Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 30 Apr 2026 15:04:15 +0000
From:      Dag-Erling=?utf-8?Q? Sm=C3=B8rg?=rav <des@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: 5bb9cd154dfa - stable/15 - caroot: Regenerate
Message-ID:  <69f36f6f.18646.6fcbdce8@gitrepo.freebsd.org>

index | next in thread | raw e-mail

The branch stable/15 has been updated by des:

URL: https://cgit.FreeBSD.org/src/commit/?id=5bb9cd154dfacd3e8dfa5404d134c476836b0e74

commit 5bb9cd154dfacd3e8dfa5404d134c476836b0e74
Author:     Dag-Erling Smørgrav <des@FreeBSD.org>
AuthorDate: 2026-04-27 09:32:51 +0000
Commit:     Dag-Erling Smørgrav <des@FreeBSD.org>
CommitDate: 2026-04-30 15:02:04 +0000

    caroot: Regenerate
    
    Regenerate using certificate data from NSS 3.123.1.
    
    MFC after:      1 week
    Reviewed by:    kevans
    
    (cherry picked from commit 07b52233e8b74c5ac884b9c9a894f57fad8dbd00)
---
 ObsoleteFiles.inc                                  |  74 ++++++++++
 secure/caroot/Makefile                             |   2 +-
 secure/caroot/trusted/AffirmTrust_Commercial.pem   |  88 ------------
 secure/caroot/trusted/AffirmTrust_Networking.pem   |  88 ------------
 secure/caroot/trusted/AffirmTrust_Premium.pem      | 130 ------------------
 secure/caroot/trusted/AffirmTrust_Premium_ECC.pem  |  62 ---------
 .../caroot/trusted/Baltimore_CyberTrust_Root.pem   |  89 ------------
 .../trusted/CommScope_Public_Trust_ECC_Root-01.pem |  64 ---------
 .../trusted/CommScope_Public_Trust_ECC_Root-02.pem |  64 ---------
 .../trusted/CommScope_Public_Trust_RSA_Root-01.pem | 131 ------------------
 .../trusted/CommScope_Public_Trust_RSA_Root-02.pem | 131 ------------------
 .../trusted/FIRMAPROFESIONAL_CA_ROOT-A_WEB.pem     |  68 ----------
 secure/caroot/trusted/GLOBALTRUST_2020.pem         | 134 ------------------
 secure/caroot/trusted/OISTE_Server_Root_ECC_G1.pem |  66 +++++++++
 secure/caroot/trusted/OISTE_Server_Root_RSA_G1.pem | 134 ++++++++++++++++++
 secure/caroot/trusted/SecureTrust_CA.pem           |  99 --------------
 secure/caroot/trusted/Secure_Global_CA.pem         |  99 --------------
 .../trusted/SwissSign_RSA_TLS_Root_CA_2022_-_1.pem | 134 ++++++++++++++++++
 secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem   | 130 ------------------
 .../caroot/trusted/TrustAsia_TLS_ECC_Root_CA.pem   |  64 +++++++++
 .../caroot/trusted/TrustAsia_TLS_RSA_Root_CA.pem   | 132 ++++++++++++++++++
 .../Trustwave_Global_Certification_Authority.pem   | 134 ------------------
 ...ave_Global_ECC_P256_Certification_Authority.pem |  61 ---------
 ...ave_Global_ECC_P384_Certification_Authority.pem |  67 ---------
 secure/caroot/trusted/XRamp_Global_CA_Root.pem     | 102 --------------
 secure/caroot/trusted/certSIGN_ROOT_CA.pem         |  88 ------------
 .../caroot/trusted/e-Szigno_TLS_Root_CA_2023.pem   |  74 ++++++++++
 .../Atos_TrustedRoot_Root_CA_ECC_G2_2020.pem       |  66 +++++++++
 .../Atos_TrustedRoot_Root_CA_RSA_G2_2020.pem       | 134 ++++++++++++++++++
 .../COMODO_Certification_Authority.pem             |   0
 .../Camerfirma_Chambers_of_Commerce_Root.pem       | 109 ---------------
 .../Camerfirma_Global_Chambersign_Root.pem         | 109 ---------------
 secure/caroot/{trusted => untrusted}/Certigna.pem  |   0
 .../untrusted/Chambers_of_Commerce_Root_-_2008.pem | 149 ---------------------
 .../Comodo_AAA_Services_root.pem                   |   0
 .../untrusted/D-Trust_SBR_Root_CA_1_2022.pem       |  69 ++++++++++
 .../untrusted/D-Trust_SBR_Root_CA_2_2022.pem       | 137 +++++++++++++++++++
 .../untrusted/DIGITALSIGN_GLOBAL_ROOT_ECDSA_CA.pem |  67 +++++++++
 .../untrusted/DIGITALSIGN_GLOBAL_ROOT_RSA_CA.pem   | 135 +++++++++++++++++++
 .../DigiCert_Assured_ID_Root_CA.pem                |   0
 .../DigiCert_Global_Root_CA.pem                    |   0
 .../DigiCert_High_Assurance_EV_Root_CA.pem         |   0
 .../untrusted/DigiCert_SMIME_ECC_P384_Root_G5.pem  |  64 +++++++++
 .../untrusted/DigiCert_SMIME_RSA4096_Root_G5.pem   | 131 ++++++++++++++++++
 .../untrusted/E-Tugra_Global_Root_CA_ECC_v3.pem    |  69 ----------
 .../untrusted/E-Tugra_Global_Root_CA_RSA_v3.pem    | 136 -------------------
 secure/caroot/untrusted/EC-ACC.pem                 | 107 ---------------
 .../untrusted/EE_Certification_Centre_Root_CA.pem  |  95 -------------
 .../Entrust_Root_Certification_Authority.pem       |   0
 .../Entrust_Root_Certification_Authority_-_EC1.pem |   0
 .../Entrust_Root_Certification_Authority_-_G2.pem  |   0
 .../Entrust_net_Premium_2048_Secure_Server_CA.pem  |   0
 .../caroot/{trusted => untrusted}/GTS_Root_R2.pem  |   0
 .../GeoTrust_Primary_Certification_Authority.pem   |  90 -------------
 ...oTrust_Primary_Certification_Authority_-_G2.pem |  67 ---------
 ...oTrust_Primary_Certification_Authority_-_G3.pem |  93 -------------
 secure/caroot/untrusted/GeoTrust_Universal_CA.pem  | 132 ------------------
 .../caroot/untrusted/GeoTrust_Universal_CA_2.pem   | 132 ------------------
 .../{trusted => untrusted}/GlobalSign_Root_CA.pem  |   0
 .../untrusted/GlobalSign_Secure_Mail_Root_E45.pem  |  64 +++++++++
 .../untrusted/GlobalSign_Secure_Mail_Root_R45.pem  | 132 ++++++++++++++++++
 .../untrusted/Global_Chambersign_Root_-_2008.pem   | 148 --------------------
 .../{trusted => untrusted}/Go_Daddy_Class_2_CA.pem |   0
 .../untrusted/HARICA_Client_ECC_Root_CA_2021.pem   |  65 +++++++++
 .../untrusted/HARICA_Client_RSA_Root_CA_2021.pem   | 133 ++++++++++++++++++
 ...demic_and_Research_Institutions_RootCA_2011.pem | 103 --------------
 .../caroot/untrusted/LAWtrust_Root_CA2__4096_.pem  | 135 +++++++++++++++++++
 secure/caroot/untrusted/LuxTrust_Global_Root_2.pem | 138 -------------------
 .../Network_Solutions_Certificate_Authority.pem    |  96 -------------
 .../caroot/untrusted/OISTE_Client_Root_ECC_G1.pem  |  66 +++++++++
 .../caroot/untrusted/OISTE_Client_Root_RSA_G1.pem  | 134 ++++++++++++++++++
 .../{trusted => untrusted}/QuoVadis_Root_CA_2.pem  |   0
 .../{trusted => untrusted}/QuoVadis_Root_CA_3.pem  |   0
 .../untrusted/SSL_com_Client_ECC_Root_CA_2022.pem  |  67 +++++++++
 .../untrusted/SSL_com_Client_RSA_Root_CA_2022.pem  | 134 ++++++++++++++++++
 .../Sectigo_Public_Email_Protection_Root_E46.pem   |  64 +++++++++
 .../Sectigo_Public_Email_Protection_Root_R46.pem   | 132 ++++++++++++++++++
