Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 11 Sep 2023 22:02:54 GMT
From:      Kyle Evans <kevans@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: 25f07248916f - stable/13 - caroot: update the root bundle and regenerate with OpenSSL 3
Message-ID:  <202309112202.38BM2skI006276@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch stable/13 has been updated by kevans:

URL: https://cgit.FreeBSD.org/src/commit/?id=25f07248916f0108bd62b3deb58e21bff880b391

commit 25f07248916f0108bd62b3deb58e21bff880b391
Author:     Kyle Evans <kevans@FreeBSD.org>
AuthorDate: 2023-08-26 01:01:47 +0000
Commit:     Kyle Evans <kevans@FreeBSD.org>
CommitDate: 2023-09-11 22:02:37 +0000

    caroot: update the root bundle and regenerate with OpenSSL 3
    
    Summary:
    - Six (6) new roots
    - Four (4) distrusted roots
    
    Note that this was intentionally generated with OpenSSL 1.1.1 to avoid
    mixing updates and non-functional changes -- there will be some churn
    with OpenSSL 3.  The next commit will update the current batch of
    trusted certs with the format OpenSSL 3 produces, which I've tested
    against OpenSSL 1.1.1 to be sure that that doesn't hurt us in older
    branches.
    
    This MFC also regenerates all of the trusted certs with OpenSSL 3 to
    reduce the diff of future ENs -- this update has no existing certs
    modified, so it's the perfect time.
    
    (cherry picked from commit 65fd80909e196c8be2ce5e948775e9cbda2ef069)
    (cherry picked from commit 8ed0ecf8024d10e9cd21f5880723a6cec4fd4ae6)
---
 ObsoleteFiles.inc                                  |   6 +
 .../caroot/blacklisted/AddTrust_External_Root.pem  |  34 ++---
 .../AddTrust_Low-Value_Services_Root.pem           |  34 ++---
 .../Camerfirma_Chambers_of_Commerce_Root.pem       |  36 +++---
 .../Camerfirma_Global_Chambersign_Root.pem         |  36 +++---
 secure/caroot/blacklisted/Certum_Root_CA.pem       |  33 ++---
 .../Chambers_of_Commerce_Root_-_2008.pem           |  65 +++++-----
 .../caroot/blacklisted/Cybertrust_Global_Root.pem  |  38 +++---
 .../caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem  |  36 +++---
 secure/caroot/blacklisted/DST_Root_CA_X3.pem       |  33 ++---
 .../E-Tugra_Certification_Authority.pem            |  64 +++++-----
 .../E-Tugra_Global_Root_CA_ECC_v3.pem              |  16 +--
 .../E-Tugra_Global_Root_CA_RSA_v3.pem              |  64 +++++-----
 secure/caroot/blacklisted/EC-ACC.pem               |  34 ++---
 .../EE_Certification_Centre_Root_CA.pem            |  33 ++---
 secure/caroot/blacklisted/GeoTrust_Global_CA.pem   |  36 +++---
 .../GeoTrust_Primary_Certification_Authority.pem   |  33 ++---
 ...oTrust_Primary_Certification_Authority_-_G2.pem |  13 +-
 ...oTrust_Primary_Certification_Authority_-_G3.pem |  33 ++---
 .../caroot/blacklisted/GeoTrust_Universal_CA.pem   |  64 +++++-----
 .../caroot/blacklisted/GeoTrust_Universal_CA_2.pem |  64 +++++-----
 .../caroot/blacklisted/GlobalSign_Root_CA_-_R2.pem |  38 +++---
 .../blacklisted/Global_Chambersign_Root_-_2008.pem |  65 +++++-----
 ...demic_and_Research_Institutions_RootCA_2011.pem |  34 ++---
 .../Hongkong_Post_Root_CA_1.pem                    |  33 ++---
 .../caroot/blacklisted/LuxTrust_Global_Root_2.pem  |  65 +++++-----
 .../Network_Solutions_Certificate_Authority.pem    |  35 +++---
 .../OISTE_WISeKey_Global_Root_GA_CA.pem            |  33 ++---
 secure/caroot/blacklisted/QuoVadis_Root_CA.pem     |  36 +++---
 .../caroot/blacklisted/Sonera_Class_2_Root_CA.pem  |  33 ++---
 .../Staat_der_Nederlanden_EV_Root_CA.pem           |  61 ++++-----
 .../Staat_der_Nederlanden_Root_CA_-_G2.pem         |  62 +++++-----
 .../Staat_der_Nederlanden_Root_CA_-_G3.pem         |  61 ++++-----
 .../blacklisted/SwissSign_Platinum_CA_-_G2.pem     |  65 +++++-----
 ...Public_Primary_Certification_Authority_-_G4.pem |  13 +-
 ...Public_Primary_Certification_Authority_-_G6.pem |  33 ++---
 ...Public_Primary_Certification_Authority_-_G4.pem |  13 +-
 ...Public_Primary_Certification_Authority_-_G6.pem |  33 ++---
 secure/caroot/blacklisted/Taiwan_GRCA.pem          |  61 ++++-----
 secure/caroot/blacklisted/TrustCor_ECA-1.pem       |  36 +++---
 .../caroot/blacklisted/TrustCor_RootCert_CA-1.pem  |  36 +++---
 .../caroot/blacklisted/TrustCor_RootCert_CA-2.pem  |  64 +++++-----
 secure/caroot/blacklisted/Trustis_FPS_Root_CA.pem  |  36 +++---
 ...Public_Primary_Certification_Authority_-_G4.pem |  13 +-
 ...Public_Primary_Certification_Authority_-_G5.pem |  33 ++---
 ...Sign_Universal_Root_Certification_Authority.pem |  33 ++---
 ...Public_Primary_Certification_Authority_-_G3.pem |  33 ++---
 ...Public_Primary_Certification_Authority_-_G3.pem |  33 ++---
 ...Public_Primary_Certification_Authority_-_G3.pem |  33 ++---
 .../caroot/blacklisted/thawte_Primary_Root_CA.pem  |  33 ++---
 .../blacklisted/thawte_Primary_Root_CA_-_G2.pem    |  13 +-
 .../blacklisted/thawte_Primary_Root_CA_-_G3.pem    |  33 ++---
 secure/caroot/trusted/ACCVRAIZ1.pem                |  68 +++++-----
 secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem         |  62 +++++-----
 .../AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem        |  13 +-
 .../caroot/trusted/ANF_Secure_Server_Root_CA.pem   |  64 +++++-----
 .../trusted/Actalis_Authentication_Root_CA.pem     |  64 +++++-----
 secure/caroot/trusted/AffirmTrust_Commercial.pem   |  33 ++---
 secure/caroot/trusted/AffirmTrust_Networking.pem   |  33 ++---
 secure/caroot/trusted/AffirmTrust_Premium.pem      |  61 ++++-----
 secure/caroot/trusted/AffirmTrust_Premium_ECC.pem  |  13 +-
 secure/caroot/trusted/Amazon_Root_CA_1.pem         |  33 ++---
 secure/caroot/trusted/Amazon_Root_CA_2.pem         |  61 ++++-----
 secure/caroot/trusted/Amazon_Root_CA_3.pem         |   9 +-
 secure/caroot/trusted/Amazon_Root_CA_4.pem         |  13 +-
 secure/caroot/trusted/Atos_TrustedRoot_2011.pem    |  37 +++---
 .../Atos_TrustedRoot_Root_CA_ECC_TLS_2021.pem      |  67 ++++++++++
 .../Atos_TrustedRoot_Root_CA_RSA_TLS_2021.pem      | 134 ++++++++++++++++++++
