Re: [lfs-support] Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-05-21)

"Rainer Fiebig" ([email protected] via blfs-support Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
Am 21.05.25 um 09:12 schrieb "Douglas R. Reno"
([email protected] via lfs-support Mailing List):

/* snip */
> 
> Another important thing to mention is that **all** users who have
> make-ca installed need to make sure that they are on make-ca-1.16 to
> prevent issues with obtaining updated security certificates from
> Mozilla. Mozilla recently changed the domain that we get the
> certificates from hg.mozilla.org to hg-edge.mozilla.org, and in addition
> to the domain, also changed the organization that signs the certificate
> for the new domain. Because of that, previous versions of make-ca will
> no longer be able to contact Mozilla's servers to download the security
> certificates. In make-ca-1.16 we fixed this by shipping the correct root
> certificate to contact hg-edge.mozilla.org, and corrected the domain name.
I think there may be a problem for those who have an  /etc/make-ca.conf
 and used make-ca-1.16's  /etc/make-ca/make-ca.conf.dist  to replace
that file because that  make-ca.conf.dist  still contained the old
invalid URL.  If that URL is used to obtain certdata.text, the certs
would not be updated because the URL in make-ca.conf overrules that used
in /sbin/make-ca.

So I suggest that everyone who updated to make-ca-1.16 makes sure that
the URL used in  /etc/make-ca.conf  matches that in /sbin/make-ca or is
otherwise still valid.

Rainer

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.