|
|
Log in / Subscribe / Register

Debian alert DLA-4726-1 (ca-certificates)

From:  rouca@debian.org
To:  <debian-lts-announce@lists.debian.org>
Subject:  [SECURITY] [DLA 4726-1] ca-certificates CA certificate update
Date:  Sun, 09 Aug 2026 22:55:51 +0200
Message-ID:  <5346103ab54d86dcd7b679d5346b69db@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4726-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Bastien Roucariès August 09, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ca-certificates Version : 20250419~deb12u1~deb11u1 20250419~deb12u1 Debian Bug : 981663 1023945 1031490 1032916 1050112 1058658 1063093 1067042 ca-certificates a package that contains the certificate authorities shipped with Mozilla's browser to allow SSL-based applications to check for the authenticity of SSL connections, was updated Mozilla certificate authority bundle was updated to version 2.74 The following certificate authorities were added (+): + D-TRUST BR Root CA 2 2023 + D-TRUST EV Root CA 2 2023 + Telekom Security TLS ECC Root 2020 + Telekom Security TLS RSA Root 2023 + FIRMAPROFESIONAL CA ROOT-A WEB + TWCA CYBER Root CA + SecureSign Root CA12 + SecureSign Root CA14 + SecureSign Root CA15 + Atos TrustedRoot Root CA ECC TLS 2021 + Atos TrustedRoot Root CA RSA TLS 2021 + BJCA Global Root CA1 + BJCA Global Root CA2 + CommScope Public Trust ECC Root-01 + CommScope Public Trust ECC Root-02 + CommScope Public Trust RSA Root-01 + CommScope Public Trust RSA Root-02 + Sectigo Public Server Authentication Root E46 + Sectigo Public Server Authentication Root R46 + SSL.com TLS ECC Root CA 2022 + SSL.com TLS RSA Root CA 2022 + TrustAsia Global Root CA G3 + TrustAsia Global Root CA G4 The following certificate authorities were removed (-): - Entrust Root Certification Authority - G4 - SecureSign RootCA11 - Security Communication RootCA3 - SwissSign Silver CA - G2 - Security Communication Root CA (closes: #1063093) - Autoridad de Certificacion Firmaprofesional CIF A62634068 - E-Tugra Certification Authority (closes: #1032916) - E-Tugra Global Root CA ECC v3 - E-Tugra Global Root CA RSA v3 - Hongkong Post Root CA 1 - TrustCor ECA-1 - TrustCor RootCert CA-1 - TrustCor RootCert CA-2 (closes: #1023945) Please note that Debian can neither confirm nor deny whether the certificate authorities whose certificates are included in this package have in any way been audited for trustworthiness or RFC 3647 compliance. Full responsibility to assess them belongs to the local system administrator. For Debian 11 bullseye, this problem has been fixed in version 20250419~deb12u1~deb11u1. For Debian 12 bookworm, this problem has been fixed in version 20250419~deb12u1. We recommend that you upgrade your ca-certificates packages. For the detailed security status of ca-certificates please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ca-certificates Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp46VcACgkQADoaLapB CF/aAA/+P6ocKto843+PDizf3h5Ylj8rQ28HD2qHo1Eb6t3Vmny6ytZXWbtng3J1 EtIrDmB+p17X9vnqWNyNZH20C33TFeunRgWoMY7b4tHH4hY8/313Wnq/qJbwq2ZI VSDa+adfnSpLYD5mFGpkZ6Rr9FZg3nYOY37x4ME0NvqAWiCSMPGnVLtuQ6lFNrLT 7qVcR8E914NDVOppU4uA8vxEfRdo4OMZ+L55SNyfV3a7o9UKP/xWTxNaOszLYN1j KAUmlVK0R2weJjwUeARJWgpO63nNBumW6dF71ysT+fPoTg66kOHiIzi8G5+y997n FJT2iWjZm1V7iRmfA/rXNDnsrET8mtT2AaizrBCP4id0G0Xh/vIVFe9NPhWsc9CS seamphRJBmB0a6zXUfwn71fS0HhCGuoYNVWSYPS0YzessWpPktNRqRCaDjexFx6M jL/cXa6MImgiJCm9CLdPuXlay9ch+B6/I4PxMFhbOyz+R0egjB/yu2Dv2e7FGjO3 4WY2QlYRjX4IpE032OqeRjEyUlHJtYGpJkzQhCf2BK2YDjxxgTeH0VCIqyPd3z5/ 7eUIVFx77HK5i1MkrOyKpmMUHVYtHuF6fgSDF/cFjfS35o+tJF14rGfb/+G62Gj8 xr6HTr704NwsBNJc6AGOW3aNpqJXw7P6+8eMAeDCvSs6GF1HHVI= =m4f5 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds