Re: [lfs-support] Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-05-21)
| Newsgroups | gmane.linux.lfs.beyond.support |
|---|---|
| Message-ID | <[email protected]> |
Am 21.05.25 um 09:12 schrieb "Douglas R. Reno" ([email protected] via lfs-support Mailing List): /* snip */ > > Another important thing to mention is that **all** users who have > make-ca installed need to make sure that they are on make-ca-1.16 to > prevent issues with obtaining updated security certificates from > Mozilla. Mozilla recently changed the domain that we get the > certificates from hg.mozilla.org to hg-edge.mozilla.org, and in addition > to the domain, also changed the organization that signs the certificate > for the new domain. Because of that, previous versions of make-ca will > no longer be able to contact Mozilla's servers to download the security > certificates. In make-ca-1.16 we fixed this by shipping the correct root > certificate to contact hg-edge.mozilla.org, and corrected the domain name. I think there may be a problem for those who have an /etc/make-ca.conf and used make-ca-1.16's /etc/make-ca/make-ca.conf.dist to replace that file because that make-ca.conf.dist still contained the old invalid URL. If that URL is used to obtain certdata.text, the certs would not be updated because the URL in make-ca.conf overrules that used in /sbin/make-ca. So I suggest that everyone who updated to make-ca-1.16 makes sure that the URL used in /etc/make-ca.conf matches that in /sbin/make-ca or is otherwise still valid. Rainer -- http://lists.linuxfromscratch.org/sympa/info/blfs-support Unsubscribe: See the above information page