head	1.17;
access;
symbols
	pkgsrc-2026Q1:1.16.0.8
	pkgsrc-2026Q1-base:1.16
	pkgsrc-2025Q4:1.16.0.6
	pkgsrc-2025Q4-base:1.16
	pkgsrc-2025Q3:1.16.0.4
	pkgsrc-2025Q3-base:1.16
	pkgsrc-2025Q2:1.16.0.2
	pkgsrc-2025Q2-base:1.16
	pkgsrc-2025Q1:1.15.0.10
	pkgsrc-2025Q1-base:1.15
	pkgsrc-2024Q4:1.15.0.8
	pkgsrc-2024Q4-base:1.15
	pkgsrc-2024Q3:1.15.0.6
	pkgsrc-2024Q3-base:1.15
	pkgsrc-2024Q2:1.15.0.4
	pkgsrc-2024Q2-base:1.15
	pkgsrc-2024Q1:1.15.0.2
	pkgsrc-2024Q1-base:1.15
	pkgsrc-2023Q4:1.14.0.4
	pkgsrc-2023Q4-base:1.14
	pkgsrc-2023Q3:1.14.0.2
	pkgsrc-2023Q3-base:1.14
	pkgsrc-2023Q2:1.11.0.2
	pkgsrc-2023Q2-base:1.11
	pkgsrc-2023Q1:1.10.0.4
	pkgsrc-2023Q1-base:1.10
	pkgsrc-2022Q4:1.10.0.2
	pkgsrc-2022Q4-base:1.10
	pkgsrc-2022Q3:1.9.0.2
	pkgsrc-2022Q3-base:1.9
	pkgsrc-2022Q2:1.7.0.2
	pkgsrc-2022Q2-base:1.7
	pkgsrc-2022Q1:1.5.0.2
	pkgsrc-2022Q1-base:1.5
	pkgsrc-2021Q4:1.3.0.10
	pkgsrc-2021Q4-base:1.3
	pkgsrc-2021Q3:1.3.0.8
	pkgsrc-2021Q3-base:1.3
	pkgsrc-2021Q2:1.3.0.6
	pkgsrc-2021Q2-base:1.3
	pkgsrc-2021Q1:1.3.0.4
	pkgsrc-2021Q1-base:1.3
	pkgsrc-2020Q4:1.3.0.2
	pkgsrc-2020Q4-base:1.3
	pkgsrc-2020Q3:1.2.0.4
	pkgsrc-2020Q3-base:1.2
	pkgsrc-2020Q2:1.2.0.2
	pkgsrc-2020Q2-base:1.2;
locks; strict;
comment	@# @;


1.17
date	2026.04.04.21.48.56;	author kim;	state Exp;
branches;
next	1.16;
commitid	AdYgLRcBcqxbMGAG;

1.16
date	2025.04.30.18.29.53;	author kim;	state Exp;
branches;
next	1.15;
commitid	zNqzGQd3BmT7A6TF;

1.15
date	2024.03.22.05.37.43;	author kim;	state Exp;
branches;
next	1.14;
commitid	MbVZljs7mNsTh73F;

1.14
date	2023.08.14.05.25.09;	author wiz;	state Exp;
branches;
next	1.13;
commitid	LOSB79OLVxvXjIAE;

1.13
date	2023.07.05.18.13.22;	author kim;	state Exp;
branches;
next	1.12;
commitid	WmbmrTXh8jUHRDvE;

1.12
date	2023.07.05.17.30.23;	author kim;	state Exp;
branches;
next	1.11;
commitid	O8LQPOkDyEHWCDvE;

1.11
date	2023.05.21.16.33.50;	author kim;	state Exp;
branches;
next	1.10;
commitid	A0i8GSfBouJIKQpE;

1.10
date	2022.10.19.13.56.32;	author nia;	state Exp;
branches;
next	1.9;
commitid	SJILZksUbr0GLkYD;

