Re: CA's TLS Certificate Bundle in base = BAD

Roger Marquis <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
After running a 12.4 installworld found TrustCor certs had been
reinstalled.  Out of curiosity, were these known bad certificates
intentionally left in RELEASE?  If so it does appear we could use a
ports-based solution.  At this point all the port would need to do is
periodically "rm /usr/share/certs/trusted/TrustCor*" but there's sure to
be room for options to better harden PKI.

Roger Marquis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.