 secure/caroot/untrusted/SecureSign_RootCA11.pem    |  89 ------------
 .../untrusted/Security_Communication_RootCA3.pem   | 132 ------------------
 .../Starfield_Class_2_CA.pem                       |   0
 .../SwissSign_Gold_CA_-_G2.pem                     |   0
 .../untrusted/SwissSign_Platinum_CA_-_G2.pem       | 137 -------------------
 .../SwissSign_RSA_SMIME_Root_CA_2022_-_1.pem       | 134 ++++++++++++++++++
 .../caroot/untrusted/SwissSign_Silver_CA_-_G2.pem  | 137 -------------------
 ...Public_Primary_Certification_Authority_-_G4.pem |  67 ---------
 ...Public_Primary_Certification_Authority_-_G6.pem |  93 -------------
 ...Public_Primary_Certification_Authority_-_G4.pem |  67 ---------
 ...Public_Primary_Certification_Authority_-_G6.pem |  93 -------------
 secure/caroot/untrusted/TWCA_Global_Root_CA_G2.pem | 134 ++++++++++++++++++
 secure/caroot/untrusted/Taiwan_GRCA.pem            | 132 ------------------
 .../Telekom_Security_SMIME_ECC_Root_2021.pem       |  65 +++++++++
 .../Telekom_Security_SMIME_RSA_Root_2023.pem       | 135 +++++++++++++++++++
 .../untrusted/TrustAsia_SMIME_ECC_Root_CA.pem      |  64 +++++++++
 .../untrusted/TrustAsia_SMIME_RSA_Root_CA.pem      | 132 ++++++++++++++++++
 secure/caroot/untrusted/TrustCor_ECA-1.pem         |  96 -------------
 secure/caroot/untrusted/TrustCor_RootCert_CA-1.pem |  96 -------------
 secure/caroot/untrusted/TrustCor_RootCert_CA-2.pem | 137 -------------------
 ...Public_Primary_Certification_Authority_-_G4.pem |  73 ----------
 ...Public_Primary_Certification_Authority_-_G5.pem |  99 --------------
 ...Sign_Universal_Root_Certification_Authority.pem |  99 --------------
 ...Public_Primary_Certification_Authority_-_G3.pem |  86 ------------
 ...Public_Primary_Certification_Authority_-_G3.pem |  86 ------------
 ...Public_Primary_Certification_Authority_-_G3.pem |  86 ------------
 secure/caroot/untrusted/thawte_Primary_Root_CA.pem |  94 -------------
 .../untrusted/thawte_Primary_Root_CA_-_G2.pem      |  66 ---------
 .../untrusted/thawte_Primary_Root_CA_-_G3.pem      |  94 -------------
 106 files changed, 3272 insertions(+), 5662 deletions(-)

diff --git a/ObsoleteFiles.inc b/ObsoleteFiles.inc
index 661cdd3884a0..d8090aa28cc7 100644
--- a/ObsoleteFiles.inc
+++ b/ObsoleteFiles.inc
@@ -51,6 +51,80 @@
 #   xargs -n1 | sort | uniq -d;
 # done
 
+# 20260430: Regenerate trust store
+OLD_FILES+=usr/share/certs/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
+OLD_FILES+=usr/share/certs/trusted/AffirmTrust_Premium.pem
+OLD_FILES+=usr/share/certs/trusted/Starfield_Class_2_CA.pem
+OLD_FILES+=usr/share/certs/trusted/GTS_Root_R2.pem
+OLD_FILES+=usr/share/certs/trusted/GLOBALTRUST_2020.pem
+OLD_FILES+=usr/share/certs/trusted/Secure_Global_CA.pem
+OLD_FILES+=usr/share/certs/trusted/GlobalSign_Root_CA.pem
+OLD_FILES+=usr/share/certs/trusted/CommScope_Public_Trust_RSA_Root-01.pem
+OLD_FILES+=usr/share/certs/trusted/Trustwave_Global_ECC_P384_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/SwissSign_Gold_CA_-_G2.pem
+OLD_FILES+=usr/share/certs/trusted/Go_Daddy_Class_2_CA.pem
+OLD_FILES+=usr/share/certs/trusted/FIRMAPROFESIONAL_CA_ROOT-A_WEB.pem
+OLD_FILES+=usr/share/certs/trusted/Trustwave_Global_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/Trustwave_Global_ECC_P256_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/CommScope_Public_Trust_ECC_Root-01.pem
+OLD_FILES+=usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
+OLD_FILES+=usr/share/certs/trusted/Certigna.pem
+OLD_FILES+=usr/share/certs/trusted/AffirmTrust_Commercial.pem
+OLD_FILES+=usr/share/certs/trusted/DigiCert_Assured_ID_Root_CA.pem
+OLD_FILES+=usr/share/certs/trusted/Baltimore_CyberTrust_Root.pem
+OLD_FILES+=usr/share/certs/trusted/CommScope_Public_Trust_ECC_Root-02.pem
+OLD_FILES+=usr/share/certs/trusted/Entrust_Root_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/AffirmTrust_Premium_ECC.pem
+OLD_FILES+=usr/share/certs/trusted/CommScope_Public_Trust_RSA_Root-02.pem
+OLD_FILES+=usr/share/certs/trusted/TeliaSonera_Root_CA_v1.pem
+OLD_FILES+=usr/share/certs/trusted/QuoVadis_Root_CA_2.pem
+OLD_FILES+=usr/share/certs/trusted/COMODO_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/SecureTrust_CA.pem
+OLD_FILES+=usr/share/certs/trusted/Comodo_AAA_Services_root.pem
+OLD_FILES+=usr/share/certs/trusted/Entrust_Root_Certification_Authority_-_G2.pem
+OLD_FILES+=usr/share/certs/trusted/QuoVadis_Root_CA_3.pem
+OLD_FILES+=usr/share/certs/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
+OLD_FILES+=usr/share/certs/trusted/certSIGN_ROOT_CA.pem
+OLD_FILES+=usr/share/certs/trusted/DigiCert_Global_Root_CA.pem
+OLD_FILES+=usr/share/certs/trusted/AffirmTrust_Networking.pem
+OLD_FILES+=usr/share/certs/trusted/XRamp_Global_CA_Root.pem
+OLD_FILES+=usr/share/certs/untrusted/Security_Communication_RootCA3.pem
+OLD_FILES+=usr/share/certs/untrusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
+OLD_FILES+=usr/share/certs/untrusted/E-Tugra_Global_Root_CA_ECC_v3.pem
+OLD_FILES+=usr/share/certs/untrusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
+OLD_FILES+=usr/share/certs/untrusted/EE_Certification_Centre_Root_CA.pem
+OLD_FILES+=usr/share/certs/untrusted/EC-ACC.pem
+OLD_FILES+=usr/share/certs/untrusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
+OLD_FILES+=usr/share/certs/untrusted/GeoTrust_Universal_CA.pem
+OLD_FILES+=usr/share/certs/untrusted/Global_Chambersign_Root_-_2008.pem
+OLD_FILES+=usr/share/certs/untrusted/Camerfirma_Global_Chambersign_Root.pem
+OLD_FILES+=usr/share/certs/untrusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
+OLD_FILES+=usr/share/certs/untrusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
+OLD_FILES+=usr/share/certs/untrusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
+OLD_FILES+=usr/share/certs/untrusted/TrustCor_RootCert_CA-2.pem
+OLD_FILES+=usr/share/certs/untrusted/GeoTrust_Universal_CA_2.pem
+OLD_FILES+=usr/share/certs/untrusted/Network_Solutions_Certificate_Authority.pem
+OLD_FILES+=usr/share/certs/untrusted/thawte_Primary_Root_CA.pem
+OLD_FILES+=usr/share/certs/untrusted/E-Tugra_Global_Root_CA_RSA_v3.pem
+OLD_FILES+=usr/share/certs/untrusted/GeoTrust_Primary_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/untrusted/Taiwan_GRCA.pem
+OLD_FILES+=usr/share/certs/untrusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