 ...ertificacion_Firmaprofesional_CIF_A62634068.pem |  62 +++++-----
 secure/caroot/trusted/BJCA_Global_Root_CA1.pem     |  61 ++++-----
 secure/caroot/trusted/BJCA_Global_Root_CA2.pem     |  13 +-
 .../caroot/trusted/Baltimore_CyberTrust_Root.pem   |  33 ++---
 secure/caroot/trusted/Buypass_Class_2_Root_CA.pem  |  61 ++++-----
 secure/caroot/trusted/Buypass_Class_3_Root_CA.pem  |  61 ++++-----
 secure/caroot/trusted/CA_Disig_Root_R2.pem         |  61 ++++-----
 secure/caroot/trusted/CFCA_EV_ROOT.pem             |  64 +++++-----
 .../trusted/COMODO_Certification_Authority.pem     |  35 +++---
 .../trusted/COMODO_ECC_Certification_Authority.pem |  13 +-
 .../trusted/COMODO_RSA_Certification_Authority.pem |  61 ++++-----
 secure/caroot/trusted/Certainly_Root_E1.pem        |  13 +-
 secure/caroot/trusted/Certainly_Root_R1.pem        |  61 ++++-----
 secure/caroot/trusted/Certigna.pem                 |  34 ++---
 secure/caroot/trusted/Certigna_Root_CA.pem         |  68 +++++-----
 secure/caroot/trusted/Certum_EC-384_CA.pem         |  13 +-
 .../caroot/trusted/Certum_Trusted_Network_CA.pem   |  33 ++---
 .../caroot/trusted/Certum_Trusted_Network_CA_2.pem |  61 ++++-----
 secure/caroot/trusted/Certum_Trusted_Root_CA.pem   |  61 ++++-----
 secure/caroot/trusted/Comodo_AAA_Services_root.pem |  36 +++---
 .../caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem   |  16 ++-
 .../caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem   |  16 ++-
 .../trusted/D-TRUST_Root_Class_3_CA_2_2009.pem     |  36 +++---
 .../trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem  |  36 +++---
 .../caroot/trusted/DigiCert_Assured_ID_Root_CA.pem |  36 +++---
 .../caroot/trusted/DigiCert_Assured_ID_Root_G2.pem |  33 ++---
 .../caroot/trusted/DigiCert_Assured_ID_Root_G3.pem |  13 +-
 secure/caroot/trusted/DigiCert_Global_Root_CA.pem  |  36 +++---
 secure/caroot/trusted/DigiCert_Global_Root_G2.pem  |  33 ++---
 secure/caroot/trusted/DigiCert_Global_Root_G3.pem  |  13 +-
 .../trusted/DigiCert_High_Assurance_EV_Root_CA.pem |  36 +++---
 .../trusted/DigiCert_TLS_ECC_P384_Root_G5.pem      |  13 +-
 .../trusted/DigiCert_TLS_RSA4096_Root_G5.pem       |  61 ++++-----
 secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem |  61 ++++-----
 .../Entrust_Root_Certification_Authority.pem       |  36 +++---
 .../Entrust_Root_Certification_Authority_-_EC1.pem |  13 +-
 .../Entrust_Root_Certification_Authority_-_G2.pem  |  33 ++---
 .../Entrust_Root_Certification_Authority_-_G4.pem  |  61 ++++-----
 .../Entrust_net_Premium_2048_Secure_Server_CA.pem  |  33 ++---
 secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem   |  61 ++++-----
 secure/caroot/trusted/GLOBALTRUST_2020.pem         |  64 +++++-----
 secure/caroot/trusted/GTS_Root_R1.pem              |  61 ++++-----
 secure/caroot/trusted/GTS_Root_R2.pem              |  61 ++++-----
 secure/caroot/trusted/GTS_Root_R3.pem              |  13 +-
 secure/caroot/trusted/GTS_Root_R4.pem              |  13 +-
 .../caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem |   9 +-
 .../caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem |  13 +-
 secure/caroot/trusted/GlobalSign_Root_CA.pem       |  33 ++---
 secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem  |  33 ++---
 secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem  |  64 +++++-----
 secure/caroot/trusted/GlobalSign_Root_E46.pem      |  13 +-
 secure/caroot/trusted/GlobalSign_Root_R46.pem      |  61 ++++-----
 secure/caroot/trusted/Go_Daddy_Class_2_CA.pem      |  34 ++---
 .../Go_Daddy_Root_Certificate_Authority_-_G2.pem   |  33 ++---
 .../caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem |  13 +-
 .../caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem |  61 ++++-----
 ...c_and_Research_Institutions_ECC_RootCA_2015.pem |  13 +-
 ...demic_and_Research_Institutions_RootCA_2015.pem |  61 ++++-----
 secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem       |  61 ++++-----
 secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem  |  64 +++++-----
 secure/caroot/trusted/ISRG_Root_X1.pem             |  61 ++++-----
 secure/caroot/trusted/ISRG_Root_X2.pem             |  13 +-
 .../trusted/IdenTrust_Commercial_Root_CA_1.pem     |  61 ++++-----
 .../trusted/IdenTrust_Public_Sector_Root_CA_1.pem  |  61 ++++-----
 secure/caroot/trusted/Izenpe_com.pem               |  61 ++++-----
 .../trusted/Microsec_e-Szigno_Root_CA_2009.pem     |  36 +++---
 ...crosoft_ECC_Root_Certificate_Authority_2017.pem |  13 +-
 ...crosoft_RSA_Root_Certificate_Authority_2017.pem |  61 ++++-----
 .../NAVER_Global_Root_Certification_Authority.pem  |  61 ++++-----
 ...etLock_Arany__Class_Gold__F__tan__s__tv__ny.pem |  33 ++---
 .../trusted/OISTE_WISeKey_Global_Root_GB_CA.pem    |  33 ++---
 .../trusted/OISTE_WISeKey_Global_Root_GC_CA.pem    |  13 +-
 secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem    |  61 ++++-----
 secure/caroot/trusted/QuoVadis_Root_CA_2.pem       |  62 +++++-----
 secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem    |  61 ++++-----
 secure/caroot/trusted/QuoVadis_Root_CA_3.pem       |  63 +++++-----
 secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem    |  61 ++++-----
 ...SSL_com_EV_Root_Certification_Authority_ECC.pem |  16 +--
 ..._com_EV_Root_Certification_Authority_RSA_R2.pem |  64 +++++-----
 .../SSL_com_Root_Certification_Authority_ECC.pem   |  16 +--
 .../SSL_com_Root_Certification_Authority_RSA.pem   |  64 +++++-----
 .../trusted/SSL_com_TLS_ECC_Root_CA_2022.pem       |  69 +++++++++++
 .../trusted/SSL_com_TLS_RSA_Root_CA_2022.pem       | 137 +++++++++++++++++++++
 secure/caroot/trusted/SZAFIR_ROOT_CA2.pem          |  33 ++---
 ...ctigo_Public_Server_Authentication_Root_E46.pem |  67 ++++++++++
 ...ctigo_Public_Server_Authentication_Root_R46.pem | 135 ++++++++++++++++++++
 secure/caroot/trusted/SecureSign_RootCA11.pem      |  33 ++---
 secure/caroot/trusted/SecureTrust_CA.pem           |  35 +++---
 secure/caroot/trusted/Secure_Global_CA.pem         |  35 +++---
 .../trusted/Security_Communication_ECC_RootCA1.pem |  13 +-