1.9
date	2022.07.17.02.58.32;	author tnn;	state Exp;
branches;
next	1.8;
commitid	cQq3lb39Yijr9cMD;

1.8
date	2022.07.09.09.38.57;	author wiz;	state Exp;
branches;
next	1.7;
commitid	GbkZn6BfZnQLCcLD;

1.7
date	2022.06.12.07.05.30;	author kim;	state Exp;
branches;
next	1.6;
commitid	7USBYLAYYSZWCIHD;

1.6
date	2022.04.21.11.00.00;	author wiz;	state Exp;
branches;
next	1.5;
commitid	0f49QkLAsVT0C3BD;

1.5
date	2022.02.28.06.46.52;	author kim;	state Exp;
branches;
next	1.4;
commitid	DjZ5tOP9rVWLSluD;

1.4
date	2022.02.28.05.48.44;	author kim;	state Exp;
branches;
next	1.3;
commitid	js5Y4QdKAzbExluD;

1.3
date	2020.10.12.21.52.30;	author kim;	state Exp;
branches;
next	1.2;
commitid	zRSvtaatfi4O5FrC;

1.2
date	2020.06.08.09.55.36;	author kim;	state Exp;
branches;
next	1.1;
commitid	MAmEQEImQirr9pbC;

1.1
date	2020.05.31.15.53.44;	author kim;	state Exp;
branches;
next	;
commitid	wIuGk1cLslBHppaC;


desc
@@


1.17
log
@ca-certificates: Update to 20260223

ca-certificates (20260223) unstable; urgency=medium

  * Update Mozilla certificate authority bundle to version 2.82
    The following certificate authorities were added (+):
    + TrustAsia TLS ECC Root CA
    + TrustAsia TLS RSA Root CA
    + SwissSign RSA TLS Root CA 2022 - 1
    + OISTE Server Root ECC G1
    +  OISTE Server Root RSA G1
    The following certificate authorities were removed (-):
    - GlobalSign Root CA
    - Entrust.net Premium 2048 Secure Server CA
    - Baltimore CyberTrust Root (closes: #1121936)
    - Comodo AAA Services root
    - XRamp Global CA Root
    - Go Daddy Class 2 CA
    - Starfield Class 2 CA
    - CommScope Public Trust ECC Root-01
    - CommScope Public Trust ECC Root-02
    - CommScope Public Trust RSA Root-01
    - CommScope Public Trust RSA Root-02
  * Use dh_usrlocal to create /usr/local/share/ca-certificates
    (closes: #1127100)

 -- Julien Cristau <jcristau@@debian.org>  Mon, 23 Feb 2026 17:46:55 +0100
@
text
@# $NetBSD: Makefile,v 1.16 2025/04/30 18:29:53 kim Exp $

PKGNAME=	ca-certificates-20260223
DISTNAME=	${PKGNAME_NOREV:C/-([^-]*)$/_\1/}
CATEGORIES=	security
MASTER_SITES=	http://deb.debian.org/debian/pool/main/c/ca-certificates/
EXTRACT_SUFX=	.tar.xz

MAINTAINER=	pkgsrc-users@@NetBSD.org
HOMEPAGE=	https://packages.debian.org/source/sid/ca-certificates
COMMENT=	Root CA certificates from the Mozilla Project
LICENSE=	gnu-gpl-v2 AND mpl-2.0

NO_CONFIGURE=			yes
PYTHON_FOR_BUILD_ONLY=		tool
PYTHON_VERSIONS_INCOMPATIBLE=	27

USE_TOOLS=	echo:run find:run ln:run openssl:run rm:run sed:run sort:run wc:run

WRKSRC=		${WRKDIR}/${PKGBASE}
DATADIR=	${PREFIX}/share/${PKGBASE}
DOCDIR=		${PREFIX}/share/doc/${PKGBASE}
EGDIR=		${PREFIX}/share/examples/${PKGBASE}
MANDIR=		${PREFIX}/${PKGMANDIR}/man8

