R/GpBVOALrhR4ux6f5AqfHf0D9cryzeVA5DwOmXJrSGj0dVoBhVJ7Jo/mey0nR
+DvIxIal5CiRj525pMaZqXxx8d2flaaHZP2Wfj2afVIrkHBtuAaqM4XQxTZCSZ/8O
+GjIYBQyMKpL1RA+mcixtL+yNd8pDQM51L6t2Q8yJAgMBAAGjggG8MIIBuDAfBgNV
+HSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQUWzjVuiZfw96y
+EFdU57BPHDn9EpswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0l
+BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGyMQEC
+AhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJhY3Rz
+L2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYraHR0
+cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggrBgEF
+BQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dhbmRp
+U3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdhbmRp
+Lm5ldDAtBgNVHREEJjAkgg5zc28uZGViaWFuLm9yZ4ISd3d3LnNzby5kZWJpYW4u
+b3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCtzWMy5wz0HBYthOxmaNkjFKqj5n6L5YXs
+eCruCsa0PdwVJPzoFGcaeffPs0PkEnWAYYD4wAlrfl/ZlfXMbuRNx/RnRKGD/liK
+iXw1kv5INo2QmHuJmEH4IBTZ1SeHQJ5UvhyYsV8kkbO47IwLMRdZ4U6+uShM7Yxr
+VjROiw1QFxnndNKDTizES0C3W0Xw9PBem3mF9W/032XiGJhoVWAnWX7AhOA+skRC
+tmy7CL+IEuVIPkBgPtsZvL2UM7e+H8xgwXZuy2JSMzQQzypYfV45nKziGyfU3FsQ
+92zC2BPUrb+ACVMeBTWULfuYS+LwDUKMjBw+w3Gy1XZjXoeTEsgU
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/udd.debian.org-new.crt b/modules/ssl/files/servicecerts/udd.debian.org-new.crt
new file mode 100644 (file)
index 0000000..6cf9dd4
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            bb:27:08:0a:32:ae:fa:2d:b2:9d:f5:db:ee:88:fa:94
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 30 00:00:00 2013 GMT
+            Not After : Dec 30 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=udd.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:c1:eb:19:ed:92:6f:75:c5:03:29:c5:44:91:6c:
+                    a8:89:34:02:54:1a:70:ce:ea:3d:db:ee:dd:aa:4f:
+                    04:03:e7:eb:46:54:92:92:a6:70:03:1d:48:9b:c1:
+                    0d:b6:77:d3:98:4e:c9:51:e5:6d:a3:9e:62:71:50:
+                    53:65:70:ea:7b:84:3f:97:2e:37:74:f5:fe:78:0d:
+                    1d:3a:27:b0:7a:32:ba:23:95:d4:07:31:2d:5e:5c:
+                    4c:3f:12:29:bf:f3:22:72:e7:d0:8d:8b:dc:ec:6c:
+                    bc:cf:ca:c9:d3:5a:9b:07:6f:d7:9b:cb:66:33:e8:
+                    fd:de:62:92:f2:f7:54:7c:49:0c:b3:4b:f5:da:e3:
+                    28:7d:38:48:34:80:b9:52:b8:24:03:a4:cb:ee:17:
+                    d8:88:43:55:7c:e3:9c:34:e1:eb:a5:07:85:b4:d3:
+                    91:75:1f:6c:ea:c2:07:f0:4e:3d:8b:af:8d:4b:f8:
+                    72:ca:6f:34:e5:0e:c4:d7:0b:e0:86:da:cc:1b:4f:
+                    d7:f6:7b:59:2f:be:84:53:cd:04:15:a5:1f:ab:45:
+                    ac:fd:90:21:9a:26:f4:4b:d2:ac:c4:69:d8:5a:f4:
+                    2c:74:31:ad:70:44:2a:b0:d8:57:20:17:0b:70:e4:
+                    ca:a5:c9:5a:bb:d5:6c:2f:8e:8c:cf:b0:37:57:17:
+                    8d:e6:0f:c4:94:45:6c:1a:b4:1a:34:7d:4e:35:de:
+                    16:d7:22:5d:49:f5:49:78:3b:fa:cc:04:f9:d9:c5:
+                    dd:b5:8a:a0:d1:ec:e4:d3:0d:5b:8f:57:65:a2:31:
+                    4f:6f:8c:98:cc:59:eb:25:74:d8:19:e0:43:10:f3:
+                    80:0c:8e:74:0f:3f:31:24:17:c9:91:ff:59:1b:9a:
+                    57:4e:9b:87:92:8b:91:68:a2:a5:a2:95:63:7f:2d:
+                    d7:66:4c:9d:f7:74:6d:00:3b:a4:3c:d3:71:c9:30:
+                    b7:f5:84:ee:0f:1c:22:1a:bf:92:b5:31:ab:09:dc:
+                    b2:f6:25:2d:bc:46:67:1c:d8:33
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                C9:00:B8:C3:DE:B0:10:B5:9B:9E:7C:EF:32:20:81:65:89:50:15:10
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:udd.debian.org, DNS:www.udd.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         a3:db:73:4a:b0:b4:57:60:10:82:45:c6:ad:79:93:9f:84:b3:
+         be:50:d7:cf:df:d0:1c:35:bc:f7:b6:11:c8:44:9b:e1:ee:6e:
+         d6:ea:22:b1:bb:7c:f1:dd:96:f3:8b:a7:0f:b4:cc:e1:33:8a:
+         88:c2:4c:cc:72:53:4a:d2:2f:e4:7f:af:07:3e:d7:8e:14:70:
+         ea:75:b8:10:a5:bb:c2:af:81:27:5f:10:68:ff:21:6e:fc:97:
+         ac:98:31:15:ad:c0:71:d5:7c:4b:fb:e8:45:e3:fb:c8:94:f4:
+         b5:6d:81:4c:e4:9e:1e:14:c0:a1:72:d8:f2:f8:cd:02:b4:ea:
+         56:d0:d6:df:e8:37:56:dd:59:99:9c:31:fd:5d:f4:72:64:66:
+         e8:49:90:15:ed:b4:fa:e4:f1:3a:97:94:aa:79:6a:81:37:5b:
+         04:4e:7d:ac:c7:66:47:90:b2:54:1f:e4:2a:c5:9c:72:8e:2b:
+         ce:76:64:82:41:eb:7e:2f:d4:2a:81:d7:8c:b2:9f:65:0d:0a:
+         a5:22:a5:59:9c:99:3e:25:3b:38:5a:21:91:b3:4c:d4:39:23:
+         c6:2a:c4:a9:19:bc:fe:3a:a3:3d:9c:21:12:b6:b1:0c:52:b8:
+         27:f5:3e:42:5e:19:fd:20:da:c7:c6:e6:f0:d8:6d:ef:f3:27:
+         a6:4e:fd:49
+-----BEGIN CERTIFICATE-----
+MIIFYzCCBEugAwIBAgIRALsnCAoyrvotsp312+6I+pQwDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMDAwMDAwMFoXDTE0MTIzMDIzNTk1
+OVowWTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxFzAVBgNVBAMTDnVkZC5kZWJpYW4ub3JnMIIB
+ojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAwesZ7ZJvdcUDKcVEkWyoiTQC
+VBpwzuo92+7dqk8EA+frRlSSkqZwAx1Im8ENtnfTmE7JUeVto55icVBTZXDqe4Q/
+ly43dPX+eA0dOiewejK6I5XUBzEtXlxMPxIpv/MicufQjYvc7Gy8z8rJ01qbB2/X
+m8tmM+j93mKS8vdUfEkMs0v12uMofThINIC5UrgkA6TL7hfYiENVfOOcNOHrpQeF
+tNORdR9s6sIH8E49i6+NS/hyym805Q7E1wvghtrMG0/X9ntZL76EU80EFaUfq0Ws
+/ZAhmib0S9KsxGnYWvQsdDGtcEQqsNhXIBcLcOTKpclau9VsL46Mz7A3VxeN5g/E
+lEVsGrQaNH1ONd4W1yJdSfVJeDv6zAT52cXdtYqg0ezk0w1bj1dlojFPb4yYzFnr
+JXTYGeBDEPOADI50Dz8xJBfJkf9ZG5pXTpuHkouRaKKlopVjfy3XZkyd93RtADuk
+PNNxyTC39YTuDxwiGr+StTGrCdyy9iUtvEZnHNgzAgMBAAGjggG8MIIBuDAfBgNV
+HSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQUyQC4w96wELWb
+nnzvMiCBZYlQFRAwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0l
+BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGyMQEC
+AhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJhY3Rz
+L2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYraHR0
+cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggrBgEF
+BQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dhbmRp
+U3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdhbmRp
+Lm5ldDAtBgNVHREEJjAkgg51ZGQuZGViaWFuLm9yZ4ISd3d3LnVkZC5kZWJpYW4u
+b3JnMA0GCSqGSIb3DQEBBQUAA4IBAQCj23NKsLRXYBCCRcateZOfhLO+UNfP39Ac
+Nbz3thHIRJvh7m7W6iKxu3zx3Zbzi6cPtMzhM4qIwkzMclNK0i/kf68HPteOFHDq
+dbgQpbvCr4EnXxBo/yFu/JesmDEVrcBx1XxL++hF4/vIlPS1bYFM5J4eFMChctjy
++M0CtOpW0Nbf6DdW3VmZnDH9XfRyZGboSZAV7bT65PE6l5SqeWqBN1sETn2sx2ZH
+kLJUH+QqxZxyjivOdmSCQet+L9QqgdeMsp9lDQqlIqVZnJk+JTs4WiGRs0zUOSPG
+KsSpGbz+OqM9nCEStrEMUrgn9T5CXhn9INrHxubw2G3v8yemTv1J
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/vote.debian.org-new.crt b/modules/ssl/files/servicecerts/vote.debian.org-new.crt
new file mode 100644 (file)
index 0000000..d8aac26
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            50:0a:b9:84:b9:1b:4f:7e:90:cc:74:97:ef:71:e5:3c
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jan  1 00:00:00 2014 GMT
+            Not After : Jan  1 23:59:59 2015 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=vote.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:c4:13:2e:18:48:aa:5b:3a:25:20:a4:12:9f:bc:
+                    3b:0b:08:c5:5d:8e:df:c5:b4:f5:b9:9e:a2:48:5a:
+                    7b:47:18:26:d9:1a:47:6c:17:ff:9a:63:f8:1c:2b:
+                    95:a7:5a:cf:e2:d7:e3:8a:a0:d8:b0:ab:d1:96:4d:
+                    d6:2c:90:fa:85:04:0f:a5:a4:39:39:12:22:a0:10:
+                    0f:bf:c0:75:5f:36:70:89:e3:c3:02:09:e8:31:3e:
+                    61:e4:08:98:61:18:d2:82:ef:10:1f:27:7d:ae:c8:
+                    77:12:fb:b3:cd:70:7d:66:d7:a6:28:4c:c6:52:a4:
+                    92:b1:de:91:5b:b0:f1:28:33:7a:6a:29:8a:02:ff:
+                    d7:01:5d:a8:e8:60:de:72:bd:51:af:03:e8:39:ae:
+                    a7:dc:17:e3:c8:a5:a4:aa:2a:6e:54:19:aa:1a:14:
+                    b6:cd:28:9d:3e:0a:a9:46:76:0e:32:ee:d7:6a:2d:
+                    31:75:33:bc:b7:c0:67:b9:83:e0:f1:d6:de:34:51:
+                    14:ba:56:6e:b9:b9:fc:ee:a7:7b:a6:cf:a9:52:0a:
+                    3f:63:96:b1:6e:42:55:56:7d:c9:7c:49:fc:09:af:
+                    84:62:0d:22:b7:e9:b4:38:a4:7e:5b:81:63:36:e2:
+                    b5:bb:86:7a:97:62:2c:fc:1c:64:9c:3e:4c:b9:9f:
+                    84:ea:99:db:ee:ed:ef:38:ef:29:1f:1c:54:c1:a1:
+                    49:90:ba:64:2a:b6:ad:aa:05:ea:fe:f6:ff:60:b4:
+                    66:fa:8a:27:4d:ba:9b:57:25:0d:a3:38:08:90:08:
+                    a4:a7:0a:87:2c:f4:6e:66:9b:ff:20:40:f9:c1:55:
+                    0d:8a:dc:69:35:d0:39:7b:14:21:dd:a8:00:6f:02:
+                    14:91:d4:36:61:d9:5b:b1:6f:8c:1e:ef:c4:bc:2b:
+                    e0:1c:d7:a7:6d:d0:2b:43:5f:d0:65:78:76:30:4a:
+                    22:f5:0d:41:fd:19:61:2f:c3:36:b3:0a:06:98:f7:
+                    89:5e:b7:c7:2f:bc:65:03:5a:c9
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                E4:58:4E:FF:D0:C7:CF:B7:09:40:B0:0E:5C:AF:E4:28:6D:EB:1D:95
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:vote.debian.org, DNS:www.vote.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         a2:d1:4e:8e:f0:cf:bf:91:2f:3e:cf:91:c0:34:e4:70:cb:34:
+         a5:5d:a9:af:75:6c:e4:5f:a2:98:b6:24:1d:78:2c:01:d9:ad:
+         43:b3:f4:ce:36:ad:1a:38:cc:07:55:44:f4:8d:a3:89:3a:4e:
+         a7:1f:9a:08:4d:66:cb:2d:b6:37:9b:24:42:f7:2d:72:88:00:
+         d9:72:65:84:e4:36:d5:3d:4f:5e:ea:07:a3:75:4a:c7:7d:ef:
+         e2:29:c9:e8:fd:26:39:22:80:8a:ba:3e:8d:21:7e:84:3f:58:
+         9a:69:90:e9:64:84:b0:23:fd:91:d6:84:d5:af:ad:3a:11:e1:
+         18:51:a1:f1:49:ac:43:bf:1d:f8:c8:b6:64:4d:36:bd:1a:14:
+         0a:93:6e:df:4e:81:40:54:12:3d:1f:19:f7:fe:ba:a8:98:c1:
+         6a:9a:ab:0b:3a:7d:86:99:8f:ae:87:c4:09:ad:3d:77:b0:70:
+         f2:83:b0:54:c9:95:a2:0e:62:ac:38:0a:df:0b:ea:ea:4e:50:
+         a0:6c:7c:0a:b3:cd:02:bd:84:b3:71:1b:c5:6a:c2:cd:63:70:
+         31:a6:e2:57:47:d5:4d:29:04:69:a1:a1:87:8a:23:c1:22:7e:
+         da:91:f6:bf:b4:b6:84:f9:73:b4:83:14:c2:89:3c:7c:82:43:
+         34:7e:9b:01
+-----BEGIN CERTIFICATE-----
+MIIFZTCCBE2gAwIBAgIQUAq5hLkbT36QzHSX73HlPDANBgkqhkiG9w0BAQUFADBB
+MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
+aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTQwMTAxMDAwMDAwWhcNMTUwMTAxMjM1OTU5
+WjBaMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
+EkdhbmRpIFN0YW5kYXJkIFNTTDEYMBYGA1UEAxMPdm90ZS5kZWJpYW4ub3JnMIIB
+ojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAxBMuGEiqWzolIKQSn7w7CwjF
+XY7fxbT1uZ6iSFp7Rxgm2RpHbBf/mmP4HCuVp1rP4tfjiqDYsKvRlk3WLJD6hQQP
+paQ5ORIioBAPv8B1XzZwiePDAgnoMT5h5AiYYRjSgu8QHyd9rsh3EvuzzXB9Ztem
+KEzGUqSSsd6RW7DxKDN6aimKAv/XAV2o6GDecr1RrwPoOa6n3BfjyKWkqipuVBmq
+GhS2zSidPgqpRnYOMu7Xai0xdTO8t8BnuYPg8dbeNFEUulZuubn87qd7ps+pUgo/
+Y5axbkJVVn3JfEn8Ca+EYg0it+m0OKR+W4FjNuK1u4Z6l2Is/BxknD5MuZ+E6pnb
+7u3vOO8pHxxUwaFJkLpkKratqgXq/vb/YLRm+oonTbqbVyUNozgIkAikpwqHLPRu
+Zpv/IED5wVUNitxpNdA5exQh3agAbwIUkdQ2YdlbsW+MHu/EvCvgHNenbdArQ1/Q
+ZXh2MEoi9Q1B/RlhL8M2swoGmPeJXrfHL7xlA1rJAgMBAAGjggG+MIIBujAfBgNV
+HSMEGDAWgBS2qP+iqC/Qps1LsWjz51AQMad5ITAdBgNVHQ4EFgQU5FhO/9DHz7cJ
+QLAOXK/kKG3rHZUwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0l
+BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGAGA1UdIARZMFcwSwYLKwYBBAGyMQEC
+AhowPDA6BggrBgEFBQcCARYuaHR0cDovL3d3dy5nYW5kaS5uZXQvY29udHJhY3Rz
+L2ZyL3NzbC9jcHMvcGRmLzAIBgZngQwBAgEwPAYDVR0fBDUwMzAxoC+gLYYraHR0
+cDovL2NybC5nYW5kaS5uZXQvR2FuZGlTdGFuZGFyZFNTTENBLmNybDBqBggrBgEF
+BQcBAQReMFwwNwYIKwYBBQUHMAKGK2h0dHA6Ly9jcnQuZ2FuZGkubmV0L0dhbmRp
+U3RhbmRhcmRTU0xDQS5jcnQwIQYIKwYBBQUHMAGGFWh0dHA6Ly9vY3NwLmdhbmRp
+Lm5ldDAvBgNVHREEKDAmgg92b3RlLmRlYmlhbi5vcmeCE3d3dy52b3RlLmRlYmlh
+bi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAKLRTo7wz7+RLz7PkcA05HDLNKVdqa91
+bORfopi2JB14LAHZrUOz9M42rRo4zAdVRPSNo4k6TqcfmghNZssttjebJEL3LXKI
+ANlyZYTkNtU9T17qB6N1Ssd97+Ipyej9JjkigIq6Po0hfoQ/WJppkOlkhLAj/ZHW
+hNWvrToR4RhRofFJrEO/HfjItmRNNr0aFAqTbt9OgUBUEj0fGff+uqiYwWqaqws6
+fYaZj66HxAmtPXewcPKDsFTJlaIOYqw4Ct8L6upOUKBsfAqzzQK9hLNxG8Vqws1j
+cDGm4ldH1U0pBGmhoYeKI8EiftqR9r+0toT5c7SDFMKJPHyCQzR+mwE=
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/wiki.debian.org-new.crt b/modules/ssl/files/servicecerts/wiki.debian.org-new.crt
new file mode 100644 (file)
index 0000000..80fec76
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            e9:bd:1c:0b:a3:e1:c2:85:86:13:09:57:43:2b:4d:ae
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Jul 29 00:00:00 2013 GMT
+            Not After : Jul 29 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=wiki.debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:d1:0d:ee:73:7a:54:33:34:d6:fe:41:c8:e6:0a:
+                    57:08:3b:a6:41:0a:47:05:21:b4:80:a6:f7:e6:8e:
+                    02:dd:d9:27:e5:65:30:2f:6e:bc:42:b5:2f:97:a5:
+                    d1:17:a2:43:bb:fe:00:61:85:cc:52:d1:12:56:97:
+                    ac:33:61:2b:8b:35:51:6e:da:90:e0:8e:c6:6f:63:
+                    bc:be:ee:c7:a2:eb:e2:2b:0e:fe:bb:6a:00:7e:4d:
+                    69:e7:a3:1f:5a:f2:4d:49:c6:28:3e:ec:f7:36:3a:
+                    65:78:21:0c:65:c3:f0:28:1f:e1:96:f1:0b:72:62:
+                    02:e9:95:53:13:50:eb:5b:4b:91:ae:9d:0f:79:74:
+                    cb:ce:a2:a6:5e:f8:7c:1e:72:79:94:13:f1:c0:1e:
+                    52:d3:1b:07:66:6b:72:e9:57:f6:b0:2f:12:4f:06:
+                    af:12:7c:b6:0b:b6:87:a9:03:2c:7d:d6:ff:6c:a4:
+                    df:e3:9c:ab:7b:cc:2b:8e:b9:ef:2c:13:c9:b4:34:
+                    a7:59:5d:70:0a:40:2b:d8:6a:53:99:80:80:43:d4:
+                    01:36:f7:22:2d:6c:9e:f8:34:b3:30:fa:c3:eb:5a:
+                    f0:dd:6e:68:3a:94:ac:1e:9c:46:0d:60:dd:5f:36:
+                    2f:7c:1b:00:df:de:26:95:57:91:52:3f:47:84:d5:
+                    4d:c1:3c:92:f7:13:9e:69:3e:c9:52:ab:1e:f5:12:
+                    0e:bf:b5:3f:f3:3f:5e:9b:74:14:c4:0e:31:6c:46:
+                    e5:66:b0:03:c3:7a:e3:79:6e:8f:e7:b0:fb:7e:a2:
+                    a0:b0:8a:3a:17:c4:62:ff:57:4a:d6:80:53:02:99:
+                    da:7d:36:29:b1:43:0c:cb:3d:78:e0:e7:c6:0c:81:
+                    5a:c8:1d:48:2a:f6:ce:c1:4c:8f:ad:6b:97:5a:32:
+                    d2:f8:68:3a:17:fa:6e:1e:8f:f4:5c:fa:35:32:15:
+                    da:8f:5a:d0:88:cc:07:ef:ab:0e:c0:96:36:b9:68:
+                    b8:6a:f5:a1:5a:5c:62:95:ab:59
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                FA:AE:C6:F4:6E:42:7E:7C:95:04:0D:3A:AF:C6:55:3A:3F:B5:5B:19
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:wiki.debian.org, DNS:www.wiki.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         50:26:93:4a:31:b3:42:17:ec:9e:06:27:e1:25:ce:82:e2:2a:
+         e7:35:a1:fe:26:24:6d:84:77:2c:24:7c:6e:d2:a7:4f:ac:bd:
+         fd:81:5d:10:b9:92:d1:e3:b9:26:0e:72:46:9a:70:6b:2f:c3:
+         e9:7a:5c:cc:d0:9a:e5:8d:3b:b4:8e:64:47:ba:d1:24:59:55:
+         7e:5b:9b:22:92:8d:9c:9e:cb:4d:1e:48:a8:14:db:94:97:bf:
+         8c:05:17:37:39:ad:77:47:58:5f:95:d1:62:f4:47:4c:94:0b:
+         34:39:b9:ac:e0:19:82:10:2b:6f:40:05:a2:83:e9:6c:bc:7d:
+         e7:15:d0:4d:8f:f0:ea:56:47:50:15:40:4a:d8:88:4c:3e:43:
+         88:08:6e:9f:6a:58:e6:bf:7d:62:f6:d9:ee:43:75:20:80:65:
+         c8:2f:0b:62:68:42:80:46:66:8a:1f:be:be:7e:e3:7a:a7:ee:
+         80:d6:1d:a3:ac:01:70:43:b8:72:4d:5f:24:39:3e:21:db:dd:
+         73:e8:0b:0f:77:33:85:79:1b:f4:83:63:e9:f6:d4:26:45:84:
+         c3:ef:c5:15:9c:ff:0f:fc:29:cd:14:a7:82:8a:ca:e5:c3:7b:
+         d8:86:09:cf:20:32:ee:ba:9a:75:d1:97:8f:35:3f:a3:70:00:
+         b4:be:f8:76
+-----BEGIN CERTIFICATE-----
+MIIFZjCCBE6gAwIBAgIRAOm9HAuj4cKFhhMJV0MrTa4wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMDcyOTAwMDAwMFoXDTE0MDcyOTIzNTk1
+OVowWjEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxGDAWBgNVBAMTD3dpa2kuZGViaWFuLm9yZzCC
+AaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBANEN7nN6VDM01v5ByOYKVwg7
+pkEKRwUhtICm9+aOAt3ZJ+VlMC9uvEK1L5el0ReiQ7v+AGGFzFLRElaXrDNhK4s1
+UW7akOCOxm9jvL7ux6Lr4isO/rtqAH5NaeejH1ryTUnGKD7s9zY6ZXghDGXD8Cgf
+4ZbxC3JiAumVUxNQ61tLka6dD3l0y86ipl74fB5yeZQT8cAeUtMbB2ZrculX9rAv
+Ek8GrxJ8tgu2h6kDLH3W/2yk3+Ocq3vMK4657ywTybQ0p1ldcApAK9hqU5mAgEPU
+ATb3Ii1snvg0szD6w+ta8N1uaDqUrB6cRg1g3V82L3wbAN/eJpVXkVI/R4TVTcE8
+kvcTnmk+yVKrHvUSDr+1P/M/Xpt0FMQOMWxG5WawA8N643luj+ew+36ioLCKOhfE
+Yv9XStaAUwKZ2n02KbFDDMs9eODnxgyBWsgdSCr2zsFMj61rl1oy0vhoOhf6bh6P
+9Fz6NTIV2o9a0IjMB++rDsCWNrlouGr1oVpcYpWrWQIDAQABo4IBvjCCAbowHwYD
+VR0jBBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFPquxvRuQn58
+lQQNOq/GVTo/tVsZMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1Ud
+JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQBsjEB
+AgIaMDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRyYWN0
+cy9mci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2GK2h0
+dHA6Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYIKwYB
+BQUHAQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9HYW5k
+aVN0YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5nYW5k
+aS5uZXQwLwYDVR0RBCgwJoIPd2lraS5kZWJpYW4ub3JnghN3d3cud2lraS5kZWJp
+YW4ub3JnMA0GCSqGSIb3DQEBBQUAA4IBAQBQJpNKMbNCF+yeBifhJc6C4irnNaH+
+JiRthHcsJHxu0qdPrL39gV0QuZLR47kmDnJGmnBrL8PpelzM0JrljTu0jmRHutEk
+WVV+W5siko2cnstNHkioFNuUl7+MBRc3Oa13R1hfldFi9EdMlAs0Obms4BmCECtv
+QAWig+lsvH3nFdBNj/DqVkdQFUBK2IhMPkOICG6faljmv31i9tnuQ3UggGXILwti
+aEKARmaKH76+fuN6p+6A1h2jrAFwQ7hyTV8kOT4h291z6AsPdzOFeRv0g2Pp9tQm
+RYTD78UVnP8P/CnNFKeCisrlw3vYhgnPIDLuupp10ZePNT+jcAC0vvh2
+-----END CERTIFICATE-----
diff --git a/modules/ssl/files/servicecerts/www.debian.org-new.crt b/modules/ssl/files/servicecerts/www.debian.org-new.crt
new file mode 100644 (file)
index 0000000..2603bad
--- /dev/null
@@ -0,0 +1,117 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            de:28:c6:a7:02:8c:11:d6:b7:50:d8:19:80:87:1d:ed
+    Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+        Validity
