Skip to content

Preparing for DST Root CA X3 expiration (September 2021) #3471

@KexyBiscuit

Description

@KexyBiscuit

Tasks

  • Update ca-certs package.
    • Blacklist DST Root CA X3 so any self built old copies of OpenSSL or GnuTLS should work after September 30, 2021.
  • Drop openssl+1.0 since it's no longer used by any package.

Regression

Connectivity to "DST Root CA X3" websites only, even under faketime set to dates prior to 30th of September 2021 will not work, as "DST Root CA X3" certificate is no longer installed. users should locally install and enable that CA certificate, or allow dangerous unverified connectivity to websites using expired CA certs.

See also

Metadata

Metadata

Assignees

Labels

securityTopic/issue involves a security issue/fixedupgradeTopic/issue involves a package upgrade

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions