SUSE-RU-2024:4356-1: important: Recommended update for openssl-certs
SLE-UPDATES
null at suse.de
Tue Dec 17 16:36:23 UTC 2024
# Recommended update for openssl-certs
Announcement ID: SUSE-RU-2024:4356-1
Release Date: 2024-12-17T12:37:57Z
Rating: important
References:
* bsc#1206212
* bsc#1206622
* bsc#1214248
* bsc#1220356
* bsc#1227525
Affected Products:
* SUSE Linux Enterprise Server 11 SP4
* SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
An update that has five fixes can now be installed.
## Description:
This update for openssl-certs fixes the following issues:
* Updated to 2.68 state of Mozilla SSL root CAs (bsc#1227525)
* Added: FIRMAPROFESIONAL CA ROOT-A WEB
* Distrust: GLOBALTRUST 2020
* Updated to 2.66 state of Mozilla SSL root CAs (bsc#1220356)
Added:
* CommScope Public Trust ECC Root-01
* CommScope Public Trust ECC Root-02
* CommScope Public Trust RSA Root-01
* CommScope Public Trust RSA Root-02
* D-Trust SBR Root CA 1 2022
* D-Trust SBR Root CA 2 2022
* Telekom Security SMIME ECC Root 2021
* Telekom Security SMIME RSA Root 2023
* Telekom Security TLS ECC Root 2020
* Telekom Security TLS RSA Root 2023
* TrustAsia Global Root CA G3
* TrustAsia Global Root CA G4
Removed:
* Autoridad de Certificacion Firmaprofesional CIF A62634068
* Chambers of Commerce Root - 2008
* Global Chambersign Root - 2008
* Security Communication Root CA
* Symantec Class 1 Public Primary Certification Authority - G6
* Symantec Class 2 Public Primary Certification Authority - G6
* TrustCor ECA-1
* TrustCor RootCert CA-1
* TrustCor RootCert CA-2
* VeriSign Class 1 Public Primary Certification Authority - G3
* VeriSign Class 2 Public Primary Certification Authority - G3
* Updated to 2.62 state of Mozilla SSL root CAs (bsc#1214248)
Added:
* Atos TrustedRoot Root CA ECC G2 2020
* Atos TrustedRoot Root CA ECC TLS 2021
* Atos TrustedRoot Root CA RSA G2 2020
* Atos TrustedRoot Root CA RSA TLS 2021
* BJCA Global Root CA1
* BJCA Global Root CA2
* LAWtrust Root CA2 (4096)
* Sectigo Public Email Protection Root E46
* Sectigo Public Email Protection Root R46
* Sectigo Public Server Authentication Root E46
* Sectigo Public Server Authentication Root R46
* SSL.com Client ECC Root CA 2022
* SSL.com Client RSA Root CA 2022
* SSL.com TLS ECC Root CA 2022
* SSL.com TLS RSA Root CA 2022
Removed CAs:
* Chambers of Commerce Root
* E-Tugra Certification Authority
* E-Tugra Global Root CA ECC v3
* E-Tugra Global Root CA RSA v3
* Hongkong Post Root CA 1
* Updated to 2.60 state of Mozilla SSL root CAs (bsc#1206622)
Removed CAs:
* Global Chambersign Root
* EC-ACC
* Network Solutions Certificate Authority
* Staat der Nederlanden EV Root CA
* SwissSign Platinum CA - G2
Added CAs:
* DIGITALSIGN GLOBAL ROOT ECDSA CA
* DIGITALSIGN GLOBAL ROOT RSA CA
* Security Communication ECC RootCA1
* Security Communication RootCA3
Changed trust:
* TrustCor certificates only trusted up to Nov 30 (bsc#1206212)
* Removed CAs (bsc#1206212) as most code does not handle "valid before nov 30
2022" and it is not clear how many certs were issued for SSL middleware by
TrustCor:
* TrustCor RootCert CA-1
* TrustCor RootCert CA-2
* TrustCor ECA-1
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2024-4356=1
* SUSE Linux Enterprise Server 11 SP4
zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2024-4356=1
## Package List:
* SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch)
* openssl-certs-2.66-0.7.30.1
* SUSE Linux Enterprise Server 11 SP4 (noarch)
* openssl-certs-2.66-0.7.30.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id=1206212
* https://bugzilla.suse.com/show_bug.cgi?id=1206622
* https://bugzilla.suse.com/show_bug.cgi?id=1214248
* https://bugzilla.suse.com/show_bug.cgi?id=1220356
* https://bugzilla.suse.com/show_bug.cgi?id=1227525
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20241217/28cc8b00/attachment.htm>
More information about the sle-updates
mailing list