+OLD_FILES+=usr/share/certs/untrusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
+OLD_FILES+=usr/share/certs/untrusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
+OLD_FILES+=usr/share/certs/untrusted/SwissSign_Platinum_CA_-_G2.pem
+OLD_FILES+=usr/share/certs/untrusted/TrustCor_RootCert_CA-1.pem
+OLD_FILES+=usr/share/certs/untrusted/thawte_Primary_Root_CA_-_G3.pem
+OLD_FILES+=usr/share/certs/untrusted/Camerfirma_Chambers_of_Commerce_Root.pem
+OLD_FILES+=usr/share/certs/untrusted/SwissSign_Silver_CA_-_G2.pem
+OLD_FILES+=usr/share/certs/untrusted/TrustCor_ECA-1.pem
+OLD_FILES+=usr/share/certs/untrusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
+OLD_FILES+=usr/share/certs/untrusted/SecureSign_RootCA11.pem
+OLD_FILES+=usr/share/certs/untrusted/Chambers_of_Commerce_Root_-_2008.pem
+OLD_FILES+=usr/share/certs/untrusted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
+OLD_FILES+=usr/share/certs/untrusted/VeriSign_Universal_Root_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/untrusted/LuxTrust_Global_Root_2.pem
+OLD_FILES+=usr/share/certs/untrusted/thawte_Primary_Root_CA_-_G2.pem
+OLD_FILES+=usr/share/certs/untrusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
 
 # 20260402: posix_spawn_file_actions_addchdir lost _np suffix
 OLD_FILES+=usr/share/man/man3/posix_spawn_file_actions_addchdir_np.3.gz
diff --git a/secure/caroot/Makefile b/secure/caroot/Makefile
index c20499e52a76..fa4119034dd9 100644
--- a/secure/caroot/Makefile
+++ b/secure/caroot/Makefile
@@ -7,7 +7,7 @@ SUBDIR+=	untrusted
 
 # Set this to an upstream hash or tag
 # https://hg-edge.mozilla.org/projects/nss/tags
-HGVER = e71e3de47d4ca7a3efa7c11096ab2e20ae71683e
+HGVER = NSS_3_123_1_RTM
 
 # To be used by secteam@ to update the trusted certificates
 fetchcerts: .PHONY
diff --git a/secure/caroot/trusted/AffirmTrust_Commercial.pem b/secure/caroot/trusted/AffirmTrust_Commercial.pem
deleted file mode 100644
index b889d02ba6b7..000000000000
--- a/secure/caroot/trusted/AffirmTrust_Commercial.pem
+++ /dev/null
@@ -1,88 +0,0 @@
-##
-##  AffirmTrust Commercial
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number: 8608355977964138876 (0x7777062726a9b17c)
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Commercial
-        Validity
-            Not Before: Jan 29 14:06:06 2010 GMT
-            Not After : Dec 31 14:06:06 2030 GMT
-        Subject: C=US, O=AffirmTrust, CN=AffirmTrust Commercial
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (2048 bit)
-                Modulus:
-                    00:f6:1b:4f:67:07:2b:a1:15:f5:06:22:cb:1f:01:
-                    b2:e3:73:45:06:44:49:2c:bb:49:25:14:d6:ce:c3:
-                    b7:ab:2c:4f:c6:41:32:94:57:fa:12:a7:5b:0e:e2:
-                    8f:1f:1e:86:19:a7:aa:b5:2d:b9:5f:0d:8a:c2:af:
-                    85:35:79:32:2d:bb:1c:62:37:f2:b1:5b:4a:3d:ca:
-                    cd:71:5f:e9:42:be:94:e8:c8:de:f9:22:48:64:c6:
-                    e5:ab:c6:2b:6d:ad:05:f0:fa:d5:0b:cf:9a:e5:f0:
-                    50:a4:8b:3b:47:a5:23:5b:7a:7a:f8:33:3f:b8:ef:
-                    99:97:e3:20:c1:d6:28:89:cf:94:fb:b9:45:ed:e3:
-                    40:17:11:d4:74:f0:0b:31:e2:2b:26:6a:9b:4c:57:
-                    ae:ac:20:3e:ba:45:7a:05:f3:bd:9b:69:15:ae:7d:
-                    4e:20:63:c4:35:76:3a:07:02:c9:37:fd:c7:47:ee:
-                    e8:f1:76:1d:73:15:f2:97:a4:b5:c8:7a:79:d9:42:
-                    aa:2b:7f:5c:fe:ce:26:4f:a3:66:81:35:af:44:ba:
-                    54:1e:1c:30:32:65:9d:e6:3c:93:5e:50:4e:7a:e3:
-                    3a:d4:6e:cc:1a:fb:f9:d2:37:ae:24:2a:ab:57:03:
-                    22:28:0d:49:75:7f:b7:28:da:75:bf:8e:e3:dc:0e:
-                    79:31
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Subject Key Identifier: 
-                9D:93:C6:53:8B:5E:CA:AF:3F:9F:1E:0F:E5:99:95:BC:24:F6:94:8F
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-    Signature Algorithm: sha256WithRSAEncryption
-    Signature Value:
-        58:ac:f4:04:0e:cd:c0:0d:ff:0a:fd:d4:ba:16:5f:29:bd:7b:
-        68:99:58:49:d2:b4:1d:37:4d:7f:27:7d:46:06:5d:43:c6:86:
-        2e:3e:73:b2:26:7d:4f:93:a9:b6:c4:2a:9a:ab:21:97:14:b1:
-        de:8c:d3:ab:89:15:d8:6b:24:d4:f1:16:ae:d8:a4:5c:d4:7f:
-        51:8e:ed:18:01:b1:93:63:bd:bc:f8:61:80:9a:9e:b1:ce:42:
-        70:e2:a9:7d:06:25:7d:27:a1:fe:6f:ec:b3:1e:24:da:e3:4b:
-        55:1a:00:3b:35:b4:3b:d9:d7:5d:30:fd:81:13:89:f2:c2:06:
-        2b:ed:67:c4:8e:c9:43:b2:5c:6b:15:89:02:bc:62:fc:4e:f2:
-        b5:33:aa:b2:6f:d3:0a:a2:50:e3:f6:3b:e8:2e:44:c2:db:66:
-        38:a9:33:56:48:f1:6d:1b:33:8d:0d:8c:3f:60:37:9d:d3:ca:
-        6d:7e:34:7e:0d:9f:72:76:8b:1b:9f:72:fd:52:35:41:45:02:
-        96:2f:1c:b2:9a:73:49:21:b1:49:47:45:47:b4:ef:6a:34:11:
-        c9:4d:9a:cc:59:b7:d6:02:9e:5a:4e:65:b5:94:ae:1b:df:29:
-        b0:16:f1:bf:00:9e:07:3a:17:64:b5:04:b5:23:21:99:0a:95:
-        3b:97:7c:ef
-SHA1 Fingerprint=F9:B5:B6:32:45:5F:9C:BE:EC:57:5F:80:DC:E9:6E:2C:C7:B2:78:B7
------BEGIN CERTIFICATE-----
-MIIDTDCCAjSgAwIBAgIId3cGJyapsXwwDQYJKoZIhvcNAQELBQAwRDELMAkGA1UE
-BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZpcm1UcnVz
-dCBDb21tZXJjaWFsMB4XDTEwMDEyOTE0MDYwNloXDTMwMTIzMTE0MDYwNlowRDEL
-MAkGA1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZp
-cm1UcnVzdCBDb21tZXJjaWFsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
-AQEA9htPZwcroRX1BiLLHwGy43NFBkRJLLtJJRTWzsO3qyxPxkEylFf6EqdbDuKP
-Hx6GGaeqtS25Xw2Kwq+FNXkyLbscYjfysVtKPcrNcV/pQr6U6Mje+SJIZMblq8Yr
-ba0F8PrVC8+a5fBQpIs7R6UjW3p6+DM/uO+Zl+MgwdYoic+U+7lF7eNAFxHUdPAL
-MeIrJmqbTFeurCA+ukV6BfO9m2kVrn1OIGPENXY6BwLJN/3HR+7o8XYdcxXyl6S1
-yHp52UKqK39c/s4mT6NmgTWvRLpUHhwwMmWd5jyTXlBOeuM61G7MGvv50jeuJCqr
-VwMiKA1JdX+3KNp1v47j3A55MQIDAQABo0IwQDAdBgNVHQ4EFgQUnZPGU4teyq8/
-nx4P5ZmVvCT2lI8wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwDQYJ
-KoZIhvcNAQELBQADggEBAFis9AQOzcAN/wr91LoWXym9e2iZWEnStB03TX8nfUYG
-XUPGhi4+c7ImfU+TqbbEKpqrIZcUsd6M06uJFdhrJNTxFq7YpFzUf1GO7RgBsZNj
-vbz4YYCanrHOQnDiqX0GJX0nof5v7LMeJNrjS1UaADs1tDvZ110w/YETifLCBivt
-Z8SOyUOyXGsViQK8YvxO8rUzqrJv0wqiUOP2O+guRMLbZjipM1ZI8W0bM40NjD9g
-N53Tym1+NH4Nn3J2ixufcv1SNUFFApYvHLKac0khsUlHRUe072o0EclNmsxZt9YC
-nlpOZbWUrhvfKbAW8b8Angc6F2S1BLUjIZkKlTuXfO8=
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/AffirmTrust_Networking.pem b/secure/caroot/trusted/AffirmTrust_Networking.pem
deleted file mode 100644
index e4a201bc82ae..000000000000
