HomeFreeBSD

caroot: update the root bundle and regenerate with OpenSSL 3

Description

caroot: update the root bundle and regenerate with OpenSSL 3

Summary:

  • Six (6) new roots
  • Four (4) distrusted roots

Note that this was intentionally generated with OpenSSL 1.1.1 to avoid
mixing updates and non-functional changes -- there will be some churn
with OpenSSL 3. The next commit will update the current batch of
trusted certs with the format OpenSSL 3 produces, which I've tested
against OpenSSL 1.1.1 to be sure that that doesn't hurt us in older
branches.

This MFC also regenerates all of the trusted certs with OpenSSL 3 to
reduce the diff of future ENs -- this update has no existing certs
modified, so it's the perfect time.

(cherry picked from commit 65fd80909e196c8be2ce5e948775e9cbda2ef069)
(cherry picked from commit 8ed0ecf8024d10e9cd21f5880723a6cec4fd4ae6)

Details

Provenance
kevansAuthored on Aug 26 2023, 1:01 AM
Parents
rG3ff148ad9274: caroot: drop the VERSION tag from already-processed certs
Branches
Unknown
Tags
Unknown