# Set default certificate store path depending on whether we depend on
# builtin or pkgsrc openssl.

CHECK_BUILTIN.openssl=	yes
.include "../../security/openssl/builtin.mk"
CHECK_BUILTIN.openssl=	no
.if !empty(USE_BUILTIN.openssl:M[yY][eE][sS])
SSLDIR=		/etc/openssl
.else
SSLDIR=		${PKG_SYSCONFDIR}/openssl
.endif

SUBST_CLASSES=		conf paths
SUBST_MESSAGE.conf=	Adjusting configuration file.
SUBST_STAGE.conf=	post-build
SUBST_FILES.conf=	ca-certificates.conf
SUBST_SED.conf=		-e 's,^share/ca-certificates/,,'
SUBST_MESSAGE.paths=	Replacing hard-coded paths.
SUBST_STAGE.paths=	post-build
SUBST_FILES.paths=	Makefile sbin/Makefile
SUBST_FILES.paths+=	ca-certificates.conf
SUBST_FILES.paths+=	ca-certificates-dir.conf
SUBST_FILES.paths+=	sbin/update-ca-certificates sbin/update-ca-certificates.8
SUBST_FILES.paths+=	README.pkgsrc
SUBST_SED.paths=	-e 's,/usr/sbin,${PREFIX}/sbin,g'
SUBST_SED.paths+=	-e 's,/etc/ca-certificates,${PKG_SYSCONFDIR}/ca-certificates,g'
SUBST_SED.paths+=	-e 's,/etc/ssl,${SSLDIR},g'
SUBST_SED.paths+=	-e 's,/usr/share/ca-certificates,${DATADIR},g'

INSTALLATION_DIRS=	sbin ${DATADIR} ${DOCDIR} ${EGDIR} ${MANDIR}

CONF_FILES=		${EGDIR}/ca-certificates.conf \
			${PKG_SYSCONFDIR}/ca-certificates.conf \
			${EGDIR}/ca-certificates-dir.conf \
			${PKG_SYSCONFDIR}/ca-certificates-dir.conf

pre-build:
	${CP} ${FILESDIR}/ca-certificates.conf ${FILESDIR}/ca-certificates-dir.conf \
	    ${FILESDIR}/README.pkgsrc ${WRKSRC}/
	${GREP} '^share/ca-certificates/' ${FILESDIR}/../PLIST \
	    >> ${WRKSRC}/ca-certificates.conf

post-install:
	${INSTALL_MAN} \
	    ${WRKSRC}/sbin/update-ca-certificates.8 \
	    ${DESTDIR}${MANDIR}/
	${INSTALL_DATA} \
	    ${WRKSRC}/README.pkgsrc \
	    ${WRKSRC}/debian/README.source \
	    ${WRKSRC}/debian/changelog \
	    ${DESTDIR}${DOCDIR}/
	${INSTALL_DATA} \
	    ${WRKSRC}/ca-certificates.conf \
	    ${WRKSRC}/ca-certificates-dir.conf \
	    ${DESTDIR}${EGDIR}/

.include "../../lang/python/tool.mk"
PYTHON_VERSIONED_DEPENDENCIES+=	cryptography:tool
.include "../../lang/python/versioned_dependencies.mk"
.include "../../mk/bsd.pkg.mk"
@


1.16
log
@ca-certificates: Update to 20250419

ca-certificates (20250419) unstable; urgency=medium

  [ Alexander Kanavin ]
  * update-ca-certificates: add a --sysroot option

  [ Julien Cristau ]
  * Update Mozilla certificate authority bundle to version 2.74.
    The following certificate authorities were added (+):
    + D-TRUST BR Root CA 2 2023
    + D-TRUST EV Root CA 2 2023
    The following certificate authorities were removed (-):
    - Entrust Root Certification Authority - G4
    - SecureSign RootCA11
    - Security Communication RootCA3
    - SwissSign Silver CA - G2

