@@ -63,146 +63,132 @@ Use the following environment variable to configure non default .pem files or ov
6363## List of Default Trusted Certificate Authorities
6464If not mentioned explicitly, issuing CAs listed will sign X.509 certificates with [ Extended Key Usage] ( https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.12 ) entries ` TLS WWW server authentication ` and ` TLS WWW client authentication ` .
6565
66- ### CAs Trusted by Common Web Browsers and Operating Systems
67-
6866* Root CA: ** HARICA TLS ECC Root CA 2021**
6967 Info: https://crt.sh/?caid=202185
7068 X509 Certificate: https://crt.sh/?id=4147045948
7169 Not after: Feb 13 11:01:09 2045 GMT
72- * Issuing CA: ** GEANT TLS ECC 1**
73- Info: https://crt.sh/?caid=390050
74- X509 Certificate: https://crt.sh/?id=16099180990
75- Not after: Dec 31 11:14:20 2039 GMT
76- * Issuing CA: ** HARICA OV TLS ECC**
77- Info: https://crt.sh/?caid=207661
78- X509 Certificate: https://crt.sh/?id=4442848530
79- Not after: Mar 15 09:33:51 2036 GMT
70+ * Issuing CA: ** GEANT TLS ECC 1**
71+ Info: https://crt.sh/?caid=390050
72+ X509 Certificate: https://crt.sh/?id=16099180990
73+ Not after: Dec 31 11:14:20 2039 GMT
74+ * Issuing CA: ** HARICA OV TLS ECC**
75+ Info: https://crt.sh/?caid=207661
76+ X509 Certificate: https://crt.sh/?id=4442848530
77+ Not after: Mar 15 09:33:51 2036 GMT
8078* Root CA: ** HARICA TLS RSA Root CA 2021**
8179 Info: https://crt.sh/?caid=202184
8280 X509 Certificate: https://crt.sh/?id=4147041876
8381 Not after: Feb 13 10:55:37 2045 GMT
84- * Issuing CA: ** GEANT TLS RSA 1**
85- Info: https://crt.sh/?caid=390054
86- X509 Certificate: https://crt.sh/?id=16099180997
87- Not after: Dec 31 11:14:59 2039 GMT
88- * Issuing CA: ** HARICA OV TLS RSA**
89- Info: https://crt.sh/?caid=207660
90- X509 Certificate: https://crt.sh/?id=4442848529
91- Not after: Mar 15 09:34:16 2036 GMT
82+ * Issuing CA: ** GEANT TLS RSA 1**
83+ Info: https://crt.sh/?caid=390054
84+ X509 Certificate: https://crt.sh/?id=16099180997
85+ Not after: Dec 31 11:14:59 2039 GMT
86+ * Issuing CA: ** HARICA OV TLS RSA**
87+ Info: https://crt.sh/?caid=207660
88+ X509 Certificate: https://crt.sh/?id=4442848529
89+ Not after: Mar 15 09:34:16 2036 GMT
9290* Root CA: ** HARICA Client ECC Root CA 2021**
9391 Info: https://crt.sh/?caid=202189
9492 X509 Certificate: https://crt.sh/?id=4147052292
9593 Not after: Feb 13 11:03:33 2045 GMT
96- * Issuing CA: ** GEANT S/MIME ECC 1** [ client/smime certificates only]
97- Info: https://crt.sh/?caid=390048
98- X509 Certificate: https://crt.sh/?id=16099180988
99- Not after: Dec 31 11:11:39 2039 GMT
100- * Issuing CA: ** HARICA S/MIME ECC** [ client/smime certificates only]
101- Info: https://crt.sh/?caid=207659
102- X509 Certificate: https://crt.sh/?id=4442848523
103- Not after: Mar 15 09:36:57 2036 GMT
94+ * Issuing CA: ** GEANT S/MIME ECC 1** [ client/smime certificates only]
95+ Info: https://crt.sh/?caid=390048
96+ X509 Certificate: https://crt.sh/?id=16099180988
97+ Not after: Dec 31 11:11:39 2039 GMT
98+ * Issuing CA: ** HARICA S/MIME ECC** [ client/smime certificates only]
99+ Info: https://crt.sh/?caid=207659
100+ X509 Certificate: https://crt.sh/?id=4442848523
101+ Not after: Mar 15 09:36:57 2036 GMT
102+ * Issuing CA: ** HARICA Client Authentication ECC** [ client certificates only]
