diff --git a/ca-certificates.spec b/ca-certificates.spec index 468f4a03b04e1d71d971a224f80e96d6e368a8b0..e8ec263443a24dd39e1ff5afff9b961776a9e790 100644 --- a/ca-certificates.spec +++ b/ca-certificates.spec @@ -38,7 +38,7 @@ Name: ca-certificates Version: 2023.2.64 # for Rawhide, please always use release >= 2 # for Fedora release branches, please use release < 2 (1.0, 1.1, ...) -Release: 2 +Release: 3 License: Public Domain Group: System Environment/Base @@ -72,10 +72,10 @@ Requires(post): coreutils Requires: bash Requires: grep Requires: sed -Requires(post): p11-kit >= 0.23.10 -Requires(post): p11-kit-trust >= 0.23.10 -Requires: p11-kit >= 0.23.10 -Requires: p11-kit-trust >= 0.23.10 +Requires(post): p11-kit >= 0.24 +Requires(post): p11-kit-trust >= 0.24 +Requires: p11-kit >= 0.24 +Requires: p11-kit-trust >= 0.24 BuildRequires: perl-interpreter BuildRequires: python3 @@ -185,7 +185,7 @@ mkdir -p -m 755 $RPM_BUILD_ROOT%{pkidir}/java mkdir -p -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/ssl mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/source mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/source/anchors -mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/source/blacklist +mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/source/blocklist mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/extracted mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/extracted/pem mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/extracted/openssl @@ -193,7 +193,7 @@ mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/extracted/java mkdir -p -m 755 $RPM_BUILD_ROOT%{catrustdir}/extracted/edk2 mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/pki/ca-trust-source mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/pki/ca-trust-source/anchors -mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/pki/ca-trust-source/blacklist +mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/pki/ca-trust-source/blocklist mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/pki/ca-trust-legacy mkdir -p -m 755 $RPM_BUILD_ROOT%{_bindir} mkdir -p -m 755 $RPM_BUILD_ROOT%{_mandir}/man8 @@ -328,7 +328,7 @@ fi %dir %{catrustdir} %dir %{catrustdir}/source %dir %{catrustdir}/source/anchors -%dir %{catrustdir}/source/blacklist +%dir %{catrustdir}/source/blocklist %dir %{catrustdir}/extracted %dir %{catrustdir}/extracted/pem %dir %{catrustdir}/extracted/openssl @@ -336,7 +336,7 @@ fi %dir %{_datadir}/pki %dir %{_datadir}/pki/ca-trust-source %dir %{_datadir}/pki/ca-trust-source/anchors -%dir %{_datadir}/pki/ca-trust-source/blacklist +%dir %{_datadir}/pki/ca-trust-source/blocklist %dir %{_datadir}/pki/ca-trust-legacy %config(noreplace) %{catrustdir}/ca-legacy.conf @@ -379,6 +379,9 @@ fi %changelog +* Thu Jun 05 2025 wangjiang - 2023.2.64-3 +- remove blacklist directory now that p11-kit is using blocklist + * Mon Jul 01 2024 wangjiang - 2023.2.64-2 - remove expired and sync new certificates Removing: diff --git a/update-ca-trust.8.txt b/update-ca-trust.8.txt index 93143da511d8c0112bc5c3a1559cd88319588cd8..5886cb5144b72692d594eca151c5645e7c642661 100644 --- a/update-ca-trust.8.txt +++ b/update-ca-trust.8.txt @@ -98,13 +98,13 @@ subdirectory in the /etc hierarchy. * add it as a new file to directory /etc/pki/ca-trust/source/anchors/ * run 'update-ca-trust extract' -.*QUICK HELP 2*: If your certificate is in the extended BEGIN TRUSTED file format (which may contain distrust/blacklist trust flags, or trust flags for usages other than TLS) then: +.*QUICK HELP 2*: If your certificate is in the extended BEGIN TRUSTED file format (which may contain distrust/blocklist trust flags, or trust flags for usages other than TLS) then: * add it as a new file to directory /etc/pki/ca-trust/source/ * run 'update-ca-trust extract' .In order to offer simplicity and flexibility, the way certificate files are treated depends on the subdirectory they are installed to. * simple trust anchors subdirectory: /usr/share/pki/ca-trust-source/anchors/ or /etc/pki/ca-trust/source/anchors/ -* simple blacklist (distrust) subdirectory: /usr/share/pki/ca-trust-source/blacklist/ or /etc/pki/ca-trust/source/blacklist/ +* simple blocklist (distrust) subdirectory: /usr/share/pki/ca-trust-source/blocklist/ or /etc/pki/ca-trust/source/blocklist/ * extended format directory: /usr/share/pki/ca-trust-source/ or /etc/pki/ca-trust/source/ .In the main directories /usr/share/pki/ca-trust-source/ or /etc/pki/ca-trust/source/ you may install one or multiple files in the following file formats: @@ -134,7 +134,7 @@ you may install one or multiple certificates in either the DER file format or in the PEM (BEGIN/END CERTIFICATE) file format. Each certificate will be treated as *trusted* for all purposes. -In the blacklist subdirectories /usr/share/pki/ca-trust-source/blacklist/ or /etc/pki/ca-trust/source/blacklist/ +In the blocklist subdirectories /usr/share/pki/ca-trust-source/blocklist/ or /etc/pki/ca-trust/source/blocklist/ you may install one or multiple certificates in either the DER file format or in the PEM (BEGIN/END CERTIFICATE) file format. Each certificate will be treated as *distrusted* for all purposes.