--- a/secure/caroot/trusted/AffirmTrust_Networking.pem
+++ /dev/null
@@ -1,88 +0,0 @@
-##
-##  AffirmTrust Networking
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number: 8957382827206547757 (0x7c4f04391cd4992d)
-        Signature Algorithm: sha1WithRSAEncryption
-        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Networking
-        Validity
-            Not Before: Jan 29 14:08:24 2010 GMT
-            Not After : Dec 31 14:08:24 2030 GMT
-        Subject: C=US, O=AffirmTrust, CN=AffirmTrust Networking
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (2048 bit)
-                Modulus:
-                    00:b4:84:cc:33:17:2e:6b:94:6c:6b:61:52:a0:eb:
-                    a3:cf:79:94:4c:e5:94:80:99:cb:55:64:44:65:8f:
-                    67:64:e2:06:e3:5c:37:49:f6:2f:9b:84:84:1e:2d:
-                    f2:60:9d:30:4e:cc:84:85:e2:2c:cf:1e:9e:fe:36:
-                    ab:33:77:35:44:d8:35:96:1a:3d:36:e8:7a:0e:d8:
-                    d5:47:a1:6a:69:8b:d9:fc:bb:3a:ae:79:5a:d5:f4:
-                    d6:71:bb:9a:90:23:6b:9a:b7:88:74:87:0c:1e:5f:
-                    b9:9e:2d:fa:ab:53:2b:dc:bb:76:3e:93:4c:08:08:
-                    8c:1e:a2:23:1c:d4:6a:ad:22:ba:99:01:2e:6d:65:
-                    cb:be:24:66:55:24:4b:40:44:b1:1b:d7:e1:c2:85:
-                    c0:de:10:3f:3d:ed:b8:fc:f1:f1:23:53:dc:bf:65:
-                    97:6f:d9:f9:40:71:8d:7d:bd:95:d4:ce:be:a0:5e:
-                    27:23:de:fd:a6:d0:26:0e:00:29:eb:3c:46:f0:3d:
-                    60:bf:3f:50:d2:dc:26:41:51:9e:14:37:42:04:a3:
-                    70:57:a8:1b:87:ed:2d:fa:7b:ee:8c:0a:e3:a9:66:
-                    89:19:cb:41:f9:dd:44:36:61:cf:e2:77:46:c8:7d:
-                    f6:f4:92:81:36:fd:db:34:f1:72:7e:f3:0c:16:bd:
-                    b4:15
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Subject Key Identifier: 
-                07:1F:D2:E7:9C:DA:C2:6E:A2:40:B4:B0:7A:50:10:50:74:C4:C8:BD
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-    Signature Algorithm: sha1WithRSAEncryption
-    Signature Value:
-        89:57:b2:16:7a:a8:c2:fd:d6:d9:9b:9b:34:c2:9c:b4:32:14:
-        4d:a7:a4:df:ec:be:a7:be:f8:43:db:91:37:ce:b4:32:2e:50:
-        55:1a:35:4e:76:43:71:20:ef:93:77:4e:15:70:2e:87:c3:c1:
-        1d:6d:dc:cb:b5:27:d4:2c:56:d1:52:53:3a:44:d2:73:c8:c4:
-        1b:05:65:5a:62:92:9c:ee:41:8d:31:db:e7:34:ea:59:21:d5:
-        01:7a:d7:64:b8:64:39:cd:c9:ed:af:ed:4b:03:48:a7:a0:99:
-        01:80:dc:65:a3:36:ae:65:59:48:4f:82:4b:c8:65:f1:57:1d:
-        e5:59:2e:0a:3f:6c:d8:d1:f5:e5:09:b4:6c:54:00:0a:e0:15:
-        4d:87:75:6d:b7:58:96:5a:dd:6d:d2:00:a0:f4:9b:48:be:c3:
-        37:a4:ba:36:e0:7c:87:85:97:1a:15:a2:de:2e:a2:5b:bd:af:
-        18:f9:90:50:cd:70:59:f8:27:67:47:cb:c7:a0:07:3a:7d:d1:
-        2c:5d:6c:19:3a:66:b5:7d:fd:91:6f:82:b1:be:08:93:db:14:
-        47:f1:a2:37:c7:45:9e:3c:c7:77:af:64:a8:93:df:f6:69:83:
-        82:60:f2:49:42:34:ed:5a:00:54:85:1c:16:36:92:0c:5c:fa:
-        a6:ad:bf:db
-SHA1 Fingerprint=29:36:21:02:8B:20:ED:02:F5:66:C5:32:D1:D6:ED:90:9F:45:00:2F
------BEGIN CERTIFICATE-----
-MIIDTDCCAjSgAwIBAgIIfE8EORzUmS0wDQYJKoZIhvcNAQEFBQAwRDELMAkGA1UE
-BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZpcm1UcnVz
-dCBOZXR3b3JraW5nMB4XDTEwMDEyOTE0MDgyNFoXDTMwMTIzMTE0MDgyNFowRDEL
-MAkGA1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZp
-cm1UcnVzdCBOZXR3b3JraW5nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
-AQEAtITMMxcua5Rsa2FSoOujz3mUTOWUgJnLVWREZY9nZOIG41w3SfYvm4SEHi3y
-YJ0wTsyEheIszx6e/jarM3c1RNg1lho9Nuh6DtjVR6FqaYvZ/Ls6rnla1fTWcbua
-kCNrmreIdIcMHl+5ni36q1Mr3Lt2PpNMCAiMHqIjHNRqrSK6mQEubWXLviRmVSRL
-QESxG9fhwoXA3hA/Pe24/PHxI1Pcv2WXb9n5QHGNfb2V1M6+oF4nI979ptAmDgAp
-6zxG8D1gvz9Q0twmQVGeFDdCBKNwV6gbh+0t+nvujArjqWaJGctB+d1ENmHP4ndG
-yH329JKBNv3bNPFyfvMMFr20FQIDAQABo0IwQDAdBgNVHQ4EFgQUBx/S55zawm6i
-QLSwelAQUHTEyL0wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwDQYJ
-KoZIhvcNAQEFBQADggEBAIlXshZ6qML91tmbmzTCnLQyFE2npN/svqe++EPbkTfO
-tDIuUFUaNU52Q3Eg75N3ThVwLofDwR1t3Mu1J9QsVtFSUzpE0nPIxBsFZVpikpzu
-QY0x2+c06lkh1QF612S4ZDnNye2v7UsDSKegmQGA3GWjNq5lWUhPgkvIZfFXHeVZ
-Lgo/bNjR9eUJtGxUAArgFU2HdW23WJZa3W3SAKD0m0i+wzekujbgfIeFlxoVot4u
-olu9rxj5kFDNcFn4J2dHy8egBzp90SxdbBk6ZrV9/ZFvgrG+CJPbFEfxojfHRZ48
-x3evZKiT3/Zpg4Jg8klCNO1aAFSFHBY2kgxc+qatv9s=
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/AffirmTrust_Premium.pem b/secure/caroot/trusted/AffirmTrust_Premium.pem
deleted file mode 100644
index 853f7dc0e2d3..000000000000
--- a/secure/caroot/trusted/AffirmTrust_Premium.pem
+++ /dev/null
@@ -1,130 +0,0 @@
-##
-##  AffirmTrust Premium
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number: 7893706540734352110 (0x6d8c1446b1a60aee)
-        Signature Algorithm: sha384WithRSAEncryption
-        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Premium
-        Validity
-            Not Before: Jan 29 14:10:36 2010 GMT
-            Not After : Dec 31 14:10:36 2040 GMT
-        Subject: C=US, O=AffirmTrust, CN=AffirmTrust Premium
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (4096 bit)
-                Modulus:
-                    00:c4:12:df:a9:5f:fe:41:dd:dd:f5:9f:8a:e3:f6:
-                    ac:e1:3c:78:9a:bc:d8:f0:7f:7a:a0:33:2a:dc:8d:
-                    20:5b:ae:2d:6f:e7:93:d9:36:70:6a:68:cf:8e:51:
-                    a3:85:5b:67:04:a0:10:24:6f:5d:28:82:c1:97:57:
-                    d8:48:29:13:b6:e1:be:91:4d:df:85:0c:53:18:9a:
-                    1e:24:a2:4f:8f:f0:a2:85:0b:cb:f4:29:7f:d2:a4:
-                    58:ee:26:4d:c9:aa:a8:7b:9a:d9:fa:38:de:44:57:
-                    15:e5:f8:8c:c8:d9:48:e2:0d:16:27:1d:1e:c8:83:
-                    85:25:b7:ba:aa:55:41:cc:03:22:4b:2d:91:8d:8b:
-                    e6:89:af:66:c7:e9:ff:2b:e9:3c:ac:da:d2:b3:c3:
-                    e1:68:9c:89:f8:7a:00:56:de:f4:55:95:6c:fb:ba:
-                    64:dd:62:8b:df:0b:77:32:eb:62:cc:26:9a:9b:bb:
-                    aa:62:83:4c:b4:06:7a:30:c8:29:bf:ed:06:4d:97:
-                    b9:1c:c4:31:2b:d5:5f:bc:53:12:17:9c:99:57:29:
-                    66:77:61:21:31:07:2e:25:49:9d:18:f2:ee:f3:2b:
-                    71:8c:b5:ba:39:07:49:77:fc:ef:2e:92:90:05:8d:
-                    2d:2f:77:7b:ef:43:bf:35:bb:9a:d8:f9:73:a7:2c:
-                    f2:d0:57:ee:28:4e:26:5f:8f:90:68:09:2f:b8:f8:
-                    dc:06:e9:2e:9a:3e:51:a7:d1:22:c4:0a:a7:38:48:
-                    6c:b3:f9:ff:7d:ab:86:57:e3:ba:d6:85:78:77:ba:
-                    43:ea:48:7f:f6:d8:be:23:6d:1e:bf:d1:36:6c:58:
-                    5c:f1:ee:a4:19:54:1a:f5:03:d2:76:e6:e1:8c:bd:
-                    3c:b3:d3:48:4b:e2:c8:f8:7f:92:a8:76:46:9c:42:
-                    65:3e:a4:1e:c1:07:03:5a:46:2d:b8:97:f3:b7:d5:
-                    b2:55:21:ef:ba:dc:4c:00:97:fb:14:95:27:33:bf:
-                    e8:43:47:46:d2:08:99:16:60:3b:9a:7e:d2:e6:ed:
-                    38:ea:ec:01:1e:3c:48:56:49:09:c7:4c:37:00:9e:
-                    88:0e:c0:73:e1:6f:66:e9:72:47:30:3e:10:e5:0b:
-                    03:c9:9a:42:00:6c:c5:94:7e:61:c4:8a:df:7f:82:
-                    1a:0b:59:c4:59:32:77:b3:bc:60:69:56:39:fd:b4:
-                    06:7b:2c:d6:64:36:d9:bd:48:ed:84:1f:7e:a5:22:
-                    8f:2a:b8:42:f4:82:b7:d4:53:90:78:4e:2d:1a:fd:
-                    81:6f:44:d7:3b:01:74:96:42:e0:00:e2:2e:6b:ea:
-                    c5:ee:72:ac:bb:bf:fe:ea:aa:a8:f8:dc:f6:b2:79:
-                    8a:b6:67
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Subject Key Identifier: 
-                9D:C0:67:A6:0C:22:D9:26:F5:45:AB:A6:65:52:11:27:D8:45:AC:63
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-    Signature Algorithm: sha384WithRSAEncryption
-    Signature Value:
-        b3:57:4d:10:62:4e:3a:e4:ac:ea:b8:1c:af:32:23:c8:b3:49:
-        5a:51:9c:76:28:8d:79:aa:57:46:17:d5:f5:52:f6:b7:44:e8:
-        08:44:bf:18:84:d2:0b:80:cd:c5:12:fd:00:55:05:61:87:41:
-        dc:b5:24:9e:3c:c4:d8:c8:fb:70:9e:2f:78:96:83:20:36:de:
-        7c:0f:69:13:88:a5:75:36:98:08:a6:c6:df:ac:ce:e3:58:d6:
-        b7:3e:de:ba:f3:eb:34:40:d8:a2:81:f5:78:3f:2f:d5:a5:fc:
-        d9:a2:d4:5e:04:0e:17:ad:fe:41:f0:e5:b2:72:fa:44:82:33:
-        42:e8:2d:58:f7:56:8c:62:3f:ba:42:b0:9c:0c:5c:7e:2e:65:
-        26:5c:53:4f:00:b2:78:7e:a1:0d:99:2d:8d:b8:1d:8e:a2:c4:
-        b0:fd:60:d0:30:a4:8e:c8:04:62:a9:c4:ed:35:de:7a:97:ed:
-        0e:38:5e:92:2f:93:70:a5:a9:9c:6f:a7:7d:13:1d:7e:c6:08:
-        48:b1:5e:67:eb:51:08:25:e9:e6:25:6b:52:29:91:9c:d2:39:
-        73:08:57:de:99:06:b4:5b:9d:10:06:e1:c2:00:a8:b8:1c:4a:
-        02:0a:14:d0:c1:41:ca:fb:8c:35:21:7d:82:38:f2:a9:54:91:
-        19:35:93:94:6d:6a:3a:c5:b2:d0:bb:89:86:93:e8:9b:c9:0f:
-        3a:a7:7a:b8:a1:f0:78:46:fa:fc:37:2f:e5:8a:84:f3:df:fe:
-        04:d9:a1:68:a0:2f:24:e2:09:95:06:d5:95:ca:e1:24:96:eb:
-        7c:f6:93:05:bb:ed:73:e9:2d:d1:75:39:d7:e7:24:db:d8:4e:
-        5f:43:8f:9e:d0:14:39:bf:55:70:48:99:57:31:b4:9c:ee:4a:
-        98:03:96:30:1f:60:06:ee:1b:23:fe:81:60:23:1a:47:62:85:
-        a5:cc:19:34:80:6f:b3:ac:1a:e3:9f:f0:7b:48:ad:d5:01:d9:
-        67:b6:a9:72:93:ea:2d:66:b5:b2:b8:e4:3d:3c:b2:ef:4c:8c:
-        ea:eb:07:bf:ab:35:9a:55:86:bc:18:a6:b5:a8:5e:b4:83:6c:
-        6b:69:40:d3:9f:dc:f1:c3:69:6b:b9:e1:6d:09:f4:f1:aa:50:
-        76:0a:7a:7d:7a:17:a1:55:96:42:99:31:09:dd:60:11:8d:05:
-        30:7e:e6:8e:46:d1:9d:14:da:c7:17:e4:05:96:8c:c4:24:b5:
-        1b:cf:14:07:b2:40:f8:a3:9e:41:86:bc:04:d0:6b:96:c8:2a:
-        80:34:fd:bf:ef:06:a3:dd:58:c5:85:3d:3e:8f:fe:9e:29:e0:
-        b6:b8:09:68:19:1c:18:43
-SHA1 Fingerprint=D8:A6:33:2C:E0:03:6F:B1:85:F6:63:4F:7D:6A:06:65:26:32:28:27
------BEGIN CERTIFICATE-----
-MIIFRjCCAy6gAwIBAgIIbYwURrGmCu4wDQYJKoZIhvcNAQEMBQAwQTELMAkGA1UE
-BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MRwwGgYDVQQDDBNBZmZpcm1UcnVz
-dCBQcmVtaXVtMB4XDTEwMDEyOTE0MTAzNloXDTQwMTIzMTE0MTAzNlowQTELMAkG
-A1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MRwwGgYDVQQDDBNBZmZpcm1U
-cnVzdCBQcmVtaXVtMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxBLf
-qV/+Qd3d9Z+K4/as4Tx4mrzY8H96oDMq3I0gW64tb+eT2TZwamjPjlGjhVtnBKAQ
-JG9dKILBl1fYSCkTtuG+kU3fhQxTGJoeJKJPj/CihQvL9Cl/0qRY7iZNyaqoe5rZ
-+jjeRFcV5fiMyNlI4g0WJx0eyIOFJbe6qlVBzAMiSy2RjYvmia9mx+n/K+k8rNrS
-s8PhaJyJ+HoAVt70VZVs+7pk3WKL3wt3MutizCaam7uqYoNMtAZ6MMgpv+0GTZe5
-HMQxK9VfvFMSF5yZVylmd2EhMQcuJUmdGPLu8ytxjLW6OQdJd/zvLpKQBY0tL3d7
-70O/Nbua2Plzpyzy0FfuKE4mX4+QaAkvuPjcBukumj5Rp9EixAqnOEhss/n/fauG
-V+O61oV4d7pD6kh/9ti+I20ev9E2bFhc8e6kGVQa9QPSdubhjL08s9NIS+LI+H+S
-qHZGnEJlPqQewQcDWkYtuJfzt9WyVSHvutxMAJf7FJUnM7/oQ0dG0giZFmA7mn7S
-5u046uwBHjxIVkkJx0w3AJ6IDsBz4W9m6XJHMD4Q5QsDyZpCAGzFlH5hxIrff4Ia
-C1nEWTJ3s7xgaVY5/bQGeyzWZDbZvUjthB9+pSKPKrhC9IK31FOQeE4tGv2Bb0TX
-OwF0lkLgAOIua+rF7nKsu7/+6qqo+Nz2snmKtmcCAwEAAaNCMEAwHQYDVR0OBBYE
-FJ3AZ6YMItkm9UWrpmVSESfYRaxjMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/
-BAQDAgEGMA0GCSqGSIb3DQEBDAUAA4ICAQCzV00QYk465KzquByvMiPIs0laUZx2
-KI15qldGF9X1Uva3ROgIRL8YhNILgM3FEv0AVQVhh0HctSSePMTYyPtwni94loMg
-Nt58D2kTiKV1NpgIpsbfrM7jWNa3Pt668+s0QNiigfV4Py/VpfzZotReBA4Xrf5B
-8OWycvpEgjNC6C1Y91aMYj+6QrCcDFx+LmUmXFNPALJ4fqENmS2NuB2OosSw/WDQ
-MKSOyARiqcTtNd56l+0OOF6SL5Nwpamcb6d9Ex1+xghIsV5n61EIJenmJWtSKZGc
-0jlzCFfemQa0W50QBuHCAKi4HEoCChTQwUHK+4w1IX2COPKpVJEZNZOUbWo6xbLQ
-u4mGk+ibyQ86p3q4ofB4Rvr8Ny/lioTz3/4E2aFooC8k4gmVBtWVyuEklut89pMF
-u+1z6S3RdTnX5yTb2E5fQ4+e0BQ5v1VwSJlXMbSc7kqYA5YwH2AG7hsj/oFgIxpH
-YoWlzBk0gG+zrBrjn/B7SK3VAdlntqlyk+otZrWyuOQ9PLLvTIzq6we/qzWaVYa8
-GKa1qF60g2xraUDTn9zxw2lrueFtCfTxqlB2Cnp9ehehVZZCmTEJ3WARjQUwfuaO
-RtGdFNrHF+QFlozEJLUbzxQHskD4o55BhrwE0GuWyCqANP2/7waj3VjFhT0+j/6e
-KeC2uAloGRwYQw==
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem b/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
deleted file mode 100644
index 68ce02904f4f..000000000000
--- a/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
+++ /dev/null
@@ -1,62 +0,0 @@
-##
-##  AffirmTrust Premium ECC
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number: 8401224907861490260 (0x7497258ac73f7a54)
-        Signature Algorithm: ecdsa-with-SHA384
-        Issuer: C=US, O=AffirmTrust, CN=AffirmTrust Premium ECC
-        Validity
-            Not Before: Jan 29 14:20:24 2010 GMT
-            Not After : Dec 31 14:20:24 2040 GMT
-        Subject: C=US, O=AffirmTrust, CN=AffirmTrust Premium ECC
-        Subject Public Key Info:
-            Public Key Algorithm: id-ecPublicKey
-                Public-Key: (384 bit)
-                pub:
-                    04:0d:30:5e:1b:15:9d:03:d0:a1:79:35:b7:3a:3c:
-                    92:7a:ca:15:1c:cd:62:f3:9c:26:5c:07:3d:e5:54:
-                    fa:a3:d6:cc:12:ea:f4:14:5f:e8:8e:19:ab:2f:2e:
-                    48:e6:ac:18:43:78:ac:d0:37:c3:bd:b2:cd:2c:e6:
-                    47:e2:1a:e6:63:b8:3d:2e:2f:78:c4:4f:db:f4:0f:
-                    a4:68:4c:55:72:6b:95:1d:4e:18:42:95:78:cc:37:
-                    3c:91:e2:9b:65:2b:29
-                ASN1 OID: secp384r1
-                NIST CURVE: P-384
-        X509v3 extensions:
-            X509v3 Subject Key Identifier: 
-                9A:AF:29:7A:C0:11:35:35:26:51:30:00:C3:6A:FE:40:D5:AE:D6:3C
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-    Signature Algorithm: ecdsa-with-SHA384
-    Signature Value:
-        30:64:02:30:17:09:f3:87:88:50:5a:af:c8:c0:42:bf:47:5f:
-        f5:6c:6a:86:e0:c4:27:74:e4:38:53:d7:05:7f:1b:34:e3:c6:
-        2f:b3:ca:09:3c:37:9d:d7:e7:b8:46:f1:fd:a1:e2:71:02:30:
-        42:59:87:43:d4:51:df:ba:d3:09:32:5a:ce:88:7e:57:3d:9c:
-        5f:42:6b:f5:07:2d:b5:f0:82:93:f9:59:6f:ae:64:fa:58:e5:
-        8b:1e:e3:63:be:b5:81:cd:6f:02:8c:79
-SHA1 Fingerprint=B8:23:6B:00:2F:1D:16:86:53:01:55:6C:11:A4:37:CA:EB:FF:C3:BB
------BEGIN CERTIFICATE-----
-MIIB/jCCAYWgAwIBAgIIdJclisc/elQwCgYIKoZIzj0EAwMwRTELMAkGA1UEBhMC
-VVMxFDASBgNVBAoMC0FmZmlybVRydXN0MSAwHgYDVQQDDBdBZmZpcm1UcnVzdCBQ
-cmVtaXVtIEVDQzAeFw0xMDAxMjkxNDIwMjRaFw00MDEyMzExNDIwMjRaMEUxCzAJ
-BgNVBAYTAlVTMRQwEgYDVQQKDAtBZmZpcm1UcnVzdDEgMB4GA1UEAwwXQWZmaXJt
-VHJ1c3QgUHJlbWl1bSBFQ0MwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQNMF4bFZ0D
-0KF5Nbc6PJJ6yhUczWLznCZcBz3lVPqj1swS6vQUX+iOGasvLkjmrBhDeKzQN8O9
-ss0s5kfiGuZjuD0uL3jET9v0D6RoTFVya5UdThhClXjMNzyR4ptlKymjQjBAMB0G
-A1UdDgQWBBSaryl6wBE1NSZRMADDav5A1a7WPDAPBgNVHRMBAf8EBTADAQH/MA4G
-A1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAwNnADBkAjAXCfOHiFBar8jAQr9HX/Vs
-aobgxCd05DhT1wV/GzTjxi+zygk8N53X57hG8f2h4nECMEJZh0PUUd+60wkyWs6I
-flc9nF9Ca/UHLbXwgpP5WW+uZPpY5Yse42O+tYHNbwKMeQ==
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem b/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
deleted file mode 100644
index 8f5973a12f5b..000000000000
--- a/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
+++ /dev/null
@@ -1,89 +0,0 @@
-##
-##  Baltimore CyberTrust Root
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number: 33554617 (0x20000b9)
-        Signature Algorithm: sha1WithRSAEncryption
-        Issuer: C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
-        Validity
-            Not Before: May 12 18:46:00 2000 GMT
-            Not After : May 12 23:59:00 2025 GMT
-        Subject: C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (2048 bit)
-                Modulus:
-                    00:a3:04:bb:22:ab:98:3d:57:e8:26:72:9a:b5:79:
-                    d4:29:e2:e1:e8:95:80:b1:b0:e3:5b:8e:2b:29:9a:
-                    64:df:a1:5d:ed:b0:09:05:6d:db:28:2e:ce:62:a2:
-                    62:fe:b4:88:da:12:eb:38:eb:21:9d:c0:41:2b:01:
-                    52:7b:88:77:d3:1c:8f:c7:ba:b9:88:b5:6a:09:e7:
-                    73:e8:11:40:a7:d1:cc:ca:62:8d:2d:e5:8f:0b:a6:
-                    50:d2:a8:50:c3:28:ea:f5:ab:25:87:8a:9a:96:1c:
-                    a9:67:b8:3f:0c:d5:f7:f9:52:13:2f:c2:1b:d5:70:
-                    70:f0:8f:c0:12:ca:06:cb:9a:e1:d9:ca:33:7a:77:
-                    d6:f8:ec:b9:f1:68:44:42:48:13:d2:c0:c2:a4:ae:
-                    5e:60:fe:b6:a6:05:fc:b4:dd:07:59:02:d4:59:18:
-                    98:63:f5:a5:63:e0:90:0c:7d:5d:b2:06:7a:f3:85:
-                    ea:eb:d4:03:ae:5e:84:3e:5f:ff:15:ed:69:bc:f9:
-                    39:36:72:75:cf:77:52:4d:f3:c9:90:2c:b9:3d:e5:
-                    c9:23:53:3f:1f:24:98:21:5c:07:99:29:bd:c6:3a:
-                    ec:e7:6e:86:3a:6b:97:74:63:33:bd:68:18:31:f0:
-                    78:8d:76:bf:fc:9e:8e:5d:2a:86:a7:4d:90:dc:27:
-                    1a:39
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Subject Key Identifier: 
-                E5:9D:59:30:82:47:58:CC:AC:FA:08:54:36:86:7B:3A:B5:04:4D:F0
-            X509v3 Basic Constraints: critical
-                CA:TRUE, pathlen:3
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-    Signature Algorithm: sha1WithRSAEncryption
-    Signature Value:
-        85:0c:5d:8e:e4:6f:51:68:42:05:a0:dd:bb:4f:27:25:84:03:
-        bd:f7:64:fd:2d:d7:30:e3:a4:10:17:eb:da:29:29:b6:79:3f:
-        76:f6:19:13:23:b8:10:0a:f9:58:a4:d4:61:70:bd:04:61:6a:
-        12:8a:17:d5:0a:bd:c5:bc:30:7c:d6:e9:0c:25:8d:86:40:4f:
-        ec:cc:a3:7e:38:c6:37:11:4f:ed:dd:68:31:8e:4c:d2:b3:01:
-        74:ee:be:75:5e:07:48:1a:7f:70:ff:16:5c:84:c0:79:85:b8:
-        05:fd:7f:be:65:11:a3:0f:c0:02:b4:f8:52:37:39:04:d5:a9:
-        31:7a:18:bf:a0:2a:f4:12:99:f7:a3:45:82:e3:3c:5e:f5:9d:
-        9e:b5:c8:9e:7c:2e:c8:a4:9e:4e:08:14:4b:6d:fd:70:6d:6b:
-        1a:63:bd:64:e6:1f:b7:ce:f0:f2:9f:2e:bb:1b:b7:f2:50:88:
-        73:92:c2:e2:e3:16:8d:9a:32:02:ab:8e:18:dd:e9:10:11:ee:
-        7e:35:ab:90:af:3e:30:94:7a:d0:33:3d:a7:65:0f:f5:fc:8e:
-        9e:62:cf:47:44:2c:01:5d:bb:1d:b5:32:d2:47:d2:38:2e:d0:
-        fe:81:dc:32:6a:1e:b5:ee:3c:d5:fc:e7:81:1d:19:c3:24:42:
-        ea:63:39:a9
-SHA1 Fingerprint=D4:DE:20:D0:5E:66:FC:53:FE:1A:50:88:2C:78:DB:28:52:CA:E4:74
------BEGIN CERTIFICATE-----
-MIIDdzCCAl+gAwIBAgIEAgAAuTANBgkqhkiG9w0BAQUFADBaMQswCQYDVQQGEwJJ
-RTESMBAGA1UEChMJQmFsdGltb3JlMRMwEQYDVQQLEwpDeWJlclRydXN0MSIwIAYD
-VQQDExlCYWx0aW1vcmUgQ3liZXJUcnVzdCBSb290MB4XDTAwMDUxMjE4NDYwMFoX
-DTI1MDUxMjIzNTkwMFowWjELMAkGA1UEBhMCSUUxEjAQBgNVBAoTCUJhbHRpbW9y
-ZTETMBEGA1UECxMKQ3liZXJUcnVzdDEiMCAGA1UEAxMZQmFsdGltb3JlIEN5YmVy
-VHJ1c3QgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKMEuyKr
-mD1X6CZymrV51Cni4eiVgLGw41uOKymaZN+hXe2wCQVt2yguzmKiYv60iNoS6zjr
-IZ3AQSsBUnuId9Mcj8e6uYi1agnnc+gRQKfRzMpijS3ljwumUNKoUMMo6vWrJYeK
-mpYcqWe4PwzV9/lSEy/CG9VwcPCPwBLKBsua4dnKM3p31vjsufFoREJIE9LAwqSu
-XmD+tqYF/LTdB1kC1FkYmGP1pWPgkAx9XbIGevOF6uvUA65ehD5f/xXtabz5OTZy
-dc93Uk3zyZAsuT3lySNTPx8kmCFcB5kpvcY67Oduhjprl3RjM71oGDHweI12v/ye
-jl0qhqdNkNwnGjkCAwEAAaNFMEMwHQYDVR0OBBYEFOWdWTCCR1jMrPoIVDaGezq1
-BE3wMBIGA1UdEwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3
-DQEBBQUAA4IBAQCFDF2O5G9RaEIFoN27TyclhAO992T9Ldcw46QQF+vaKSm2eT92
-9hkTI7gQCvlYpNRhcL0EYWoSihfVCr3FvDB81ukMJY2GQE/szKN+OMY3EU/t3Wgx
-jkzSswF07r51XgdIGn9w/xZchMB5hbgF/X++ZRGjD8ACtPhSNzkE1akxehi/oCr0
-Epn3o0WC4zxe9Z2etciefC7IpJ5OCBRLbf1wbWsaY71k5h+3zvDyny67G7fyUIhz
-ksLi4xaNmjICq44Y3ekQEe5+NauQrz4wlHrQMz2nZQ/1/I6eYs9HRCwBXbsdtTLS
-R9I4LtD+gdwyah617jzV/OeBHRnDJELqYzmp
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-01.pem b/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-01.pem
deleted file mode 100644