 .../trusted/Security_Communication_RootCA2.pem     |  33 ++---
 .../trusted/Security_Communication_RootCA3.pem     |  61 ++++-----
 .../trusted/Security_Communication_Root_CA.pem     |  33 ++---
 secure/caroot/trusted/Starfield_Class_2_CA.pem     |  34 ++---
 .../Starfield_Root_Certificate_Authority_-_G2.pem  |  33 ++---
 ...ld_Services_Root_Certificate_Authority_-_G2.pem |  33 ++---
 secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem   |  65 +++++-----
 secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem |  65 +++++-----
 .../trusted/T-TeleSec_GlobalRoot_Class_2.pem       |  33 ++---
 .../trusted/T-TeleSec_GlobalRoot_Class_3.pem       |  33 ++---
 ...BITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem |  33 ++---
 secure/caroot/trusted/TWCA_Global_Root_CA.pem      |  61 ++++-----
 .../trusted/TWCA_Root_Certification_Authority.pem  |  33 ++---
 secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem   |  61 ++++-----
 secure/caroot/trusted/Telia_Root_CA_v2.pem         |  64 +++++-----
 .../Trustwave_Global_Certification_Authority.pem   |  61 ++++-----
 ...ave_Global_ECC_P256_Certification_Authority.pem |   9 +-
 ...ave_Global_ECC_P384_Certification_Authority.pem |  13 +-
 secure/caroot/trusted/TunTrust_Root_CA.pem         |  64 +++++-----
 .../trusted/UCA_Extended_Validation_Root.pem       |  61 ++++-----
 secure/caroot/trusted/UCA_Global_G2_Root.pem       |  61 ++++-----
 .../USERTrust_ECC_Certification_Authority.pem      |  13 +-
 .../USERTrust_RSA_Certification_Authority.pem      |  61 ++++-----
 secure/caroot/trusted/XRamp_Global_CA_Root.pem     |  35 +++---
 secure/caroot/trusted/certSIGN_ROOT_CA.pem         |  33 ++---
 secure/caroot/trusted/certSIGN_Root_CA_G2.pem      |  61 ++++-----
 secure/caroot/trusted/e-Szigno_Root_CA_2017.pem    |  12 +-
 .../trusted/ePKI_Root_Certification_Authority.pem  |  61 ++++-----
 secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem  |  13 +-
 secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem  |  13 +-
 secure/caroot/trusted/emSign_Root_CA_-_C1.pem      |  33 ++---
 secure/caroot/trusted/emSign_Root_CA_-_G1.pem      |  33 ++---
 secure/caroot/trusted/vTrus_ECC_Root_CA.pem        |  13 +-
 secure/caroot/trusted/vTrus_Root_CA.pem            |  61 ++++-----
 192 files changed, 4371 insertions(+), 3679 deletions(-)

diff --git a/ObsoleteFiles.inc b/ObsoleteFiles.inc
index 14a806699b8b..3ff61da559ab 100644
--- a/ObsoleteFiles.inc
+++ b/ObsoleteFiles.inc
@@ -51,6 +51,12 @@
 #   xargs -n1 | sort | uniq -d;
 # done
 
+# 20230911: caroot bundle updated
+OLD_FILES+=usr/share/certs/trusted/E-Tugra_Certification_Authority.pem
+OLD_FILES+=usr/share/certs/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
+OLD_FILES+=usr/share/certs/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
+OLD_FILES+=usr/share/certs/trusted/Hongkong_Post_Root_CA_1.pem
+
 # 20230806: Removal of support for the VTOC8 partitioning scheme
 OLD_FILES+=usr/include/sys/disk/vtoc.h
 OLD_FILES+=usr/include/sys/vtoc.h
diff --git a/secure/caroot/blacklisted/AddTrust_External_Root.pem b/secure/caroot/blacklisted/AddTrust_External_Root.pem
index 701bc7bce072..97fe312d0e8f 100644
--- a/secure/caroot/blacklisted/AddTrust_External_Root.pem
+++ b/secure/caroot/blacklisted/AddTrust_External_Root.pem
@@ -22,7 +22,7 @@ Certificate:
         Subject: C = SE, O = AddTrust AB, OU = AddTrust External TTP Network, CN = AddTrust External CA Root
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:b7:f7:1a:33:e6:f2:00:04:2d:39:e0:4e:5b:ed:
                     1f:bc:6c:0f:cd:b5:fa:23:b6:ce:de:9b:11:33:97:
@@ -54,23 +54,23 @@ Certificate:
                 keyid:AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A
                 DirName:/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
                 serial:01
-
     Signature Algorithm: sha1WithRSAEncryption
-         b0:9b:e0:85:25:c2:d6:23:e2:0f:96:06:92:9d:41:98:9c:d9:
-         84:79:81:d9:1e:5b:14:07:23:36:65:8f:b0:d8:77:bb:ac:41:
-         6c:47:60:83:51:b0:f9:32:3d:e7:fc:f6:26:13:c7:80:16:a5:
-         bf:5a:fc:87:cf:78:79:89:21:9a:e2:4c:07:0a:86:35:bc:f2:
-         de:51:c4:d2:96:b7:dc:7e:4e:ee:70:fd:1c:39:eb:0c:02:51:
-         14:2d:8e:bd:16:e0:c1:df:46:75:e7:24:ad:ec:f4:42:b4:85:
-         93:70:10:67:ba:9d:06:35:4a:18:d3:2b:7a:cc:51:42:a1:7a:
-         63:d1:e6:bb:a1:c5:2b:c2:36:be:13:0d:e6:bd:63:7e:79:7b:
-         a7:09:0d:40:ab:6a:dd:8f:8a:c3:f6:f6:8c:1a:42:05:51:d4:
-         45:f5:9f:a7:62:21:68:15:20:43:3c:99:e7:7c:bd:24:d8:a9:
-         91:17:73:88:3f:56:1b:31:38:18:b4:71:0f:9a:cd:c8:0e:9e:
-         8e:2e:1b:e1:8c:98:83:cb:1f:31:f1:44:4c:c6:04:73:49:76:
-         60:0f:c7:f8:bd:17:80:6b:2e:e9:cc:4c:0e:5a:9a:79:0f:20:
-         0a:2e:d5:9e:63:26:1e:55:92:94:d8:82:17:5a:7b:d0:bc:c7:
-         8f:4e:86:04
+    Signature Value:
+        b0:9b:e0:85:25:c2:d6:23:e2:0f:96:06:92:9d:41:98:9c:d9:
+        84:79:81:d9:1e:5b:14:07:23:36:65:8f:b0:d8:77:bb:ac:41:
+        6c:47:60:83:51:b0:f9:32:3d:e7:fc:f6:26:13:c7:80:16:a5:
+        bf:5a:fc:87:cf:78:79:89:21:9a:e2:4c:07:0a:86:35:bc:f2:
+        de:51:c4:d2:96:b7:dc:7e:4e:ee:70:fd:1c:39:eb:0c:02:51:
+        14:2d:8e:bd:16:e0:c1:df:46:75:e7:24:ad:ec:f4:42:b4:85:
+        93:70:10:67:ba:9d:06:35:4a:18:d3:2b:7a:cc:51:42:a1:7a:
+        63:d1:e6:bb:a1:c5:2b:c2:36:be:13:0d:e6:bd:63:7e:79:7b:
+        a7:09:0d:40:ab:6a:dd:8f:8a:c3:f6:f6:8c:1a:42:05:51:d4:
+        45:f5:9f:a7:62:21:68:15:20:43:3c:99:e7:7c:bd:24:d8:a9:
+        91:17:73:88:3f:56:1b:31:38:18:b4:71:0f:9a:cd:c8:0e:9e:
+        8e:2e:1b:e1:8c:98:83:cb:1f:31:f1:44:4c:c6:04:73:49:76:
+        60:0f:c7:f8:bd:17:80:6b:2e:e9:cc:4c:0e:5a:9a:79:0f:20:
+        0a:2e:d5:9e:63:26:1e:55:92:94:d8:82:17:5a:7b:d0:bc:c7:
+        8f:4e:86:04
 SHA1 Fingerprint=02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68
 -----BEGIN CERTIFICATE-----
 MIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
diff --git a/secure/caroot/blacklisted/AddTrust_Low-Value_Services_Root.pem b/secure/caroot/blacklisted/AddTrust_Low-Value_Services_Root.pem
index 0595db909a49..afb471de944f 100644
--- a/secure/caroot/blacklisted/AddTrust_Low-Value_Services_Root.pem
+++ b/secure/caroot/blacklisted/AddTrust_Low-Value_Services_Root.pem
@@ -22,7 +22,7 @@ Certificate:
         Subject: C = SE, O = AddTrust AB, OU = AddTrust TTP Network, CN = AddTrust Class 1 CA Root
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:96:96:d4:21:49:60:e2:6b:e8:41:07:0c:de:c4:
                     e0:dc:13:23:cd:c1:35:c7:fb:d6:4e:11:0a:67:5e:
@@ -54,23 +54,23 @@ Certificate:
                 keyid:95:B1:B4:F0:94:B6:BD:C7:DA:D1:11:09:21:BE:C1:AF:49:FD:10:7B
                 DirName:/C=SE/O=AddTrust AB/OU=AddTrust TTP Network/CN=AddTrust Class 1 CA Root
                 serial:01
-
     Signature Algorithm: sha1WithRSAEncryption
-         2c:6d:64:1b:1f:cd:0d:dd:b9:01:fa:96:63:34:32:48:47:99:
-         ae:97:ed:fd:72:16:a6:73:47:5a:f4:eb:dd:e9:f5:d6:fb:45:
-         cc:29:89:44:5d:bf:46:39:3d:e8:ee:bc:4d:54:86:1e:1d:6c:
-         e3:17:27:43:e1:89:56:2b:a9:6f:72:4e:49:33:e3:72:7c:2a:
-         23:9a:bc:3e:ff:28:2a:ed:a3:ff:1c:23:ba:43:57:09:67:4d:
-         4b:62:06:2d:f8:ff:6c:9d:60:1e:d8:1c:4b:7d:b5:31:2f:d9:
-         d0:7c:5d:f8:de:6b:83:18:78:37:57:2f:e8:33:07:67:df:1e:
-         c7:6b:2a:95:76:ae:8f:57:a3:f0:f4:52:b4:a9:53:08:cf:e0:
-         4f:d3:7a:53:8b:fd:bb:1c:56:36:f2:fe:b2:b6:e5:76:bb:d5:
-         22:65:a7:3f:fe:d1:66:ad:0b:bc:6b:99:86:ef:3f:7d:f3:18:
-         32:ca:7b:c6:e3:ab:64:46:95:f8:26:69:d9:55:83:7b:2c:96:
-         07:ff:59:2c:44:a3:c6:e5:e9:a9:dc:a1:63:80:5a:21:5e:21:
-         cf:53:54:f0:ba:6f:89:db:a8:aa:95:cf:8b:e3:71:cc:1e:1b:
-         20:44:08:c0:7a:b6:40:fd:c4:e4:35:e1:1d:16:1c:d0:bc:2b:
-         8e:d6:71:d9
+    Signature Value:
+        2c:6d:64:1b:1f:cd:0d:dd:b9:01:fa:96:63:34:32:48:47:99:
+        ae:97:ed:fd:72:16:a6:73:47:5a:f4:eb:dd:e9:f5:d6:fb:45:
+        cc:29:89:44:5d:bf:46:39:3d:e8:ee:bc:4d:54:86:1e:1d:6c:
+        e3:17:27:43:e1:89:56:2b:a9:6f:72:4e:49:33:e3:72:7c:2a:
+        23:9a:bc:3e:ff:28:2a:ed:a3:ff:1c:23:ba:43:57:09:67:4d:
+        4b:62:06:2d:f8:ff:6c:9d:60:1e:d8:1c:4b:7d:b5:31:2f:d9:
+        d0:7c:5d:f8:de:6b:83:18:78:37:57:2f:e8:33:07:67:df:1e:
+        c7:6b:2a:95:76:ae:8f:57:a3:f0:f4:52:b4:a9:53:08:cf:e0:
+        4f:d3:7a:53:8b:fd:bb:1c:56:36:f2:fe:b2:b6:e5:76:bb:d5:
+        22:65:a7:3f:fe:d1:66:ad:0b:bc:6b:99:86:ef:3f:7d:f3:18:
+        32:ca:7b:c6:e3:ab:64:46:95:f8:26:69:d9:55:83:7b:2c:96:
+        07:ff:59:2c:44:a3:c6:e5:e9:a9:dc:a1:63:80:5a:21:5e:21:
+        cf:53:54:f0:ba:6f:89:db:a8:aa:95:cf:8b:e3:71:cc:1e:1b:
+        20:44:08:c0:7a:b6:40:fd:c4:e4:35:e1:1d:16:1c:d0:bc:2b:
+        8e:d6:71:d9
 SHA1 Fingerprint=CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D
 -----BEGIN CERTIFICATE-----
 MIIEGDCCAwCgAwIBAgIBATANBgkqhkiG9w0BAQUFADBlMQswCQYDVQQGEwJTRTEU
diff --git a/secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem b/secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
index f708097b5023..12bb099e2312 100644
--- a/secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
+++ b/secure/caroot/blacklisted/Camerfirma_Chambers_of_Commerce_Root.pem
@@ -21,7 +21,7 @@ Certificate:
         Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Chambers of Commerce Root
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:b7:36:55:e5:a5:5d:18:30:e0:da:89:54:91:fc:
                     c8:c7:52:f8:2f:50:d9:ef:b1:75:73:65:47:7d:1b:
@@ -46,10 +46,8 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE, pathlen:12
             X509v3 CRL Distribution Points: 
-
                 Full Name:
                   URI:http://crl.chambersign.org/chambersroot.crl
-
             X509v3 Subject Key Identifier: 
                 E3:94:F5:B1:4D:E9:DB:A1:29:5B:57:8B:4D:76:06:76:E1:D1:A2:8A
             X509v3 Key Usage: critical
@@ -63,23 +61,23 @@ Certificate:
             X509v3 Certificate Policies: 
                 Policy: 1.3.6.1.4.1.17326.10.3.1
                   CPS: http://cps.chambersign.org/cps/chambersroot.html
-
     Signature Algorithm: sha1WithRSAEncryption
-         0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
-         13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
-         01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
-         45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
-         7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
-         0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
-         c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
-         ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
-         2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
-         46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
-         3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
-         4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
-         c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
-         0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
-         3c:8b:f8:dc
+    Signature Value:
+        0c:41:97:c2:1a:86:c0:22:7c:9f:fb:90:f3:1a:d1:03:b1:ef:
+        13:f9:21:5f:04:9c:da:c9:a5:8d:27:6c:96:87:91:be:41:90:
+        01:72:93:e7:1e:7d:5f:f6:89:c6:5d:a7:40:09:3d:ac:49:45:
+        45:dc:2e:8d:30:68:b2:09:ba:fb:c3:2f:cc:ba:0b:df:3f:77:
+        7b:46:7d:3a:12:24:8e:96:8f:3c:05:0a:6f:d2:94:28:1d:6d:
+        0c:c0:2e:88:22:d5:d8:cf:1d:13:c7:f0:48:d7:d7:05:a7:cf:
+        c7:47:9e:3b:3c:34:c8:80:4f:d4:14:bb:fc:0d:50:f7:fa:b3:
+        ec:42:5f:a9:dd:6d:c8:f4:75:cf:7b:c1:72:26:b1:01:1c:5c:
+        2c:fd:7a:4e:b4:01:c5:05:57:b9:e7:3c:aa:05:d9:88:e9:07:
+        46:41:ce:ef:41:81:ae:58:df:83:a2:ae:ca:d7:77:1f:e7:00:
+        3c:9d:6f:8e:e4:32:09:1d:4d:78:34:78:34:3c:94:9b:26:ed:
+        4f:71:c6:19:7a:bd:20:22:48:5a:fe:4b:7d:03:b7:e7:58:be:
+        c6:32:4e:74:1e:68:dd:a8:68:5b:b3:3e:ee:62:7d:d9:80:e8:
+        0a:75:7a:b7:ee:b4:65:9a:21:90:e0:aa:d0:98:bc:38:b5:73:
+        3c:8b:f8:dc
 SHA1 Fingerprint=6E:3A:55:A4:19:0C:19:5C:93:84:3C:C0:DB:72:2E:31:30:61:F0:B1
 -----BEGIN CERTIFICATE-----