 -- Julien Cristau <jcristau@@debian.org>  Sat, 19 Apr 2025 09:25:37 +0200

ca-certificates (20241223) unstable; urgency=medium

  * Update Mozilla certificate authority bundle to version 2.70.
    The following certificate authorities were added (+):
    + Telekom Security TLS ECC Root 2020
    + Telekom Security TLS RSA Root 2023
    + FIRMAPROFESIONAL CA ROOT-A WEB
    + TWCA CYBER Root CA
    + SecureSign Root CA12
    + SecureSign Root CA14
    + SecureSign Root CA15
    The following certificate authorities were removed (-):
    - Security Communication Root CA (closes: #1063093)
  * Add Romanian debconf translation, thanks to Remus-Gabriel Chelu.
    Closes: #1067042, #1031490.

 -- Julien Cristau <jcristau@@debian.org>  Mon, 23 Dec 2024 12:53:45 +0100
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.15 2024/03/22 05:37:43 kim Exp $
d3 1
a3 1
PKGNAME=	ca-certificates-20250419
@


1.15
log
@ca-certificates: Update to 20240203

ca-certificates (20240203) unstable; urgency=medium

  [ Jeffrey Walton ]
  * update-ca-certificates man page updates
  * fix shellcheck warnings (closes: #1058658, #981663)

  [ Gioele Barabucci ]
  * Use standard dh sequence (closes: #1050112)

  [ Julien Cristau ]
  * Update Mozilla certificate authority bundle to version 2.64
    The following certificate authorities were added (+):
    + Atos TrustedRoot Root CA ECC TLS 2021
    + Atos TrustedRoot Root CA RSA TLS 2021
    + BJCA Global Root CA1
    + BJCA Global Root CA2
    + CommScope Public Trust ECC Root-01
    + CommScope Public Trust ECC Root-02
    + CommScope Public Trust RSA Root-01
    + CommScope Public Trust RSA Root-02
    + Sectigo Public Server Authentication Root E46
    + Sectigo Public Server Authentication Root R46
    + SSL.com TLS ECC Root CA 2022
    + SSL.com TLS RSA Root CA 2022
    + TrustAsia Global Root CA G3
    + TrustAsia Global Root CA G4
    The following certificate authorities were removed (-):
    - Autoridad de Certificacion Firmaprofesional CIF A62634068
    - E-Tugra Certification Authority (closes: #1032916)
    - E-Tugra Global Root CA ECC v3
    - E-Tugra Global Root CA RSA v3
    - Hongkong Post Root CA 1
    - TrustCor ECA-1
    - TrustCor RootCert CA-1
    - TrustCor RootCert CA-2 (closes: #1023945)

 -- Julien Cristau <jcristau@@debian.org>  Sun, 04 Feb 2024 10:41:43 +0100
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.14 2023/08/14 05:25:09 wiz Exp $
d3 1
a3 1
PKGNAME=	ca-certificates-20240203
@


1.14
log
@*: recursive bump for Python 3.11 as new default
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.13 2023/07/05 18:13:22 kim Exp $
d3 1
a3 1
PKGNAME=	ca-certificates-20230311
a4 1
PKGREVISION=	3
@


1.13
log
@ca-certificates: Fix previously improved relocatability
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.12 2023/07/05 17:30:23 kim Exp $
d5 1
a5 1
PKGREVISION=	2
@


1.12
log
@ca-certificates: Be more relocatable
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.11 2023/05/21 16:33:50 kim Exp $
d5 1
a5 1
PKGREVISION=	1
@


1.11
log
@ca-certificates: Update to 20230311

ca-certificates (20230311) unstable; urgency=medium

  [ Đoàn Trần Công Danh ]
  * ca-certificates: compat with non-GNU mktemp (closes: #1000847)

  [ Ilya Lipnitskiy ]
  * certdata2pem.py: use UTC time when checking cert validity