103+ Info: https://crt.sh/?caid=207671
104+ X509 Certificate: https://crt.sh/?id=4442848518
105+ Not after: Mar 15 09:17:38 2036 GMT
104106* Root CA: ** HARICA Client RSA Root CA 2021**
105107 Info: https://crt.sh/?caid=202188
106108 X509 Certificate: https://crt.sh/?id=4147049674
107109 Not after: Feb 13 10:58:45 2045 GMT
108- * Issuing CA: ** GEANT S/MIME RSA 1** [ client/smime certificates only]
109- Info: https://crt.sh/?caid=390049
110- X509 Certificate: https://crt.sh/?id=16099180989
111- Not after: Dec 31 11:13:07 2039 GMT
112- * Issuing CA: ** HARICA S/MIME RSA** [ client/smime certificates only]
113- Info: https://crt.sh/?caid=207658
114- X509 Certificate: https://crt.sh/?id=4442848517
115- Not after: Mar 15 09:37:37 2036 GMT
110+ * Issuing CA: ** GEANT S/MIME RSA 1** [ client/smime certificates only]
111+ Info: https://crt.sh/?caid=390049
112+ X509 Certificate: https://crt.sh/?id=16099180989
113+ Not after: Dec 31 11:13:07 2039 GMT
114+ * Issuing CA: ** HARICA S/MIME RSA** [ client/smime certificates only]
115+ Info: https://crt.sh/?caid=207658
116+ X509 Certificate: https://crt.sh/?id=4442848517
117+ Not after: Mar 15 09:37:37 2036 GMT
118+ * Issuing CA: ** HARICA Client Authentication RSA** [ client certificates only]
119+ Info: https://crt.sh/?caid=207670
120+ X509 Certificate: https://crt.sh/?id=4442848531
121+ Not after: Mar 15 09:19:36 2036 GMT
116122* Root CA: ** T-TeleSec GlobalRoot Class 2** [ will be removed in a future release, incl. derived CAs]
117123 Info: https://crt.sh/?caid=6068
118124 X509 Certificate: https://crt.sh/?id=8733622
119125 Not after: Oct 1 23:59:59 2033 GMT
120- * Intermediate Root CA: ** DFN-Verein Certification Authority 2**
121- Info: https://crt.sh/?caid=22818
122- X509 Certificate: https://crt.sh/?id=23908438
123- Not after: Feb 22 23:59:59 2031 GMT
124- * Issuing CA: ** DFN-Verein Global Issuing CA** [ existing, still valid client certificates, no new certificates]
125- Info: https://crt.sh/?caid=23770
126- X509 Certificate: https://crt.sh/?id=25484751
127- Not after: Feb 22 23:59:59 2031 GMT
128- * Issuing CA: ** Fraunhofer User CA - G02** [ existing, still valid client certificates, no new certificates]
129- Info: https://crt.sh/?caid=23772
130- X509 Certificate: https://crt.sh/?id=25484789
131- Not after: Feb 22 23:59:59 2031 GMT
126+ * Intermediate Root CA: ** DFN-Verein Certification Authority 2**
127+ Info: https://crt.sh/?caid=22818
128+ X509 Certificate: https://crt.sh/?id=23908438
129+ Not after: Feb 22 23:59:59 2031 GMT
130+ * Issuing CA: ** DFN-Verein Global Issuing CA** [ existing, still valid client certificates, no new certificates]
131+ Info: https://crt.sh/?caid=23770
132+ X509 Certificate: https://crt.sh/?id=25484751
133+ Not after: Feb 22 23:59:59 2031 GMT
134+ * Issuing CA: ** Fraunhofer User CA - G02** [ existing, still valid client certificates, no new certificates]
135+ Info: https://crt.sh/?caid=23772
136+ X509 Certificate: https://crt.sh/?id=25484789
137+ Not after: Feb 22 23:59:59 2031 GMT
132138* Root CA: ** D-TRUST Root Class 3 CA 2 2009**
133139 Info: https://crt.sh/?caid=712
134140 X509 Certificate: https://crt.sh/?id=133226
135141 Not after: Nov 5 08:35:58 2029 GMT
136- * Issuing CA: ** D-TRUST SSL Class 3 CA 1 2009** [ server certificates via TMF e.V.]
