From 57655af998ec6e95ac6bc7d745ce7bdf784c93ad Mon Sep 17 00:00:00 2001 From: Pawel Date: Mon, 21 Sep 2020 07:27:19 -0700 Subject: [PATCH 1/4] Updating changelog to be consistent with package version. --- SPECS/ca-certificates/ca-certificates.spec | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/SPECS/ca-certificates/ca-certificates.spec b/SPECS/ca-certificates/ca-certificates.spec index 1f0845d1dcc..8f7fceb5c7f 100644 --- a/SPECS/ca-certificates/ca-certificates.spec +++ b/SPECS/ca-certificates/ca-certificates.spec @@ -425,42 +425,42 @@ rm -f %{pkidir}/tls/certs/*.{0,pem} %{_bindir}/bundle2pem.sh %changelog -* Mon Sep 13 2020 Pawel Winogrodzki - 2020.7.20-7 +* Mon Sep 13 2020 Pawel Winogrodzki - 20200720-7 - Removing unused 'Requires*'. -* Wed Sep 09 2020 Pawel Winogrodzki - 2020.7.20-6 +* Wed Sep 09 2020 Pawel Winogrodzki - 20200720-6 - Adding 2 Microsoft-trusted, intermediate CAs into 'ca-certificates-base'. -* Mon Aug 24 2020 Pawel Winogrodzki - 2020.7.20-5 +* Mon Aug 24 2020 Pawel Winogrodzki - 20200720-5 - Adding 'ca-certificates-legacy' to support apps, which only work with a single cert per *.pem file. Adding a new 'ca-certificates-microsoft' subpackage with CAs trusted through the Microsoft Trusted Root Program. Converting common steps into parametrized macros. -* Tue Aug 11 2020 Pawel Winogrodzki - 2020.7.20-4 +* Tue Aug 11 2020 Pawel Winogrodzki - 20200720-4 - Updating base certificates to current intermediate CAs. - Re-assigning ownership of legacy bundles from '*-shared' to subpackages creating them. - Removing commented lines. -* Fri Jul 31 2020 Pawel Winogrodzki - 2020.7.20-3 +* Fri Jul 31 2020 Pawel Winogrodzki - 20200720-3 - Changing base certificates to trust packages.microsoft.com. -* Fri Jul 31 2020 Pawel Winogrodzki - 2020.7.20-2 +* Fri Jul 31 2020 Pawel Winogrodzki - 20200720-2 - Removed redundant 'ca-bundle.trust.p11-kit' certs bundle. - Removed unnecessary pre-install step. - Moved license and config to 'ca-certificates-shared' subpackage to guarantee these to be always present regardless of the installed certificates bundle. -* Thu Jul 23 2020 Pawel Winogrodzki - 2020.7.20-1 +* Thu Jul 23 2020 Pawel Winogrodzki - 20200720-1 - Updating certdata.txt to Mozilla version from 2020/07/20. -* Thu Jul 23 2020 Pawel Winogrodzki - 2020.4.28-4 +* Thu Jul 23 2020 Pawel Winogrodzki - 20200428-4 - Fixing installation of 'ca-certificates-base` subpackage by making shared files and directory structure a 'Requires' for all certificate packages. - Updating '%%uninstall_clean_up' macro to use pk11kit tooling. - Reordering (Build)Requires to increase clarity. -* Tue May 26 2020 Paul Monson - 2020.4.28-3 +* Tue May 26 2020 Paul Monson - 20200428-3 - Initial CBL-Mariner import from Fedora 27 (license: MIT). - License verified. - Updated Mozilla certdata.txt to latest version from the "FIREFOX_76_0_RELEASE" release. From 734a9a5e59738a0799f9c6b8e970bbc388893547 Mon Sep 17 00:00:00 2001 From: Pawel Date: Mon, 21 Sep 2020 07:35:18 -0700 Subject: [PATCH 2/4] Fixing missed update to 'nssckbi.h'. --- SPECS/ca-certificates/ca-certificates.signatures.json | 2 +- SPECS/ca-certificates/ca-certificates.spec | 5 ++++- SPECS/ca-certificates/nssckbi.h | 4 ++-- 3 files changed, 7 insertions(+), 4 deletions(-) diff --git a/SPECS/ca-certificates/ca-certificates.signatures.json b/SPECS/ca-certificates/ca-certificates.signatures.json index aade17289a9..f844713ee43 100644 --- a/SPECS/ca-certificates/ca-certificates.signatures.json +++ b/SPECS/ca-certificates/ca-certificates.signatures.json @@ -17,7 +17,7 @@ "certdata.microsoft.txt": "d647ba9622bd973b2a2cb5114825a8ff6016ba3a5499a6a7cccdc1d07af25fdb", "certdata.txt": "cc6408bd4be7fbfb8699bdb40ccb7f6de5780d681d87785ea362646e4dad5e8e", "certdata2pem.py": "0be02cecc27a6e55e1cad1783033b147f502b26f9fb1bb5a53e7a43bbcb68fa0", - "nssckbi.h": "4019b4b68df6b89b22d350ffea652707864ee995b399de2f876c6d52d41f11ac", + "nssckbi.h": "c6a7ed5791bc080e083d838dee17ac910995e1511d0c9e50b5fd05767e1b864c", "pem2bundle.sh": "79012e7fabf560c3b950349e500770a314006e5b330621a50147eeda11c633ea", "trust-fixes": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", "update-ca-trust": "0c0c0600587db7f59ba5e399666152ea6de6059f37408f3946c43438d607efdd", diff --git a/SPECS/ca-certificates/ca-certificates.spec b/SPECS/ca-certificates/ca-certificates.spec index 8f7fceb5c7f..b358279661e 100644 --- a/SPECS/ca-certificates/ca-certificates.spec +++ b/SPECS/ca-certificates/ca-certificates.spec @@ -74,7 +74,7 @@ Name: ca-certificates # (but these files might have not yet been released). Version: 20200720 -Release: 7%{?dist} +Release: 8%{?dist} License: MPLv2.0 URL: https://hg.mozilla.org Group: System Environment/Security @@ -425,6 +425,9 @@ rm -f %{pkidir}/tls/certs/*.{0,pem} %{_bindir}/bundle2pem.sh %changelog +* Mon Sep 13 2020 Pawel Winogrodzki - 20200720-8 +- Aligning 'nssckbi.h' with the used 'certdata.txt' version for the Mozilla bundle. + * Mon Sep 13 2020 Pawel Winogrodzki - 20200720-7 - Removing unused 'Requires*'. diff --git a/SPECS/ca-certificates/nssckbi.h b/SPECS/ca-certificates/nssckbi.h index ed02913c3f2..ace248f4b73 100644 --- a/SPECS/ca-certificates/nssckbi.h +++ b/SPECS/ca-certificates/nssckbi.h @@ -46,8 +46,8 @@ * It's recommend to switch back to 0 after having reached version 98/99. */ #define NSS_BUILTINS_LIBRARY_VERSION_MAJOR 2 -#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 40 -#define NSS_BUILTINS_LIBRARY_VERSION "2.40" +#define NSS_BUILTINS_LIBRARY_VERSION_MINOR 42 +#define NSS_BUILTINS_LIBRARY_VERSION "2.42" /* These version numbers detail the semantic changes to the ckfw engine. */ #define NSS_BUILTINS_HARDWARE_VERSION_MAJOR 1 From 63c79a080837dbbfa2907ded90687107ce1bd41d Mon Sep 17 00:00:00 2001 From: Pawel Date: Mon, 21 Sep 2020 07:36:01 -0700 Subject: [PATCH 3/4] Updating manifests. --- .../manifests/package/pkggen_core_aarch64.txt | 6 +++--- .../manifests/package/pkggen_core_x86_64.txt | 6 +++--- .../manifests/package/toolchain_aarch64.txt | 12 ++++++------ .../resources/manifests/package/toolchain_x86_64.txt | 12 ++++++------ 4 files changed, 18 insertions(+), 18 deletions(-) diff --git a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt index 7dd95a61503..d5c3f5aa934 100644 --- a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt @@ -160,6 +160,6 @@ libffi-3.2.1-11.cm1.aarch64.rpm libtasn1-4.14-2.cm1.aarch64.rpm p11-kit-0.23.16.1-2.cm1.aarch64.rpm p11-kit-trust-0.23.16.1-2.cm1.aarch64.rpm -ca-certificates-shared-20200720-7.cm1.noarch.rpm -ca-certificates-tools-20200720-7.cm1.noarch.rpm -ca-certificates-base-20200720-7.cm1.noarch.rpm +ca-certificates-shared-20200720-8.cm1.noarch.rpm +ca-certificates-tools-20200720-8.cm1.noarch.rpm +ca-certificates-base-20200720-8.cm1.noarch.rpm diff --git a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt index 0984c4117b9..371162444a5 100644 --- a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt @@ -160,6 +160,6 @@ libffi-3.2.1-11.cm1.x86_64.rpm libtasn1-4.14-2.cm1.x86_64.rpm p11-kit-0.23.16.1-2.cm1.x86_64.rpm p11-kit-trust-0.23.16.1-2.cm1.x86_64.rpm -ca-certificates-shared-20200720-7.cm1.noarch.rpm -ca-certificates-tools-20200720-7.cm1.noarch.rpm -ca-certificates-base-20200720-7.cm1.noarch.rpm +ca-certificates-shared-20200720-8.cm1.noarch.rpm +ca-certificates-tools-20200720-8.cm1.noarch.rpm +ca-certificates-base-20200720-8.cm1.noarch.rpm diff --git a/toolkit/resources/manifests/package/toolchain_aarch64.txt b/toolkit/resources/manifests/package/toolchain_aarch64.txt index f89bd80a91f..2799b0b2ffd 100644 --- a/toolkit/resources/manifests/package/toolchain_aarch64.txt +++ b/toolkit/resources/manifests/package/toolchain_aarch64.txt @@ -17,12 +17,12 @@ bzip2-1.0.6-15.cm1.aarch64.rpm bzip2-debuginfo-1.0.6-15.cm1.aarch64.rpm bzip2-devel-1.0.6-15.cm1.aarch64.rpm bzip2-libs-1.0.6-15.cm1.aarch64.rpm -ca-certificates-20200720-7.cm1.noarch.rpm -ca-certificates-base-20200720-7.cm1.noarch.rpm -ca-certificates-legacy-20200720-7.cm1.noarch.rpm -ca-certificates-microsoft-20200720-7.cm1.noarch.rpm -ca-certificates-shared-20200720-7.cm1.noarch.rpm -ca-certificates-tools-20200720-7.cm1.noarch.rpm +ca-certificates-20200720-8.cm1.noarch.rpm +ca-certificates-base-20200720-8.cm1.noarch.rpm +ca-certificates-legacy-20200720-8.cm1.noarch.rpm +ca-certificates-microsoft-20200720-8.cm1.noarch.rpm +ca-certificates-shared-20200720-8.cm1.noarch.rpm +ca-certificates-tools-20200720-8.cm1.noarch.rpm check-0.12.0-4.cm1.aarch64.rpm check-debuginfo-0.12.0-4.cm1.aarch64.rpm cmake-3.17.3-2.cm1.aarch64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_x86_64.txt b/toolkit/resources/manifests/package/toolchain_x86_64.txt index 901d037d590..b60f46796cd 100644 --- a/toolkit/resources/manifests/package/toolchain_x86_64.txt +++ b/toolkit/resources/manifests/package/toolchain_x86_64.txt @@ -17,12 +17,12 @@ bzip2-1.0.6-15.cm1.x86_64.rpm bzip2-debuginfo-1.0.6-15.cm1.x86_64.rpm bzip2-devel-1.0.6-15.cm1.x86_64.rpm bzip2-libs-1.0.6-15.cm1.x86_64.rpm -ca-certificates-20200720-7.cm1.noarch.rpm -ca-certificates-base-20200720-7.cm1.noarch.rpm -ca-certificates-legacy-20200720-7.cm1.noarch.rpm -ca-certificates-microsoft-20200720-7.cm1.noarch.rpm -ca-certificates-shared-20200720-7.cm1.noarch.rpm -ca-certificates-tools-20200720-7.cm1.noarch.rpm +ca-certificates-20200720-8.cm1.noarch.rpm +ca-certificates-base-20200720-8.cm1.noarch.rpm +ca-certificates-legacy-20200720-8.cm1.noarch.rpm +ca-certificates-microsoft-20200720-8.cm1.noarch.rpm +ca-certificates-shared-20200720-8.cm1.noarch.rpm +ca-certificates-tools-20200720-8.cm1.noarch.rpm check-0.12.0-4.cm1.x86_64.rpm check-debuginfo-0.12.0-4.cm1.x86_64.rpm cmake-3.17.3-2.cm1.x86_64.rpm From e0916f97b222e69b84eee0e0ccba859418b00b8d Mon Sep 17 00:00:00 2001 From: Pawel Date: Mon, 21 Sep 2020 08:48:45 -0700 Subject: [PATCH 4/4] Updating signatures. --- SPECS/ca-certificates/ca-certificates.signatures.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/SPECS/ca-certificates/ca-certificates.signatures.json b/SPECS/ca-certificates/ca-certificates.signatures.json index f844713ee43..ec15c7d3890 100644 --- a/SPECS/ca-certificates/ca-certificates.signatures.json +++ b/SPECS/ca-certificates/ca-certificates.signatures.json @@ -17,7 +17,7 @@ "certdata.microsoft.txt": "d647ba9622bd973b2a2cb5114825a8ff6016ba3a5499a6a7cccdc1d07af25fdb", "certdata.txt": "cc6408bd4be7fbfb8699bdb40ccb7f6de5780d681d87785ea362646e4dad5e8e", "certdata2pem.py": "0be02cecc27a6e55e1cad1783033b147f502b26f9fb1bb5a53e7a43bbcb68fa0", - "nssckbi.h": "c6a7ed5791bc080e083d838dee17ac910995e1511d0c9e50b5fd05767e1b864c", + "nssckbi.h": "9d916fe1586259d94632f186a736449e8344b8a18f7ac97253f13efc764d77ea", "pem2bundle.sh": "79012e7fabf560c3b950349e500770a314006e5b330621a50147eeda11c633ea", "trust-fixes": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", "update-ca-trust": "0c0c0600587db7f59ba5e399666152ea6de6059f37408f3946c43438d607efdd",