 MIIEvTCCA6WgAwIBAgIBADANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJFVTEn
diff --git a/secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem b/secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
index 1ba719b3690a..da95297880f6 100644
--- a/secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
+++ b/secure/caroot/blacklisted/Camerfirma_Global_Chambersign_Root.pem
@@ -21,7 +21,7 @@ Certificate:
         Subject: C = EU, O = AC Camerfirma SA CIF A82743287, OU = http://www.chambersign.org, CN = Global Chambersign Root
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:a2:70:a2:d0:9f:42:ae:5b:17:c7:d8:7d:cf:14:
                     83:fc:4f:c9:a1:b7:13:af:8a:d7:9e:3e:04:0a:92:
@@ -46,10 +46,8 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE, pathlen:12
             X509v3 CRL Distribution Points: 
-
                 Full Name:
                   URI:http://crl.chambersign.org/chambersignroot.crl
-
             X509v3 Subject Key Identifier: 
                 43:9C:36:9F:B0:9E:30:4D:C6:CE:5F:AD:10:AB:E5:03:A5:FA:A9:14
             X509v3 Key Usage: critical
@@ -63,23 +61,23 @@ Certificate:
             X509v3 Certificate Policies: 
                 Policy: 1.3.6.1.4.1.17326.10.1.1
                   CPS: http://cps.chambersign.org/cps/chambersignroot.html
-
     Signature Algorithm: sha1WithRSAEncryption
-         3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
-         41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
-         34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
-         d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
-         a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
-         56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
-         be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
-         a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
-         f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
-         b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
-         4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
-         3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
-         28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
-         5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
-         f5:26:8f:f0
+    Signature Value:
+        3c:3b:70:91:f9:04:54:27:91:e1:ed:ed:fe:68:7f:61:5d:e5:
+        41:65:4f:32:f1:18:05:94:6a:1c:de:1f:70:db:3e:7b:32:02:
+        34:b5:0c:6c:a1:8a:7c:a5:f4:8f:ff:d4:d8:ad:17:d5:2d:04:
+        d1:3f:58:80:e2:81:59:88:be:c0:e3:46:93:24:fe:90:bd:26:
+        a2:30:2d:e8:97:26:57:35:89:74:96:18:f6:15:e2:af:24:19:
+        56:02:02:b2:ba:0f:14:ea:c6:8a:66:c1:86:45:55:8b:be:92:
+        be:9c:a4:04:c7:49:3c:9e:e8:29:7a:89:d7:fe:af:ff:68:f5:
+        a5:17:90:bd:ac:99:cc:a5:86:57:09:67:46:db:d6:16:c2:46:
+        f1:e4:a9:50:f5:8f:d1:92:15:d3:5f:3e:c6:00:49:3a:6e:58:
+        b2:d1:d1:27:0d:25:c8:32:f8:20:11:cd:7d:32:33:48:94:54:
+        4c:dd:dc:79:c4:30:9f:eb:8e:b8:55:b5:d7:88:5c:c5:6a:24:
+        3d:b2:d3:05:03:51:c6:07:ef:cc:14:72:74:3d:6e:72:ce:18:
+        28:8c:4a:a0:77:e5:09:2b:45:44:47:ac:b7:67:7f:01:8a:05:
+        5a:93:be:a1:c1:ff:f8:e7:0e:67:a4:47:49:76:5d:75:90:1a:
+        f5:26:8f:f0
 SHA1 Fingerprint=33:9B:6B:14:50:24:9B:55:7A:01:87:72:84:D9:E0:2F:C3:D2:D8:E9
 -----BEGIN CERTIFICATE-----
 MIIExTCCA62gAwIBAgIBADANBgkqhkiG9w0BAQUFADB9MQswCQYDVQQGEwJFVTEn
diff --git a/secure/caroot/blacklisted/Certum_Root_CA.pem b/secure/caroot/blacklisted/Certum_Root_CA.pem
index c94db94aecaa..1df73e0c7336 100644
--- a/secure/caroot/blacklisted/Certum_Root_CA.pem
+++ b/secure/caroot/blacklisted/Certum_Root_CA.pem
@@ -21,7 +21,7 @@ Certificate:
         Subject: C = PL, O = Unizeto Sp. z o.o., CN = Certum CA
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:ce:b1:c1:2e:d3:4f:7c:cd:25:ce:18:3e:4f:c4:
                     8c:6f:80:6a:73:c8:5b:51:f8:9b:d2:dc:bb:00:5c:
@@ -46,21 +46,22 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
     Signature Algorithm: sha1WithRSAEncryption
-         b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
-         6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
-         b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
-         2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
-         9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
-         8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
-         bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
-         43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
-         0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
-         51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
-         f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
-         6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
-         18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
-         29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
-         06:16:2c:73
+    Signature Value:
+        b8:8d:ce:ef:e7:14:ba:cf:ee:b0:44:92:6c:b4:39:3e:a2:84:
+        6e:ad:b8:21:77:d2:d4:77:82:87:e6:20:41:81:ee:e2:f8:11:
+        b7:63:d1:17:37:be:19:76:24:1c:04:1a:4c:eb:3d:aa:67:6f:
+        2d:d4:cd:fe:65:31:70:c5:1b:a6:02:0a:ba:60:7b:6d:58:c2:
+        9a:49:fe:63:32:0b:6b:e3:3a:c0:ac:ab:3b:b0:e8:d3:09:51:
+        8c:10:83:c6:34:e0:c5:2b:e0:1a:b6:60:14:27:6c:32:77:8c:
+        bc:b2:72:98:cf:cd:cc:3f:b9:c8:24:42:14:d6:57:fc:e6:26:
+        43:a9:1d:e5:80:90:ce:03:54:28:3e:f7:3f:d3:f8:4d:ed:6a:
+        0a:3a:93:13:9b:3b:14:23:13:63:9c:3f:d1:87:27:79:e5:4c:
+        51:e3:01:ad:85:5d:1a:3b:b1:d5:73:10:a4:d3:f2:bc:6e:64:
+        f5:5a:56:90:a8:c7:0e:4c:74:0f:2e:71:3b:f7:c8:47:f4:69:
+        6f:15:f2:11:5e:83:1e:9c:7c:52:ae:fd:02:da:12:a8:59:67:
+        18:db:bc:70:dd:9b:b1:69:ed:80:ce:89:40:48:6a:0e:35:ca:
+        29:66:15:21:94:2c:e8:60:2a:9b:85:4a:40:f3:6b:8a:24:ec:
+        06:16:2c:73
 SHA1 Fingerprint=62:52:DC:40:F7:11:43:A2:2F:DE:9E:F7:34:8E:06:42:51:B1:81:18
 -----BEGIN CERTIFICATE-----
 MIIDDDCCAfSgAwIBAgIDAQAgMA0GCSqGSIb3DQEBBQUAMD4xCzAJBgNVBAYTAlBM