index a88e88b1f0c7..000000000000
--- a/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-01.pem
+++ /dev/null
@@ -1,64 +0,0 @@
-##
-##  CommScope Public Trust ECC Root-01
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number:
-            43:70:82:77:cf:4d:5d:34:f1:ca:ae:32:2f:37:f7:f4:7f:75:a0:9e
-        Signature Algorithm: ecdsa-with-SHA384
-        Issuer: C=US, O=CommScope, CN=CommScope Public Trust ECC Root-01
-        Validity
-            Not Before: Apr 28 17:35:43 2021 GMT
-            Not After : Apr 28 17:35:42 2046 GMT
-        Subject: C=US, O=CommScope, CN=CommScope Public Trust ECC Root-01
-        Subject Public Key Info:
-            Public Key Algorithm: id-ecPublicKey
-                Public-Key: (384 bit)
-                pub:
-                    04:4b:36:e9:ae:57:5e:a8:70:d7:d0:8f:74:62:77:
-                    c3:5e:7a:aa:e5:b6:a2:f1:78:fd:02:7e:57:dd:91:
-                    79:9c:6c:b9:52:88:54:bc:2f:04:be:b8:cd:f6:10:
-                    d1:29:ec:b5:d0:a0:c3:f0:89:70:19:bb:51:65:c5:
-                    43:9c:c3:9b:63:9d:20:83:3e:06:0b:a6:42:44:85:
-                    11:a7:4a:3a:2d:e9:d6:68:2f:48:4e:53:2b:07:3f:
-                    4d:bd:b9:ac:77:39:57
-                ASN1 OID: secp384r1
-                NIST CURVE: P-384
-        X509v3 extensions:
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-            X509v3 Subject Key Identifier: 
-                8E:07:62:C0:50:DD:C6:19:06:00:46:74:04:F7:F3:AE:7D:75:4D:30
-    Signature Algorithm: ecdsa-with-SHA384
-    Signature Value:
-        30:65:02:31:00:9c:33:df:41:e3:23:a8:42:36:26:97:35:5c:
-        7b:eb:db:4b:f8:aa:8b:73:55:15:5c:ac:78:29:0f:ba:21:d8:
-        c4:a0:d8:d1:03:dd:6d:d1:39:3d:c4:93:60:d2:e3:72:b2:02:
-        30:7c:c5:7e:88:d3:50:f5:1e:25:e8:fa:4e:75:e6:58:96:a4:
-        35:5f:1b:65:ea:61:9a:70:23:b5:0d:a3:9b:92:52:6f:69:a0:
-        8c:8d:4a:d0:ee:8b:0e:cb:47:8e:d0:8d:11
-SHA1 Fingerprint=07:86:C0:D8:DD:8E:C0:80:98:06:98:D0:58:7A:EF:DE:A6:CC:A2:5D
------BEGIN CERTIFICATE-----
-MIICHTCCAaOgAwIBAgIUQ3CCd89NXTTxyq4yLzf39H91oJ4wCgYIKoZIzj0EAwMw
-TjELMAkGA1UEBhMCVVMxEjAQBgNVBAoMCUNvbW1TY29wZTErMCkGA1UEAwwiQ29t
-bVNjb3BlIFB1YmxpYyBUcnVzdCBFQ0MgUm9vdC0wMTAeFw0yMTA0MjgxNzM1NDNa
-Fw00NjA0MjgxNzM1NDJaME4xCzAJBgNVBAYTAlVTMRIwEAYDVQQKDAlDb21tU2Nv
-cGUxKzApBgNVBAMMIkNvbW1TY29wZSBQdWJsaWMgVHJ1c3QgRUNDIFJvb3QtMDEw
-djAQBgcqhkjOPQIBBgUrgQQAIgNiAARLNumuV16ocNfQj3Rid8NeeqrltqLxeP0C
-flfdkXmcbLlSiFS8LwS+uM32ENEp7LXQoMPwiXAZu1FlxUOcw5tjnSCDPgYLpkJE
-hRGnSjot6dZoL0hOUysHP029uax3OVejQjBAMA8GA1UdEwEB/wQFMAMBAf8wDgYD
-VR0PAQH/BAQDAgEGMB0GA1UdDgQWBBSOB2LAUN3GGQYARnQE9/OufXVNMDAKBggq
-hkjOPQQDAwNoADBlAjEAnDPfQeMjqEI2Jpc1XHvr20v4qotzVRVcrHgpD7oh2MSg
-2NED3W3ROT3Ek2DS43KyAjB8xX6I01D1HiXo+k515liWpDVfG2XqYZpwI7UNo5uS
-Um9poIyNStDuiw7LR47QjRE=
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-02.pem b/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-02.pem
deleted file mode 100644
index 3e5828e5f8fe..000000000000
--- a/secure/caroot/trusted/CommScope_Public_Trust_ECC_Root-02.pem
+++ /dev/null
@@ -1,64 +0,0 @@
-##
-##  CommScope Public Trust ECC Root-02
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number:
-            28:fd:99:60:41:47:a6:01:3a:ca:14:7b:1f:ef:f9:68:08:83:5d:7d
-        Signature Algorithm: ecdsa-with-SHA384
-        Issuer: C=US, O=CommScope, CN=CommScope Public Trust ECC Root-02
-        Validity
-            Not Before: Apr 28 17:44:54 2021 GMT
-            Not After : Apr 28 17:44:53 2046 GMT
-        Subject: C=US, O=CommScope, CN=CommScope Public Trust ECC Root-02
-        Subject Public Key Info:
-            Public Key Algorithm: id-ecPublicKey
-                Public-Key: (384 bit)
-                pub:
-                    04:78:30:81:e8:63:1e:e5:eb:71:51:0f:f7:07:07:
-                    ca:39:99:7c:4e:d5:0f:cc:30:30:0b:8f:66:93:3e:
-                    cf:bd:c5:86:bd:f9:b1:b7:b4:3e:b4:07:c8:f3:96:
-                    31:f3:ed:a4:4f:f8:a3:4e:8d:29:15:58:b8:d5:6f:
-                    7f:ee:6c:22:b5:b0:af:48:45:0a:bd:a8:49:94:bf:
-                    84:43:b0:db:84:4a:03:23:19:67:6a:6f:c1:6e:bc:
-                    06:39:37:d1:88:22:f7
-                ASN1 OID: secp384r1
-                NIST CURVE: P-384
-        X509v3 extensions:
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-            X509v3 Subject Key Identifier: 
-                E6:18:75:FF:EF:60:DE:84:A4:F5:46:C7:DE:4A:55:E3:32:36:79:F5
-    Signature Algorithm: ecdsa-with-SHA384
-    Signature Value:
-        30:64:02:30:26:73:49:7a:b6:ab:e6:49:f4:7d:52:3f:d4:41:
-        04:ae:80:43:83:65:75:b9:85:80:38:3b:d6:6f:e4:93:86:ab:
-        8f:e7:89:c8:7f:9b:7e:6b:0a:12:55:61:aa:11:e0:79:02:30:
-        77:e8:31:71:ac:3c:71:03:d6:84:26:1e:14:b8:f3:3b:3b:de:
-        ed:59:fc:6b:4c:30:7f:59:ce:45:e9:73:60:15:9a:4c:f0:e6:
-        5e:25:22:15:6d:c2:87:59:d0:b2:8e:6a
-SHA1 Fingerprint=3C:3F:EF:57:0F:FE:65:93:86:9E:A0:FE:B0:F6:ED:8E:D1:13:C7:E5
------BEGIN CERTIFICATE-----
-MIICHDCCAaOgAwIBAgIUKP2ZYEFHpgE6yhR7H+/5aAiDXX0wCgYIKoZIzj0EAwMw
-TjELMAkGA1UEBhMCVVMxEjAQBgNVBAoMCUNvbW1TY29wZTErMCkGA1UEAwwiQ29t
-bVNjb3BlIFB1YmxpYyBUcnVzdCBFQ0MgUm9vdC0wMjAeFw0yMTA0MjgxNzQ0NTRa
-Fw00NjA0MjgxNzQ0NTNaME4xCzAJBgNVBAYTAlVTMRIwEAYDVQQKDAlDb21tU2Nv
-cGUxKzApBgNVBAMMIkNvbW1TY29wZSBQdWJsaWMgVHJ1c3QgRUNDIFJvb3QtMDIw
-djAQBgcqhkjOPQIBBgUrgQQAIgNiAAR4MIHoYx7l63FRD/cHB8o5mXxO1Q/MMDAL
-j2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmU
-v4RDsNuESgMjGWdqb8FuvAY5N9GIIvejQjBAMA8GA1UdEwEB/wQFMAMBAf8wDgYD
-VR0PAQH/BAQDAgEGMB0GA1UdDgQWBBTmGHX/72DehKT1RsfeSlXjMjZ59TAKBggq
-hkjOPQQDAwNnADBkAjAmc0l6tqvmSfR9Uj/UQQSugEODZXW5hYA4O9Zv5JOGq4/n
-ich/m35rChJVYaoR4HkCMHfoMXGsPHED1oQmHhS48zs73u1Z/GtMMH9ZzkXpc2AV
-mkzw5l4lIhVtwodZ0LKOag==
------END CERTIFICATE-----
diff --git a/secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-01.pem b/secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-01.pem
deleted file mode 100644
index 6a4e2cfb42a4..000000000000
--- a/secure/caroot/trusted/CommScope_Public_Trust_RSA_Root-01.pem
+++ /dev/null
@@ -1,131 +0,0 @@
-##
-##  CommScope Public Trust RSA Root-01
-##
-##  This is a single X.509 certificate for a public Certificate
-##  Authority (CA). It was automatically extracted from Mozilla's
-##  root CA list (the file `certdata.txt' in security/nss)
-##  licensed under the MPL 2.0, http://mozilla.org/MPL/2.0/.
-##
-##  @generated
-##
-Certificate:
-    Data:
-        Version: 3 (0x2)
-        Serial Number:
-            3e:03:49:81:75:16:74:31:8e:4c:ab:d5:c5:90:29:96:c5:39:10:dd
-        Signature Algorithm: sha256WithRSAEncryption
-        Issuer: C=US, O=CommScope, CN=CommScope Public Trust RSA Root-01
-        Validity
-            Not Before: Apr 28 16:45:54 2021 GMT
-            Not After : Apr 28 16:45:53 2046 GMT
-        Subject: C=US, O=CommScope, CN=CommScope Public Trust RSA Root-01
-        Subject Public Key Info:
-            Public Key Algorithm: rsaEncryption
-                Public-Key: (4096 bit)
-                Modulus:
-                    00:b0:48:65:a3:0d:1d:42:e3:91:6d:9d:84:a4:61:
-                    96:12:c2:ed:c3:da:23:34:19:76:f6:ea:fd:55:5a:
-                    f6:55:01:53:0f:f2:cc:8c:97:4f:b9:50:cb:b3:01:
-                    44:56:96:fd:9b:28:ec:7b:74:0b:e7:42:6b:55:ce:
-                    c9:61:b2:e8:ad:40:3c:ba:b9:41:0a:05:4f:1b:26:
-                    85:8f:43:b5:40:b5:85:d1:d4:71:dc:83:41:f3:f6:
-                    45:c7:80:a2:84:50:97:46:ce:a0:0c:c4:60:56:04:
-                    1d:07:5b:46:a5:0e:b2:4b:a4:0e:a5:7c:ee:f8:d4:
-                    62:03:b9:93:6a:8a:14:b8:70:f8:2e:82:46:38:23:
-                    0e:74:c7:6b:41:b7:d0:29:a3:9d:80:b0:7e:77:93:
-                    63:42:fb:34:83:3b:73:a3:5a:21:36:eb:47:fa:18:
-                    17:d9:ba:66:c2:93:a4:8f:fc:5d:a4:ad:fc:50:6a:
-                    95:ac:bc:24:33:d1:bd:88:7f:86:f5:f5:b2:73:2a:
-                    8f:7c:af:08:f2:1a:98:3f:a9:81:65:3f:c1:8c:89:
-                    c5:96:30:9a:0a:cf:f4:d4:c8:34:ed:9d:2f:bc:8d:
-                    38:86:53:ee:97:9f:a9:b2:63:94:17:8d:0f:dc:66:
-                    2a:7c:52:51:75:cb:99:8e:e8:3d:5c:bf:9e:3b:28:
-                    8d:83:02:0f:a9:9f:72:e2:2c:2b:b3:dc:66:97:00:
-                    40:d0:a4:54:8e:9b:5d:7b:45:36:26:d6:72:43:eb:
-                    cf:c0:ea:0d:dc:ce:12:e6:7d:38:9f:05:27:a8:97:
-                    3e:e9:51:c6:6c:05:28:c1:02:0f:e9:18:6d:ec:bd:
-                    9c:06:d4:a7:49:f4:54:05:6b:6c:30:f1:eb:03:d5:
-                    ea:3d:6a:76:c2:cb:1a:28:49:4d:7f:64:e0:fa:2b:
-                    da:73:83:81:ff:91:03:bd:94:bb:e4:b8:8e:9c:32:
-                    63:cd:9f:bb:68:81:b1:84:5b:af:36:bf:77:ee:1d:
-                    7f:f7:49:9b:52:ec:d2:77:5a:7d:91:9d:4d:c2:39:
-                    2d:e4:ba:82:f8:6f:f2:4e:1e:0f:4e:e6:3f:59:a5:
-                    23:dc:3d:87:a8:28:58:28:d1:f1:1b:36:db:4f:c4:
-                    ff:e1:8c:5b:72:8c:c7:26:03:27:a3:39:0a:01:aa:
-                    c0:b2:31:60:83:22:a1:4f:12:09:01:11:af:34:d4:
-                    cf:d7:ae:62:d3:05:07:b4:31:75:e0:0d:6d:57:4f:
-                    69:87:f9:57:a9:ba:15:f6:c8:52:6d:a1:cb:9c:1f:
-                    e5:fc:78:a8:35:9a:9f:41:14:ce:a5:b4:ce:94:08:
-                    1c:09:ad:56:e5:da:b6:49:9a:4a:ea:63:18:53:9c:
-                    2c:2e:c3
-                Exponent: 65537 (0x10001)
-        X509v3 extensions:
-            X509v3 Basic Constraints: critical
-                CA:TRUE
-            X509v3 Key Usage: critical
-                Certificate Sign, CRL Sign
-            X509v3 Subject Key Identifier: 
-                37:5D:A6:9A:74:32:C2:C2:F9:C7:A6:15:10:59:B8:E4:FD:E5:B8:6D
-    Signature Algorithm: sha256WithRSAEncryption
-    Signature Value:
-        af:a7:cf:de:ff:e0:bd:42:8d:4d:e5:22:96:df:68:ea:7d:4d:
-        2a:7d:d0:ad:3d:16:5c:43:e7:7d:c0:86:e8:7a:35:63:f1:cc:
-        81:c8:c6:0b:e8:2e:52:35:a4:a6:49:90:63:51:ac:34:ac:05:
-        3b:57:00:e9:d3:62:d3:d9:29:d5:54:be:1c:10:91:9c:b2:6d:
-        fe:59:fd:79:f7:ea:56:d0:9e:68:54:42:8f:26:52:e2:4c:df:
-        2f:97:a6:2f:d2:07:98:a8:f3:60:5d:4b:9a:58:57:88:ef:82:
-        e5:fa:af:6c:81:4b:92:8f:40:9a:93:46:59:cb:5f:78:16:b1:
-        67:3e:42:0b:df:28:d9:b0:ad:98:20:be:43:7c:d1:5e:1a:09:
-        17:24:8d:7b:5d:95:e9:ab:c1:60:ab:5b:18:64:80:fb:ad:e0:
-        06:7d:1d:ca:59:b8:f3:78:29:67:c6:56:1d:af:b6:b5:74:2a:
-        76:a1:3f:fb:75:30:9f:94:5e:3b:a5:60:f3:cb:5c:0c:e2:0e:
-        c9:60:f8:c9:1f:16:8a:26:dd:e7:27:7f:eb:25:a6:8a:bd:b8:
-        2d:36:10:9a:b1:58:4d:9a:68:4f:60:54:e5:f6:46:13:8e:88:
-        ac:bc:21:42:12:ad:c6:4a:89:7d:9b:c1:d8:2d:e9:96:03:f4:
-        a2:74:0c:bc:00:1d:bf:d6:37:25:67:b4:72:8b:af:85:bd:ea:
-        2a:03:8f:cc:fb:3c:44:24:82:e2:01:a5:0b:59:b6:34:8d:32:
-        0b:12:0d:eb:27:c2:fd:41:d7:40:3c:72:46:29:c0:8c:ea:ba:
-        0f:f1:06:93:2e:f7:9c:a8:f4:60:3e:a3:f1:38:5e:8e:13:c1:
-        b3:3a:97:87:3f:92:ca:78:a9:1c:af:d0:b0:1b:26:1e:be:70:
-        ec:7a:f5:33:98:ea:5c:ff:2b:0b:04:4e:43:dd:63:7e:0e:a7:
-        4e:78:03:95:3e:d4:2d:30:95:11:10:28:2e:bf:a0:02:3e:ff:
-        5e:59:d3:05:0e:95:5f:53:45:ef:6b:87:d5:48:cd:16:a6:96:
-        83:e1:df:b3:06:f3:c1:14:db:a7:ec:1c:8b:5d:90:90:0d:72:
-        51:e7:61:f9:14:ca:af:83:8f:bf:af:b1:0a:59:5d:dc:5c:d7:
-        e4:96:ad:5b:60:1d:da:ae:97:b2:39:d9:06:f5:76:00:13:f8:
-        68:4c:21:b0:35:c4:dc:55:b2:c9:c1:41:5a:1c:89:c0:8c:6f:
-        74:a0:6b:33:4d:b5:01:28:fd:ad:ad:89:17:3b:a6:9a:84:bc:
-        eb:8c:ea:c4:71:24:a8:ba:29:f9:08:b2:27:56:35:32:5f:ea:
-        39:fb:31:9a:d5:19:cc:f0
-SHA1 Fingerprint=6D:0A:5F:F7:B4:23:06:B4:85:B3:B7:97:64:FC:AC:75:F5:33:F2:93
------BEGIN CERTIFICATE-----
-MIIFbDCCA1SgAwIBAgIUPgNJgXUWdDGOTKvVxZAplsU5EN0wDQYJKoZIhvcNAQEL
-BQAwTjELMAkGA1UEBhMCVVMxEjAQBgNVBAoMCUNvbW1TY29wZTErMCkGA1UEAwwi
-Q29tbVNjb3BlIFB1YmxpYyBUcnVzdCBSU0EgUm9vdC0wMTAeFw0yMTA0MjgxNjQ1
-NTRaFw00NjA0MjgxNjQ1NTNaME4xCzAJBgNVBAYTAlVTMRIwEAYDVQQKDAlDb21t
-U2NvcGUxKzApBgNVBAMMIkNvbW1TY29wZSBQdWJsaWMgVHJ1c3QgUlNBIFJvb3Qt
-MDEwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCwSGWjDR1C45FtnYSk
-YZYSwu3D2iM0GXb26v1VWvZVAVMP8syMl0+5UMuzAURWlv2bKOx7dAvnQmtVzslh
-suitQDy6uUEKBU8bJoWPQ7VAtYXR1HHcg0Hz9kXHgKKEUJdGzqAMxGBWBB0HW0al
-DrJLpA6lfO741GIDuZNqihS4cPgugkY4Iw50x2tBt9Apo52AsH53k2NC+zSDO3Oj
-WiE260f6GBfZumbCk6SP/F2krfxQapWsvCQz0b2If4b19bJzKo98rwjyGpg/qYFl
-P8GMicWWMJoKz/TUyDTtnS+8jTiGU+6Xn6myY5QXjQ/cZip8UlF1y5mO6D1cv547
-KI2DAg+pn3LiLCuz3GaXAEDQpFSOm117RTYm1nJD68/A6g3czhLmfTifBSeolz7p
-UcZsBSjBAg/pGG3svZwG1KdJ9FQFa2ww8esD1eo9anbCyxooSU1/ZOD6K9pzg4H/
-kQO9lLvkuI6cMmPNn7togbGEW682v3fuHX/3SZtS7NJ3Wn2RnU3COS3kuoL4b/JO
-Hg9O5j9ZpSPcPYeoKFgo0fEbNttPxP/hjFtyjMcmAyejOQoBqsCyMWCDIqFPEgkB
-Ea801M/XrmLTBQe0MXXgDW1XT2mH+VepuhX2yFJtocucH+X8eKg1mp9BFM6ltM6U
-CBwJrVbl2rZJmkrqYxhTnCwuwwIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MA4G
-A1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUN12mmnQywsL5x6YVEFm45P3luG0wDQYJ
-KoZIhvcNAQELBQADggIBAK+nz97/4L1CjU3lIpbfaOp9TSp90K09FlxD533Ahuh6
-NWPxzIHIxgvoLlI1pKZJkGNRrDSsBTtXAOnTYtPZKdVUvhwQkZyybf5Z/Xn36lbQ
-nmhUQo8mUuJM3y+Xpi/SB5io82BdS5pYV4jvguX6r2yBS5KPQJqTRlnLX3gWsWc+
-QgvfKNmwrZggvkN80V4aCRckjXtdlemrwWCrWxhkgPut4AZ9HcpZuPN4KWfGVh2v
-trV0KnahP/t1MJ+UXjulYPPLXAziDslg+MkfFoom3ecnf+slpoq9uC02EJqxWE2a
-aE9gVOX2RhOOiKy8IUISrcZKiX2bwdgt6ZYD9KJ0DLwAHb/WNyVntHKLr4W96ioD
-j8z7PEQkguIBpQtZtjSNMgsSDesnwv1B10A8ckYpwIzqug/xBpMu95yo9GA+o/E4
-Xo4TwbM6l4c/ksp4qRyv0LAbJh6+cOx69TOY6lz/KwsETkPdY34Op054A5U+1C0w
-lREQKC6/oAI+/15Z0wUOlV9TRe9rh9VIzRamloPh37MG88EU26fsHItdkJANclHn
-YfkUyq+Dj7+vsQpZXdxc1+SWrVtgHdqul7I52Qb1dgAT+GhMIbA1xNxVssnBQVoc
*** 8686 LINES SKIPPED ***


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?69f36f6f.18646.6fcbdce8>