+            Not Before: Dec 31 00:00:00 2013 GMT
+            Not After : Dec 31 23:59:59 2014 GMT
+        Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=debian.org
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (3072 bit)
+                Modulus:
+                    00:e6:64:e5:b7:99:14:a1:9d:07:2f:e9:1a:0e:da:
+                    28:6e:13:8d:83:c2:87:e2:90:1b:bd:1f:12:4c:ca:
+                    1c:b6:3d:08:0d:c5:81:6f:8d:e2:01:76:74:7d:2d:
+                    04:6e:41:bf:f5:c5:8e:40:cf:c8:ed:46:b0:c8:ff:
+                    56:8b:53:b2:50:cf:5b:07:0f:5a:4e:b4:89:cf:d5:
+                    9e:de:db:a1:c9:b7:48:ff:1b:82:69:ef:97:64:93:
+                    ab:9c:a0:57:03:4b:c7:e1:00:ca:db:5b:87:de:43:
+                    7f:eb:b8:46:8f:52:87:23:10:17:6f:f0:2e:bc:5c:
+                    3e:e6:7d:82:24:c7:1d:c0:d4:35:b6:bb:3b:74:6c:
+                    de:f5:8d:07:a8:67:35:37:f3:a3:86:56:3c:bf:04:
+                    ce:f9:09:28:04:4a:9d:a8:08:b1:77:81:7a:51:91:
+                    90:24:7e:2f:2b:6b:11:b5:cf:c6:c7:a3:57:95:01:
+                    00:25:4d:35:5a:c8:09:8a:67:c5:3d:0f:db:bd:06:
+                    65:78:7a:45:ff:cb:b0:ac:15:d0:d4:b7:a0:5e:45:
+                    09:da:71:39:4e:6c:a3:e7:1b:f7:55:1b:62:27:91:
+                    31:30:02:3f:d1:9c:b5:53:86:c0:dd:1d:05:28:72:
+                    c7:cc:be:d2:09:17:76:2b:85:35:18:f3:09:db:67:
+                    9e:55:07:21:35:6a:f2:96:30:d2:8a:8f:6a:e4:78:
+                    6a:c4:fe:4e:9d:03:c6:16:49:a5:e4:2c:22:15:54:
+                    c0:4e:23:82:fe:36:96:88:7e:01:50:cb:bd:4f:e2:
+                    50:1b:c5:fc:93:32:62:25:40:78:3f:ab:66:97:e8:
+                    d7:51:96:87:23:fa:b6:20:fc:0a:ea:6b:8b:75:c7:
+                    5a:0c:67:4b:32:e1:a7:74:af:ff:1d:a6:7f:7e:ae:
+                    23:02:66:6c:8c:f0:7f:55:03:30:43:e8:85:cd:9f:
+                    d0:00:9e:a5:4a:1c:7f:1f:52:06:2e:05:bc:0c:d3:
+                    51:6a:0b:fb:5a:a6:a4:5d:c7:31
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Authority Key Identifier: 
+                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+
+            X509v3 Subject Key Identifier: 
+                FE:E1:00:FF:AA:4F:A0:36:54:84:72:5D:42:0C:F4:E7:6F:BE:9F:D5
+            X509v3 Key Usage: critical
+                Digital Signature, Key Encipherment
+            X509v3 Basic Constraints: critical
+                CA:FALSE
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.6449.1.2.2.26
+                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                Policy: 2.23.140.1.2.1
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+
+            Authority Information Access: 
+                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
+                OCSP - URI:http://ocsp.gandi.net
+
+            X509v3 Subject Alternative Name: 
+                DNS:debian.org, DNS:www.debian.org
+    Signature Algorithm: sha1WithRSAEncryption
+         24:ee:37:b4:a9:ca:a2:e2:05:3f:c3:fe:df:14:3f:ef:c2:6e:
+         96:93:2f:bd:2e:6c:44:ee:18:bc:82:06:3d:de:4d:de:30:5c:
+         be:ca:36:5a:55:3a:e4:30:ac:30:5b:ad:bd:c4:33:f8:12:51:
+         49:06:39:99:df:67:aa:f5:c3:75:28:d2:09:51:fd:12:fb:6d:
+         2e:71:04:94:ed:3e:7e:73:54:af:43:fa:3f:d2:53:d9:b5:26:
+         06:43:ea:47:5c:07:f4:31:5b:7f:26:4d:f3:1f:b3:49:9c:4c:
+         c5:35:63:f2:80:79:31:b9:3e:6d:d9:a9:4c:fe:62:2a:16:cf:
+         3f:f3:5f:23:71:f9:7c:a7:6a:da:18:9a:3c:15:32:f7:61:a4:
+         ba:39:2a:8a:7b:ad:81:4d:8a:44:4d:55:68:91:bc:d6:8f:d5:
+         90:5c:e7:ce:33:8e:24:f8:ee:2a:c8:ee:e3:90:c6:3d:54:3a:
+         40:b1:4c:a3:63:52:2b:11:6e:1f:88:f1:a4:6b:00:7f:42:26:
+         ce:eb:41:9e:8d:32:04:cc:c2:7a:c2:2d:68:7c:65:c9:94:98:
+         4b:19:1f:c5:cb:6e:56:3c:c6:bf:ec:9c:b4:88:06:41:f2:7d:
+         6d:ae:05:02:24:f5:54:3f:37:d6:83:9e:eb:ee:3a:4c:0b:76:
+         84:18:1b:44
+-----BEGIN CERTIFICATE-----
+MIIFVzCCBD+gAwIBAgIRAN4oxqcCjBHWt1DYGYCHHe0wDQYJKoZIhvcNAQEFBQAw
+QTELMAkGA1UEBhMCRlIxEjAQBgNVBAoTCUdBTkRJIFNBUzEeMBwGA1UEAxMVR2Fu
+ZGkgU3RhbmRhcmQgU1NMIENBMB4XDTEzMTIzMTAwMDAwMFoXDTE0MTIzMTIzNTk1
+OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRswGQYDVQQL
+ExJHYW5kaSBTdGFuZGFyZCBTU0wxEzARBgNVBAMTCmRlYmlhbi5vcmcwggGiMA0G
+CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDmZOW3mRShnQcv6RoO2ihuE42Dwofi
+kBu9HxJMyhy2PQgNxYFvjeIBdnR9LQRuQb/1xY5Az8jtRrDI/1aLU7JQz1sHD1pO
+tInP1Z7e26HJt0j/G4Jp75dkk6ucoFcDS8fhAMrbW4feQ3/ruEaPUocjEBdv8C68
+XD7mfYIkxx3A1DW2uzt0bN71jQeoZzU386OGVjy/BM75CSgESp2oCLF3gXpRkZAk
+fi8raxG1z8bHo1eVAQAlTTVayAmKZ8U9D9u9BmV4ekX/y7CsFdDUt6BeRQnacTlO
+bKPnG/dVG2InkTEwAj/RnLVThsDdHQUocsfMvtIJF3YrhTUY8wnbZ55VByE1avKW
+MNKKj2rkeGrE/k6dA8YWSaXkLCIVVMBOI4L+NpaIfgFQy71P4lAbxfyTMmIlQHg/
+q2aX6NdRlocj+rYg/Arqa4t1x1oMZ0sy4ad0r/8dpn9+riMCZmyM8H9VAzBD6IXN
+n9AAnqVKHH8fUgYuBbwM01FqC/tapqRdxzECAwEAAaOCAbQwggGwMB8GA1UdIwQY
+MBaAFLao/6KoL9CmzUuxaPPnUBAxp3khMB0GA1UdDgQWBBT+4QD/qk+gNlSEcl1C
+DPTnb76f1TAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUEFjAU
+BggrBgEFBQcDAQYIKwYBBQUHAwIwYAYDVR0gBFkwVzBLBgsrBgEEAbIxAQICGjA8
+MDoGCCsGAQUFBwIBFi5odHRwOi8vd3d3LmdhbmRpLm5ldC9jb250cmFjdHMvZnIv
+c3NsL2Nwcy9wZGYvMAgGBmeBDAECATA8BgNVHR8ENTAzMDGgL6AthitodHRwOi8v
+Y3JsLmdhbmRpLm5ldC9HYW5kaVN0YW5kYXJkU1NMQ0EuY3JsMGoGCCsGAQUFBwEB
+BF4wXDA3BggrBgEFBQcwAoYraHR0cDovL2NydC5nYW5kaS5uZXQvR2FuZGlTdGFu
+ZGFyZFNTTENBLmNydDAhBggrBgEFBQcwAYYVaHR0cDovL29jc3AuZ2FuZGkubmV0
+MCUGA1UdEQQeMByCCmRlYmlhbi5vcmeCDnd3dy5kZWJpYW4ub3JnMA0GCSqGSIb3
+DQEBBQUAA4IBAQAk7je0qcqi4gU/w/7fFD/vwm6Wky+9LmxE7hi8ggY93k3eMFy+
+yjZaVTrkMKwwW629xDP4ElFJBjmZ32eq9cN1KNIJUf0S+20ucQSU7T5+c1SvQ/o/
+0lPZtSYGQ+pHXAf0MVt/Jk3zH7NJnEzFNWPygHkxuT5t2alM/mIqFs8/818jcfl8
+p2raGJo8FTL3YaS6OSqKe62BTYpETVVokbzWj9WQXOfOM44k+O4qyO7jkMY9VDpA
+sUyjY1IrEW4fiPGkawB/QibO60GejTIEzMJ6wi1ofGXJlJhLGR/Fy25WPMa/7Jy0
+iAZB8n1trgUCJPVUPzfWg57r7jpMC3aEGBtE
+-----END CERTIFICATE-----