Re: ca-certificates and backport to bullseye => ca-certificates-java problem

Bastien Roucaries <[email protected]> Wed, 06 Aug 2025 08:28:05 +0200
Newsgroups gmane.linux.debian.devel.java,gmane.linux.debian.devel.lts
Message-ID <8983750.qOBuL9xsDt@debian-ei>
Le vendredi 1 août 2025, 21:25:05 heure d’été d’Europe centrale Bastien 
Roucaries a écrit :
Hi Vladimir, Hi Marc,

Could you review this upgradre of ca-certificates-java and view if it is 
upgrade safe ? I will after a few week upload a ca-certificates

rouca
> Le jeudi 31 juillet 2025, 22:43:35 heure d’été d’Europe centrale Bastien
> Roucaries a écrit : Hi
> 
> I have just pushed a version here:
> https://salsa.debian.org/java-team/ca-certificates-java/-/tree/bullseye?ref_
> type=heads
> 
> Can you review ?
> 
> rouca
> 
> > Le jeudi 31 juillet 2025, 22:30:11 heure d’été d’Europe centrale Vladimir
> > 
> > Petko a écrit :
> > > Hi,
> > > 
> > > As far as I remember, 20230707 removes the circular dependency that
> > > caused upgrade issues[1][2][3]. It also requires openjdk to trigger
> > > ca-certificates-java:
> > > ----JB-jre-headless.postinst.in----
> > > # Now that java is fully registered and configured,
> > > # call update-ca-certificates-java
> > > dpkg-trigger update-ca-certificates-java
> > > ------
> > > Please check that this snippet is present in bullseye's
> > > JB-jre-headless.postinst.in of openjdk package.
> > 
> > No it is not, so that it the path to fix this ?
> > 
> > 1. first upload a openjdk  that trigger update-ca-certificates-java
> > 2. upload a backport of ca-certificates-java
> > 3. upload ca-certificates
> > 
> > rouca
> > 
> > > Best Regards,
> > > 
> > >  Vladimir.
> > > 
> > > [1]
> > > https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/2003
> > > 75
> > > 0
> > > [2]
> > > https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/1999
> > > 10
> > > 3
> > > [3]
> > > https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/2004
> > > 06
> > > 1
> > > 
> > > On Fri, Aug 1, 2025 at 1:14 AM Julien Plissonneau Duquène
> > > 
> > > <[email protected]> wrote:
> > > > Hi,
> > > > 
> > > > I can't help you much there as I didn't check what could break in your
> > > > case (bullseye). The last time this was discussed on the list was
> > > > 
> > > > https://lists.debian.org/debian-java/2023/02/msg00011.html
> > > > 
> > > > According to the PT in bullseye it depends on default-jre-headless
> > > > which
> > > > depends on openjdk-11-jre-headless which depends on
> > > > ca-certificates-java, but I don't see how updating it could cause
> > > > issues.
> > > > 
> > > > Maybe Emmanuel or doko could share more details about what could go
> > > > wrong?
> > > > 
> > > > Cheers,
> > > > 
> > > > --
> > > > Julien Plissonneau Duquène
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmiS9dkACgkQADoaLapB
CF8NMw/9HE+QvTFLGLnFVKshq4Kz3qZ4NmbtFCaDeEne4qdieCgk21Gx+a40oJRc
3siuG0B8Z+UqOLBPcpMQGXc6S9AKIko9sQXp90XojQCHX+Lo48Aeqgu9GgjW9I3s
OOuBaUdJ2z23vPJJ/28ob+Zye9jo8NRml7gJf1tyzqTX6p7LaL0rnl65bxuoJLB4
Pkcxs7/XcjDlQqoK4+028RR8iTwfYBu+uYC5h/EBPFspFhYODBSa3eolhtmwofTZ
u63uP8rJ/j9uJ8ErvgGetLiHdv0xxE4Xy8EA4kZVg2w6mjZK3/cCUm3+sADpDOUJ
XEfdslOk+hr1krZhIy4U2lv0Bf4zHQyzqVaYXsk4IvzK3TfkYoCCf/LRwRj1e3cp
kprzm02eRQeTtrFyfdaoy3MURiagL/oe9L6c0EJ6j7CtZ51kP7nIKXLnCu48mSuz
yfZ2ZiBtKUgpVcgQ5XBeEYR4VmvnABGqZ4gNvnYf/l+wmXSdo4RGcKzeQVaQmMeZ
tmtJsR7e0H8JD0LVDIFU4w1ihOBqgkuY7zTs6I2va8PaMtY/aGiJPdxOh9cmV6AP
iEhTqAQg9Oc0CME20CTWjehLlk+FQO67U9Ll6xbrwWtcHPLu8zEDW6ebRgylzGXQ
n0UC8QjCyGDUK/BnwBkbUxgDgsEN4VQF8iZbTZmYsPNbV7ogIW4=
=2Vj/
-----END PGP SIGNATURE-----