diff --git a/secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem b/secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
index 0133aff5f03f..b40288095005 100644
--- a/secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
+++ b/secure/caroot/blacklisted/Chambers_of_Commerce_Root_-_2008.pem
@@ -22,7 +22,7 @@ Certificate:
         Subject: C = EU, L = Madrid (see current address at www.camerfirma.com/address), serialNumber = A82743287, O = AC Camerfirma S.A., CN = Chambers of Commerce Root - 2008
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:af:00:cb:70:37:2b:80:5a:4a:3a:6c:78:94:7d:
                     a3:7f:1a:1f:f6:35:d5:bd:db:cb:0d:44:72:3e:26:
@@ -67,45 +67,44 @@ Certificate:
                 F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
             X509v3 Authority Key Identifier: 
                 keyid:F9:24:AC:0F:B2:B5:F8:79:C0:FA:60:88:1B:C4:D9:4D:02:9E:17:19
-                DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
+                DirName:/C=EU/L=Madrid (see current address at www.camerfirma.com\/address)/serialNumber=A82743287/O=AC Camerfirma S.A./CN=Chambers of Commerce Root - 2008
                 serial:A3:DA:42:7E:A4:B1:AE:DA
-
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
             X509v3 Certificate Policies: 
                 Policy: X509v3 Any Policy
                   CPS: http://policy.camerfirma.com
-
     Signature Algorithm: sha1WithRSAEncryption
-         90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
-         3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
-         e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
-         c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
-         13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
-         c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
-         92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
-         56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
-         90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
-         7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
-         08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
-         45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
-         ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
-         97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
-         29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
-         f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
-         b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
-         a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
-         d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
-         cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
-         20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
-         f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
-         c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
-         18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
-         bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
-         be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
-         82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
-         0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
-         7c:80:c5:f0:d9:77:48:d0
+    Signature Value:
+        90:12:af:22:35:c2:a3:39:f0:2e:de:e9:b5:e9:78:7c:48:be:
+        3f:7d:45:92:5e:e9:da:b1:19:fc:16:3c:9f:b4:5b:66:9e:6a:
+        e7:c3:b9:5d:88:e8:0f:ad:cf:23:0f:de:25:3a:5e:cc:4f:a5:
+        c1:b5:2d:ac:24:d2:58:07:de:a2:cf:69:84:60:33:e8:10:0d:
+        13:a9:23:d0:85:e5:8e:7b:a6:9e:3d:72:13:72:33:f5:aa:7d:
+        c6:63:1f:08:f4:fe:01:7f:24:cf:2b:2c:54:09:de:e2:2b:6d:
+        92:c6:39:4f:16:ea:3c:7e:7a:46:d4:45:6a:46:a8:eb:75:82:
+        56:a7:ab:a0:7c:68:13:33:f6:9d:30:f0:6f:27:39:24:23:2a:
+        90:fd:90:29:35:f2:93:df:34:a5:c6:f7:f8:ef:8c:0f:62:4a:
+        7c:ae:d3:f5:54:f8:8d:b6:9a:56:87:16:82:3a:33:ab:5a:22:
+        08:f7:82:ba:ea:2e:e0:47:9a:b4:b5:45:a3:05:3b:d9:dc:2e:
+        45:40:3b:ea:dc:7f:e8:3b:eb:d1:ec:26:d8:35:a4:30:c5:3a:
+        ac:57:9e:b3:76:a5:20:7b:f9:1e:4a:05:62:01:a6:28:75:60:
+        97:92:0d:6e:3e:4d:37:43:0d:92:15:9c:18:22:cd:51:99:a0:
+        29:1a:3c:5f:8a:32:33:5b:30:c7:89:2f:47:98:0f:a3:03:c6:
+        f6:f1:ac:df:32:f0:d9:81:1a:e4:9c:bd:f6:80:14:f0:d1:2c:
+        b9:85:f5:d8:a3:b1:c8:a5:21:e5:1c:13:97:ee:0e:bd:df:29:
+        a9:ef:34:53:5b:d3:e4:6a:13:84:06:b6:32:02:c4:52:ae:22:
+        d2:dc:b2:21:42:1a:da:40:f0:29:c9:ec:0a:0c:5c:e2:d0:ba:
+        cc:48:d3:37:0a:cc:12:0a:8a:79:b0:3d:03:7f:69:4b:f4:34:
+        20:7d:b3:34:ea:8e:4b:64:f5:3e:fd:b3:23:67:15:0d:04:b8:
+        f0:2d:c1:09:51:3c:b2:6c:15:f0:a5:23:d7:83:74:e4:e5:2e:
+        c9:fe:98:27:42:c6:ab:c6:9e:b0:d0:5b:38:a5:9b:50:de:7e:
+        18:98:b5:45:3b:f6:79:b4:e8:f7:1a:7b:06:83:fb:d0:8b:da:
+        bb:c7:bd:18:ab:08:6f:3c:80:6b:40:3f:19:19:ba:65:8a:e6:
+        be:d5:5c:d3:36:d7:ef:40:52:24:60:38:67:04:31:ec:8f:f3:
+        82:c6:de:b9:55:f3:3b:31:91:5a:dc:b5:08:15:ad:76:25:0a:
+        0d:7b:2e:87:e2:0c:a6:06:bc:26:10:6d:37:9d:ec:dd:78:8c:
+        7c:80:c5:f0:d9:77:48:d0
 SHA1 Fingerprint=78:6A:74:AC:76:AB:14:7F:9C:6A:30:50:BA:9E:A8:7E:FE:9A:CE:3C
 -----BEGIN CERTIFICATE-----
 MIIHTzCCBTegAwIBAgIJAKPaQn6ksa7aMA0GCSqGSIb3DQEBBQUAMIGuMQswCQYD
diff --git a/secure/caroot/blacklisted/Cybertrust_Global_Root.pem b/secure/caroot/blacklisted/Cybertrust_Global_Root.pem
index 0a1c5a632dce..657a1b7b683c 100644
--- a/secure/caroot/blacklisted/Cybertrust_Global_Root.pem
+++ b/secure/caroot/blacklisted/Cybertrust_Global_Root.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: O = "Cybertrust, Inc", CN = Cybertrust Global Root
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:f8:c8:bc:bd:14:50:66:13:ff:f0:d3:79:ec:23:
                     f2:b7:1a:c7:8e:85:f1:12:73:a6:19:aa:10:db:9c:
@@ -53,29 +53,27 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 B6:08:7B:0D:7A:CC:AC:20:4C:86:56:32:5E:CF:AB:6E:85:2D:70:57