137- Info: https://crt.sh/?caid=713
138- X509 Certificate: https://crt.sh/?id=133227
139- Not after: Nov 5 08:35:58 2029 GMT
142+ * Issuing CA: ** D-TRUST SSL Class 3 CA 1 2009** [ server certificates via TMF e.V.]
143+ Info: https://crt.sh/?caid=713
144+ X509 Certificate: https://crt.sh/?id=133227
145+ Not after: Nov 5 08:35:58 2029 GMT
140146* Root CA: ** USERTrust ECC Certification Authority** [ will be removed in a future release, incl. derived CAs]
141147 Info: https://crt.sh/?caid=1390
142148 X509 Certificate: https://crt.sh/?id=2841410
143149 Not after: Jan 18 23:59:59 2038 GMT
144- * Issuing CA: ** Sectigo ECC Organization Validation Secure Server CA**
145- Info: https://crt.sh/?caid=105483
146- X509 Certificate: https://crt.sh/?id=924467859
147- Not after: Dec 31 23:59:59 2030 GMT
148- * Issuing CA: ** GEANT OV ECC CA 4**
149- Info: https://crt.sh/?caid=160140
150- X509 Certificate: https://crt.sh/?id=2475254970
151- * Issuing CA: ** GEANT Personal ECC CA 4** [ client/smime certificates only]
152- Info: https://crt.sh/?caid=160136
153- X509 Certificate: https://crt.sh/?id=2475254903
154- Not after: May 1 23:59:59 2033 GMT
155- * Issuing CA: ** GEANT eScience Personal ECC CA 4** [ client/smime certificates only]
156- Info: https://crt.sh/?caid=160138
157- X509 Certificate: https://crt.sh/?id=2475254888
158- Not after: May 1 23:59:59 2033 GMT
150+ * Issuing CA: ** Sectigo ECC Organization Validation Secure Server CA**
151+ Info: https://crt.sh/?caid=105483
152+ X509 Certificate: https://crt.sh/?id=924467859
153+ Not after: Dec 31 23:59:59 2030 GMT
154+ * Issuing CA: ** GEANT OV ECC CA 4**
155+ Info: https://crt.sh/?caid=160140
156+ X509 Certificate: https://crt.sh/?id=2475254970
157+ * Issuing CA: ** GEANT Personal ECC CA 4** [ client/smime certificates only]
158+ Info: https://crt.sh/?caid=160136
159+ X509 Certificate: https://crt.sh/?id=2475254903
160+ Not after: May 1 23:59:59 2033 GMT
161+ * Issuing CA: ** GEANT eScience Personal ECC CA 4** [ client/smime certificates only]
162+ Info: https://crt.sh/?caid=160138
163+ X509 Certificate: https://crt.sh/?id=2475254888
164+ Not after: May 1 23:59:59 2033 GMT
159165* Root CA: ** USERTrust RSA Certification Authority** [ will be removed in a future release, incl. derived CAs]
160166 Info: https://crt.sh/?caid=1167
161167 X509 Certificate: https://crt.sh/?id=1199354
162168 Not after: Jan 18 23:59:59 2038 GMT
163- * Issuing CA: ** Sectigo RSA Organization Validation Secure Server CA**
164- Info: https://crt.sh/?caid=105487
165- X509 Certificate: https://crt.sh/?id=924467857
166- Not after: Dec 31 23:59:59 2030 GMT
167- * Issuing CA: ** GEANT OV RSA CA 4**
168- Info: https://crt.sh/?caid=160137
169- X509 Certificate: https://crt.sh/?id=2475254782
170- Not after: May 1 23:59:59 2033 GMT
171- * Issuing CA: ** GEANT Personal CA 4** [ client/smime certificates only]
172- Info: https://crt.sh/?caid=160144
173- X509 Certificate: https://crt.sh/?id=2475255043
174- Not after: May 1 23:59:59 2033 GMT