  [ Julien Cristau ]
  * Update Mozilla certificate authority bundle to version 2.60
    The following certificate authorities were added (+):
    + "Autoridad de Certificacion Firmaprofesional CIF A62634068"
    + "Certainly Root E1"
    + "Certainly Root R1"
    + "D-TRUST BR Root CA 1 2020"
    + "D-TRUST EV Root CA 1 2020"
    + "DigiCert TLS ECC P384 Root G5"
    + "DigiCert TLS RSA4096 Root G5"
    + "E-Tugra Global Root CA ECC v3"
    + "E-Tugra Global Root CA RSA v3"
    + "HARICA TLS ECC Root CA 2021"
    + "HARICA TLS RSA Root CA 2021"
    + "HiPKI Root CA - G1"
    + "ISRG Root X2"
    + "Security Communication ECC RootCA1"
    + "Security Communication RootCA3"
    + "Telia Root CA v2"
    + "TunTrust Root CA"
    + "vTrus ECC Root CA"
    + "vTrus Root CA"
    The following certificate authorities were removed (-):
    - "Cybertrust Global Root" (expired)
    - "EC-ACC"
    - "GlobalSign Root CA - R2" (expired)
    - "Hellenic Academic and Research Institutions RootCA 2011"
    - "Network Solutions Certificate Authority"
    - "Staat der Nederlanden EV Root CA" (expired)
  * Drop trailing space from debconf template causing misformatting
    (closes: #980821)

  [ Wataru Ashihara ]
  * Make certdata2pem.py compatible with cryptography >= 35 (closes: #1008244)

 -- Julien Cristau <jcristau@@debian.org>  Sat, 11 Mar 2023 09:47:05 +0100
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.10 2022/10/19 13:56:32 nia Exp $
d5 1
@


1.10
log
@fighting a losing battle against py-cryptography rustification, part 2

Switch users to versioned_dependencies.mk.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.9 2022/07/17 02:58:32 tnn Exp $
d3 1
a3 2
PKGNAME=	ca-certificates-20211016
PKGREVISION=	4
d20 1
a20 1
WRKSRC=		${WRKDIR}/${PKGNAME_NOREV}
d63 1
a63 1
	@@${CP} ${FILESDIR}/ca-certificates.conf ${FILESDIR}/ca-certificates-dir.conf \
d65 1
a65 1
	@@${GREP} '^share/ca-certificates/' ${FILESDIR}/../PLIST \
a67 3
post-extract:
	${MV} ${WRKDIR}/work ${WRKSRC}

@


1.9
log
@ca-certificates: try to mend py-cryptography fallout
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.8 2022/07/09 09:38:57 wiz Exp $
a14 2
BUILD_DEPENDS+=	${PYPKGPREFIX}-cryptography-[0-9]*:../../security/py-cryptography

d16 1
a16 1
PYTHON_FOR_BUILD_ONLY=		yes
d87 2
@


1.8
log
@ca-certificates: this does not support python 2
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.7 2022/06/12 07:05:30 kim Exp $
d4 1
a4 1
PKGREVISION=	3
@


1.7
log
@security/ca-certificates: Add configurability for certificate store

- The location of the system certificate store can now be set using
  a new configuration file (ca-certificates-dir.conf).

- Installing the certificates to the system certificate store must
  be enabled by the administrator.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.6 2022/04/21 11:00:00 wiz Exp $
d15 1
a15 2
NO_CONFIGURE=		yes
PYTHON_FOR_BUILD_ONLY=	yes
d17 3
a19 1
PYTHON_VERSIONED_DEPENDENCIES+=	cryptography:build
a88 1
.include "../../lang/python/versioned_dependencies.mk"
@


1.6
log
@*: convert to versioned_dependencies for py-cryptography
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.5 2022/02/28 06:46:52 kim Exp $
d4 1
a4 1
PKGREVISION=	1
d28 3
a30 4
# Set paths depending on whether we depend on builtin or pkgsrc
# openssl.  \todo Arguably, we should consider installing into both
# builtin and pkgsrc, if both exist, but this requires much more
# thought.
d49 1
d53 1
a53 1
SUBST_SED.paths+=	-e 's,/etc/ca-certificates.conf,${PKG_SYSCONFDIR}/ca-certificates.conf,g'
d60 3
a62 1
			${PKG_SYSCONFDIR}/ca-certificates.conf
d65 2
a66 1
	@@${CP} ${FILESDIR}/ca-certificates.conf ${FILESDIR}/README.pkgsrc ${WRKSRC}/
d84 1
@


1.5
log
@security/ca-certificates: Fix mktemp usage
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.4 2022/02/28 05:48:44 kim Exp $
d18 1
a18 1
BUILD_DEPENDS+=	${PYPKGPREFIX}-cryptography-[0-9]*:../../security/py-cryptography
d84 1
@


1.4
log
@security/ca-certificates: Update to 20211016

ca-certificates (20211016) unstable; urgency=low

  [ Michael Shuler ]
  * Fix error on install when TEMPBUNDLE missing. Closes: #996005

 -- Julien Cristau <jcristau@@debian.org>  Sat, 16 Oct 2021 18:09:43 +0200

ca-certificates (20211004) unstable; urgency=low

  [ Debian Janitor ]
  * Fix day-of-week for changelog entry 20090624.

  [ Julien Cristau ]
  * Create temporary ca-certificates.crt on the same file system.
    Closes: #923784
  * Don't remove ca-certificates.crt before updating it, so it doesn't
    go missing for a short while (closes: #920348).  Thanks, Dimitris
    Aragiorgis!
  * Bump package priority from optional to standard.
  * mozilla/{certdata.txt,nssckbi.h}: Update Mozilla certificate authority
    bundle to version 2.50
    The following certificate authorities were added (+):
    + "AC RAIZ FNMT-RCM SERVIDORES SEGUROS"
    + "GlobalSign Root R46"
    + "GlobalSign Root E46"
    + "GLOBALTRUST 2020"
    + "ANF Secure Server Root CA"
    + "Certum EC-384 CA"
    + "Certum Trusted Root CA"
    The following certificate authorities were removed (-):
    - "QuoVadis Root CA"
    - "Sonera Class 2 Root CA"
    - "GeoTrust Primary Certification Authority - G2"
    - "VeriSign Universal Root Certification Authority"
    - "Chambers of Commerce Root - 2008"
    - "Global Chambersign Root - 2008"
    - "Trustis FPS Root CA"
    - "Staat der Nederlanden Root CA - G3"
  * Blacklist expired root certificate "DST Root CA X3" (closes: #995432)
  * mozilla/certdata2pem.py: print a warning for expired certificates.

 -- Julien Cristau <jcristau@@debian.org>  Thu, 07 Oct 2021 17:12:47 +0200

ca-certificates (20210119) unstable; urgency=medium

  [ Julien Cristau ]
  * New maintainer (closes: #976406)
  * mozilla/{certdata.txt,nssckbi.h}: Update Mozilla certificate authority
    bundle to version 2.46.
    The following certificate authorities were added (+):
    + "certSIGN ROOT CA G2"
    + "e-Szigno Root CA 2017"
    + "Microsoft ECC Root Certificate Authority 2017"
    + "Microsoft RSA Root Certificate Authority 2017"
    + "NAVER Global Root Certification Authority"
    + "Trustwave Global Certification Authority"
    + "Trustwave Global ECC P256 Certification Authority"
    + "Trustwave Global ECC P384 Certification Authority"
    The following certificate authorities were removed (-):
    - "EE Certification Centre Root CA"
    - "GeoTrust Universal CA 2"
    - "LuxTrust Global Root 2"
    - "OISTE WISeKey Global Root GA CA"
    - "Staat der Nederlanden Root CA - G2" (closes: #962079)
    - "Taiwan GRCA"
    - "Verisign Class 3 Public Primary Certification Authority - G3"

  [ Michael Shuler ]
  * mozilla/blacklist:
    Revert Symantec CA blacklist (#911289). Closes: #962596
    The following root certificates were added back (+):
    + "GeoTrust Primary Certification Authority - G2"
    + "VeriSign Universal Root Certification Authority"

  [ Gianfranco Costamagna ]
  * debian/{rules,control}:
    Merge Ubuntu patch from Matthias Klose to use Python3 during build.
    Closes: #942915

 -- Julien Cristau <jcristau@@debian.org>  Tue, 19 Jan 2021 11:11:04 +0100
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.3 2020/10/12 21:52:30 kim Exp $
d4 1
@


1.3
log
@Use PKGMANDIR
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.2 2020/06/08 09:55:36 kim Exp $
d3 1
a3 2
PKGNAME=	ca-certificates-20200601
PKGREVISION=	1
d17 2
@


1.2
log
@Upgrade to 20200601

* Update Mozilla certificate authority bundle to version 2.40.
* Add distrusted Symantec CA list to blacklist for explicit removal.
* Blacklist expired root certificate, "AddTrust External Root".

The following certificate authorities were added (+):
+ "Certigna Root CA"
+ "emSign ECC Root CA - C3"
+ "emSign ECC Root CA - G3"
+ "emSign Root CA - C1"
+ "emSign Root CA - G1"
+ "Entrust Root Certification Authority - G4"
+ "GTS Root R1"
+ "GTS Root R2"
+ "GTS Root R3"
+ "GTS Root R4"
+ "Hongkong Post Root CA 3"
+ "UCA Extended Validation Root"
+ "UCA Global G2 Root"

The following certificate authorities were removed (-):
- "AddTrust External Root"
- "Certinomis - Root CA"
- "Certplus Class 2 Primary CA"
- "Deutsche Telekom Root CA 2"
- "GeoTrust Global CA"
- "GeoTrust Primary Certification Authority"
- "GeoTrust Primary Certification Authority - G2"
- "GeoTrust Primary Certification Authority - G3"
- "GeoTrust Universal CA"
- "thawte Primary Root CA"
- "thawte Primary Root CA - G2"
- "thawte Primary Root CA - G3"
- "VeriSign Class 3 Public Primary Certification Authority - G4"
- "VeriSign Class 3 Public Primary Certification Authority - G5"
- "VeriSign Universal Root Certification Authority"

Changes for pkgsrc packaging:
* Add README.pkgsrc, replacing MESSAGE.
* Improve DESCR to better describe the functionality of the package.
* Install changelog and README.source from the distribution package.
@
text
@d1 1
a1 1
# $NetBSD: Makefile,v 1.1 2020/05/31 15:53:44 kim Exp $
d4 2
a5 1
DISTNAME=	${PKGNAME:C/-([^-]*)$/_\1/}
d24 1
a24 1
MANDIR=		${PREFIX}/share/man/man8
@


1.1
log
@Add ca-certificates-20190110

This package provides the certificates distributed by the Mozilla
Project.

It also provides a script, update-ca-certs, which can be used to manage
a location that makes certificates usable by TLS implementations,
including installing select certificates from this package.
@
text
@d1 1
a1 1
# $NetBSD$
d3 1
a3 1
PKGNAME=	ca-certificates-20190110
d17 1
a17 1
USE_TOOLS=	awk:run echo:run expr:run ln:run ls:run openssl:run rm:run mkdir:run
d21 1
d23 1
d48 1
d54 1
a54 1
INSTALLATION_DIRS=	sbin ${DATADIR} ${EGDIR} share/man/man8
d60 1
a60 1
	@@${CP} ${FILESDIR}/ca-certificates.conf ${WRKSRC}/
d64 3
d68 11
a78 4
	${INSTALL_MAN} ${WRKSRC}/sbin/update-ca-certificates.8 \
	    ${DESTDIR}${PREFIX}/share/man/man8/update-ca-certificates.8
	${INSTALL_DATA} ${WRKSRC}/ca-certificates.conf \
	    ${DESTDIR}${EGDIR}/ca-certificates.conf
@