175- * Issuing CA: ** GEANT eScience Personal CA 4** [ client/smime certificates only]
176- Info: https://crt.sh/?caid=160134
177- X509 Certificate: https://crt.sh/?id=2475253350
178- Not after: May 1 23:59:59 2033 GMT
179-
180- ### Other CAs
181-
182- * Root CA: ** HARICA Client ECC Root CA 2021**
183- Info: https://crt.sh/?caid=202189
184- X509 Certificate: https://crt.sh/?id=4147052292
185- Not after: Feb 13 11:03:33 2045 GMT
186- * Issuing CA: ** HARICA Client Authentication ECC** [ client certificates only]
187- Info: https://crt.sh/?caid=207671
188- X509 Certificate: https://crt.sh/?id=4442848518
189- Not after: Mar 15 09:17:38 2036 GMT
190- * Root CA: ** HARICA Client RSA Root CA 2021**
191- Info: https://crt.sh/?caid=202188
192- X509 Certificate: https://crt.sh/?id=4147049674
193- Not after: Feb 13 10:58:45 2045 GMT
194- * Issuing CA: ** HARICA Client Authentication RSA** [ client certificates only]
195- Info: https://crt.sh/?caid=207670
196- X509 Certificate: https://crt.sh/?id=4442848531
197- Not after: Mar 15 09:19:36 2036 GMT
198-
169+ * Issuing CA: ** Sectigo RSA Organization Validation Secure Server CA**
170+ Info: https://crt.sh/?caid=105487
171+ X509 Certificate: https://crt.sh/?id=924467857
172+ Not after: Dec 31 23:59:59 2030 GMT
173+ * Issuing CA: ** GEANT OV RSA CA 4**
174+ Info: https://crt.sh/?caid=160137
175+ X509 Certificate: https://crt.sh/?id=2475254782
176+ Not after: May 1 23:59:59 2033 GMT
177+ * Issuing CA: ** GEANT Personal CA 4** [ client/smime certificates only]
178+ Info: https://crt.sh/?caid=160144
179+ X509 Certificate: https://crt.sh/?id=2475255043
180+ Not after: May 1 23:59:59 2033 GMT
181+ * Issuing CA: ** GEANT eScience Personal CA 4** [ client/smime certificates only]
182+ Info: https://crt.sh/?caid=160134
183+ X509 Certificate: https://crt.sh/?id=2475253350
184+ Not after: May 1 23:59:59 2033 GMT
199185* Root CA: ** D-TRUST Limited Basic Root CA 1 2019**
200186 X509 Certificate: https://www.d-trust.net/cgi-bin/D-TRUST_Limited_Basic_Root_CA_1_2019.crt
201187 Not after: Jun 19 08:15:51 2034 GMT
202- * Issuing CA: ** D-TRUST Limited Basic CA 1-2 2019** [ client certificates via TMF e.V.]
203- X509 Certificate: https://www.d-trust.net/cgi-bin/D-TRUST_Limited_Basic_CA_1-2_2019.crt
204- Not after: Jun 19 08:15:51 2034 GMT
205- * Issuing CA: ** D-TRUST Limited Basic CA 1-3 2019** [ client certificates via TMF e.V.]
206- X509 Certificate: https://www.d-trust.net/cgi-bin/D-TRUST_Limited_Basic_CA_1-3_2019.crt
207- Not after: Jun 19 08:15:51 2034 GMT
188+ * Issuing CA: ** D-TRUST Limited Basic CA 1-2 2019** [ client certificates via TMF e.V.]
189+ X509 Certificate: https://www.d-trust.net/cgi-bin/D-TRUST_Limited_Basic_CA_1-2_2019.crt
190+ Not after: Jun 19 08:15:51 2034 GMT
191+ * Issuing CA: ** D-TRUST Limited Basic CA 1-3 2019** [ client certificates via TMF e.V.]
192+ X509 Certificate: https://www.d-trust.net/cgi-bin/D-TRUST_Limited_Basic_CA_1-3_2019.crt
193+ Not after: Jun 19 08:15:51 2034 GMT
208194
0 commit comments