             X509v3 CRL Distribution Points: 
-
                 Full Name:
                   URI:http://www2.public-trust.com/crl/ct/ctroot.crl
-
             X509v3 Authority Key Identifier: 
-                keyid:B6:08:7B:0D:7A:CC:AC:20:4C:86:56:32:5E:CF:AB:6E:85:2D:70:57
-
+                B6:08:7B:0D:7A:CC:AC:20:4C:86:56:32:5E:CF:AB:6E:85:2D:70:57
     Signature Algorithm: sha1WithRSAEncryption
-         56:ef:0a:23:a0:54:4e:95:97:c9:f8:89:da:45:c1:d4:a3:00:
-         25:f4:1f:13:ab:b7:a3:85:58:69:c2:30:ad:d8:15:8a:2d:e3:
-         c9:cd:81:5a:f8:73:23:5a:a7:7c:05:f3:fd:22:3b:0e:d1:06:
-         c4:db:36:4c:73:04:8e:e5:b0:22:e4:c5:f3:2e:a5:d9:23:e3:
-         b8:4e:4a:20:a7:6e:02:24:9f:22:60:67:7b:8b:1d:72:09:c5:
-         31:5c:e9:79:9f:80:47:3d:ad:a1:0b:07:14:3d:47:ff:03:69:
-         1a:0c:0b:44:e7:63:25:a7:7f:b2:c9:b8:76:84:ed:23:f6:7d:
-         07:ab:45:7e:d3:df:b3:bf:e9:8a:b6:cd:a8:a2:67:2b:52:d5:
-         b7:65:f0:39:4c:63:a0:91:79:93:52:0f:54:dd:83:bb:9f:d1:
-         8f:a7:53:73:c3:cb:ff:30:ec:7c:04:b8:d8:44:1f:93:5f:71:
-         09:22:b7:6e:3e:ea:1c:03:4e:9d:1a:20:61:fb:81:37:ec:5e:
-         fc:0a:45:ab:d7:e7:17:55:d0:a0:ea:60:9b:a6:f6:e3:8c:5b:
-         29:c2:06:60:14:9d:2d:97:4c:a9:93:15:9d:61:c4:01:5f:48:
-         d6:58:bd:56:31:12:4e:11:c8:21:e0:b3:11:91:65:db:b4:a6:
-         88:38:ce:55
+    Signature Value:
+        56:ef:0a:23:a0:54:4e:95:97:c9:f8:89:da:45:c1:d4:a3:00:
+        25:f4:1f:13:ab:b7:a3:85:58:69:c2:30:ad:d8:15:8a:2d:e3:
+        c9:cd:81:5a:f8:73:23:5a:a7:7c:05:f3:fd:22:3b:0e:d1:06:
+        c4:db:36:4c:73:04:8e:e5:b0:22:e4:c5:f3:2e:a5:d9:23:e3:
+        b8:4e:4a:20:a7:6e:02:24:9f:22:60:67:7b:8b:1d:72:09:c5:
+        31:5c:e9:79:9f:80:47:3d:ad:a1:0b:07:14:3d:47:ff:03:69:
+        1a:0c:0b:44:e7:63:25:a7:7f:b2:c9:b8:76:84:ed:23:f6:7d:
+        07:ab:45:7e:d3:df:b3:bf:e9:8a:b6:cd:a8:a2:67:2b:52:d5:
+        b7:65:f0:39:4c:63:a0:91:79:93:52:0f:54:dd:83:bb:9f:d1:
+        8f:a7:53:73:c3:cb:ff:30:ec:7c:04:b8:d8:44:1f:93:5f:71:
+        09:22:b7:6e:3e:ea:1c:03:4e:9d:1a:20:61:fb:81:37:ec:5e:
+        fc:0a:45:ab:d7:e7:17:55:d0:a0:ea:60:9b:a6:f6:e3:8c:5b:
+        29:c2:06:60:14:9d:2d:97:4c:a9:93:15:9d:61:c4:01:5f:48:
+        d6:58:bd:56:31:12:4e:11:c8:21:e0:b3:11:91:65:db:b4:a6:
+        88:38:ce:55
 SHA1 Fingerprint=5F:43:E5:B1:BF:F8:78:8C:AC:1C:C7:CA:4A:9A:C6:22:2B:CC:34:C6
 -----BEGIN CERTIFICATE-----
 MIIDoTCCAomgAwIBAgILBAAAAAABD4WqLUgwDQYJKoZIhvcNAQEFBQAwOzEYMBYG
diff --git a/secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem b/secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
index 0de1a5b43dce..81d66de7a736 100644
--- a/secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
+++ b/secure/caroot/blacklisted/D-TRUST_Root_CA_3_2013.pem
@@ -21,7 +21,7 @@ Certificate:
         Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST Root CA 3 2013
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:c4:7b:42:92:82:1f:ec:ed:54:98:8e:12:c0:ca:
                     09:df:93:6e:3a:93:5c:1b:e4:10:77:9e:4e:69:88:
@@ -50,29 +50,27 @@ Certificate:
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
             X509v3 CRL Distribution Points: 
-
                 Full Name:
                   URI:ldap://directory.d-trust.net/CN=D-TRUST%20Root%20CA%203%202013,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
-
                 Full Name:
                   URI:http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl
-
     Signature Algorithm: sha256WithRSAEncryption
-         0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
-         4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
-         c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
-         05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
-         01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
-         a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
-         c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
-         9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
-         ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
-         a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
-         8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
-         ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
-         2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
-         72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
-         75:49:5f:5c
+    Signature Value:
+        0e:59:0e:58:e4:74:48:23:44:cf:34:21:b5:9c:14:1a:ad:9a:
+        4b:b7:b3:88:6d:5c:a9:17:70:f0:2a:9f:8d:7b:f9:7b:85:fa:
+        c7:39:e8:10:08:b0:35:2b:5f:cf:02:d2:d3:9c:c8:0b:1e:ee:
+        05:54:ae:37:93:04:09:7d:6c:8f:c2:74:bc:f8:1c:94:be:31:
+        01:40:2d:f3:24:20:b7:84:55:2c:5c:c8:f5:74:4a:10:19:8b:
+        a3:c7:ed:35:d6:09:48:d3:0e:c0:ba:39:a8:b0:46:02:b0:db:
+        c6:88:59:c2:be:fc:7b:b1:2b:cf:7e:62:87:55:96:cc:01:6f:
+        9b:67:21:95:35:8b:f8:10:fc:71:1b:b7:4b:37:69:a6:3b:d6:
+        ec:8b:ee:c1:b0:f3:25:c9:8f:92:7d:a1:ea:c3:ca:44:bf:26:
+        a5:74:92:9c:e3:74:eb:9d:74:d9:cb:4d:87:d8:fc:b4:69:6c:
+        8b:a0:43:07:60:78:97:e9:d9:93:7c:c2:46:bc:9b:37:52:a3:
+        ed:8a:3c:13:a9:7b:53:4b:49:9a:11:05:2c:0b:6e:56:ac:1f:
+        2e:82:6c:e0:69:67:b5:0e:6d:2d:d9:e4:c0:15:f1:3f:fa:18:
+        72:e1:15:6d:27:5b:2d:30:28:2b:9f:48:9a:64:2b:99:ef:f2:
+        75:49:5f:5c
 SHA1 Fingerprint=6C:7C:CC:E7:D4:AE:51:5F:99:08:CD:3F:F6:E8:C3:78:DF:6F:EF:97
 -----BEGIN CERTIFICATE-----
 MIIEDjCCAvagAwIBAgIDD92sMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkRF
diff --git a/secure/caroot/blacklisted/DST_Root_CA_X3.pem b/secure/caroot/blacklisted/DST_Root_CA_X3.pem
index e9574b162807..2b0739bfe36e 100644
--- a/secure/caroot/blacklisted/DST_Root_CA_X3.pem
+++ b/secure/caroot/blacklisted/DST_Root_CA_X3.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: O = Digital Signature Trust Co., CN = DST Root CA X3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (2048 bit)
+                Public-Key: (2048 bit)
                 Modulus:
                     00:df:af:e9:97:50:08:83:57:b4:cc:62:65:f6:90:
                     82:ec:c7:d3:2c:6b:30:ca:5b:ec:d9:c3:7d:c7:40:
@@ -53,21 +53,22 @@ Certificate:
             X509v3 Subject Key Identifier: 
                 C4:A7:B1:A4:7B:2C:71:FA:DB:E1:4B:90:75:FF:C4:15:60:85:89:10
     Signature Algorithm: sha1WithRSAEncryption
-         a3:1a:2c:9b:17:00:5c:a9:1e:ee:28:66:37:3a:bf:83:c7:3f:
-         4b:c3:09:a0:95:20:5d:e3:d9:59:44:d2:3e:0d:3e:bd:8a:4b:
-         a0:74:1f:ce:10:82:9c:74:1a:1d:7e:98:1a:dd:cb:13:4b:b3:
-         20:44:e4:91:e9:cc:fc:7d:a5:db:6a:e5:fe:e6:fd:e0:4e:dd:
-         b7:00:3a:b5:70:49:af:f2:e5:eb:02:f1:d1:02:8b:19:cb:94:
-         3a:5e:48:c4:18:1e:58:19:5f:1e:02:5a:f0:0c:f1:b1:ad:a9:
-         dc:59:86:8b:6e:e9:91:f5:86:ca:fa:b9:66:33:aa:59:5b:ce:
-         e2:a7:16:73:47:cb:2b:cc:99:b0:37:48:cf:e3:56:4b:f5:cf:
-         0f:0c:72:32:87:c6:f0:44:bb:53:72:6d:43:f5:26:48:9a:52:
-         67:b7:58:ab:fe:67:76:71:78:db:0d:a2:56:14:13:39:24:31:
-         85:a2:a8:02:5a:30:47:e1:dd:50:07:bc:02:09:90:00:eb:64:
-         63:60:9b:16:bc:88:c9:12:e6:d2:7d:91:8b:f9:3d:32:8d:65:
-         b4:e9:7c:b1:57:76:ea:c5:b6:28:39:bf:15:65:1c:c8:f6:77:
-         96:6a:0a:8d:77:0b:d8:91:0b:04:8e:07:db:29:b6:0a:ee:9d:
-         82:35:35:10
+    Signature Value:
+        a3:1a:2c:9b:17:00:5c:a9:1e:ee:28:66:37:3a:bf:83:c7:3f:
+        4b:c3:09:a0:95:20:5d:e3:d9:59:44:d2:3e:0d:3e:bd:8a:4b:
+        a0:74:1f:ce:10:82:9c:74:1a:1d:7e:98:1a:dd:cb:13:4b:b3:
+        20:44:e4:91:e9:cc:fc:7d:a5:db:6a:e5:fe:e6:fd:e0:4e:dd:
+        b7:00:3a:b5:70:49:af:f2:e5:eb:02:f1:d1:02:8b:19:cb:94:
+        3a:5e:48:c4:18:1e:58:19:5f:1e:02:5a:f0:0c:f1:b1:ad:a9:
+        dc:59:86:8b:6e:e9:91:f5:86:ca:fa:b9:66:33:aa:59:5b:ce:
+        e2:a7:16:73:47:cb:2b:cc:99:b0:37:48:cf:e3:56:4b:f5:cf:
+        0f:0c:72:32:87:c6:f0:44:bb:53:72:6d:43:f5:26:48:9a:52:
+        67:b7:58:ab:fe:67:76:71:78:db:0d:a2:56:14:13:39:24:31:
+        85:a2:a8:02:5a:30:47:e1:dd:50:07:bc:02:09:90:00:eb:64:
+        63:60:9b:16:bc:88:c9:12:e6:d2:7d:91:8b:f9:3d:32:8d:65:
+        b4:e9:7c:b1:57:76:ea:c5:b6:28:39:bf:15:65:1c:c8:f6:77:
+        96:6a:0a:8d:77:0b:d8:91:0b:04:8e:07:db:29:b6:0a:ee:9d:
+        82:35:35:10
 SHA1 Fingerprint=DA:C9:02:4F:54:D8:F6:DF:94:93:5F:B1:73:26:38:CA:6A:D7:7C:13
 -----BEGIN CERTIFICATE-----
 MIIDSjCCAjKgAwIBAgIQRK+wgNajJ7qJMDmGLvhAazANBgkqhkiG9w0BAQUFADA/
diff --git a/secure/caroot/trusted/E-Tugra_Certification_Authority.pem b/secure/caroot/blacklisted/E-Tugra_Certification_Authority.pem
similarity index 75%
rename from secure/caroot/trusted/E-Tugra_Certification_Authority.pem
rename to secure/caroot/blacklisted/E-Tugra_Certification_Authority.pem
index 95a0ba7e8de6..c37e3aa0ce59 100644
--- a/secure/caroot/trusted/E-Tugra_Certification_Authority.pem
+++ b/secure/caroot/blacklisted/E-Tugra_Certification_Authority.pem
@@ -23,7 +23,7 @@ Certificate:
         Subject: C = TR, L = Ankara, O = E-Tu\C4\9Fra EBG Bili\C5\9Fim Teknolojileri ve Hizmetleri A.\C5\9E., OU = E-Tugra Sertifikasyon Merkezi, CN = E-Tugra Certification Authority
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:e2:f5:3f:93:05:51:1e:85:62:54:5e:7a:0b:f5:
                     18:07:83:ae:7e:af:7c:f7:d4:8a:6b:a5:63:43:39:
@@ -67,40 +67,40 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
-                keyid:2E:E3:DB:B2:49:D0:9C:54:79:5C:FA:27:2A:FE:CC:4E:D2:E8:4E:54
-
+                2E:E3:DB:B2:49:D0:9C:54:79:5C:FA:27:2A:FE:CC:4E:D2:E8:4E:54
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-         05:37:3a:f4:4d:b7:45:e2:45:75:24:8f:b6:77:52:e8:1c:d8:
-         10:93:65:f3:f2:59:06:a4:3e:1e:29:ec:5d:d1:d0:ab:7c:e0:
-         0a:90:48:78:ed:4e:98:03:99:fe:28:60:91:1d:30:1d:b8:63:
-         7c:a8:e6:35:b5:fa:d3:61:76:e6:d6:07:4b:ca:69:9a:b2:84:
-         7a:77:93:45:17:15:9f:24:d0:98:13:12:ff:bb:a0:2e:fd:4e:
-         4c:87:f8:ce:5c:aa:98:1b:05:e0:00:46:4a:82:80:a5:33:8b:
-         28:dc:ed:38:d3:df:e5:3e:e9:fe:fb:59:dd:61:84:4f:d2:54:
-         96:13:61:13:3e:8f:80:69:be:93:47:b5:35:43:d2:5a:bb:3d:
-         5c:ef:b3:42:47:cd:3b:55:13:06:b0:09:db:fd:63:f6:3a:88:
-         0a:99:6f:7e:e1:ce:1b:53:6a:44:66:23:51:08:7b:bc:5b:52:
-         a2:fd:06:37:38:40:61:8f:4a:96:b8:90:37:f8:66:c7:78:90:
-         00:15:2e:8b:ad:51:35:53:07:a8:6b:68:ae:f9:4e:3c:07:26:
-         cd:08:05:70:cc:39:3f:76:bd:a5:d3:67:26:01:86:a6:53:d2:
-         60:3b:7c:43:7f:55:8a:bc:95:1a:c1:28:39:4c:1f:43:d2:91:
-         f4:72:59:8a:b9:56:fc:3f:b4:9d:da:70:9c:76:5a:8c:43:50:
-         ee:8e:30:72:4d:df:ff:49:f7:c6:a9:67:d9:6d:ac:02:11:e2:
-         3a:16:25:a7:58:08:cb:6f:53:41:9c:48:38:47:68:33:d1:d7:
-         c7:8f:d4:74:21:d4:c3:05:90:7a:ff:ce:96:88:b1:15:29:5d:
-         23:ab:d0:60:a1:12:4f:de:f4:17:cd:32:e5:c9:bf:c8:43:ad:
-         fd:2e:8e:f1:af:e2:f4:98:fa:12:1f:20:d8:c0:a7:0c:85:c5:
-         90:f4:3b:2d:96:26:b1:2c:be:4c:ab:eb:b1:d2:8a:c9:db:78:
-         13:0f:1e:09:9d:6d:8f:00:9f:02:da:c1:fa:1f:7a:7a:09:c4:
-         4a:e6:88:2a:97:9f:89:8b:fd:37:5f:5f:3a:ce:38:59:86:4b:
-         af:71:0b:b4:d8:f2:70:4f:9f:32:13:e3:b0:a7:57:e5:da:da:
-         43:cb:84:34:f2:28:c4:ea:6d:f4:2a:ef:c1:6b:76:da:fb:7e:
-         bb:85:3c:d2:53:c2:4d:be:71:e1:45:d1:fd:23:67:0d:13:75:
-         fb:cf:65:67:22:9d:ae:b0:09:d1:09:ff:1d:34:bf:fe:23:97:
-         37:d2:39:fa:3d:0d:06:0b:b4:db:3b:a3:ab:6f:5c:1d:b6:7e:
-         e8:b3:82:34:ed:06:5c:24
+    Signature Value:
+        05:37:3a:f4:4d:b7:45:e2:45:75:24:8f:b6:77:52:e8:1c:d8:
+        10:93:65:f3:f2:59:06:a4:3e:1e:29:ec:5d:d1:d0:ab:7c:e0:
+        0a:90:48:78:ed:4e:98:03:99:fe:28:60:91:1d:30:1d:b8:63:
+        7c:a8:e6:35:b5:fa:d3:61:76:e6:d6:07:4b:ca:69:9a:b2:84:
+        7a:77:93:45:17:15:9f:24:d0:98:13:12:ff:bb:a0:2e:fd:4e:
+        4c:87:f8:ce:5c:aa:98:1b:05:e0:00:46:4a:82:80:a5:33:8b:
+        28:dc:ed:38:d3:df:e5:3e:e9:fe:fb:59:dd:61:84:4f:d2:54:
+        96:13:61:13:3e:8f:80:69:be:93:47:b5:35:43:d2:5a:bb:3d:
+        5c:ef:b3:42:47:cd:3b:55:13:06:b0:09:db:fd:63:f6:3a:88:
+        0a:99:6f:7e:e1:ce:1b:53:6a:44:66:23:51:08:7b:bc:5b:52:
+        a2:fd:06:37:38:40:61:8f:4a:96:b8:90:37:f8:66:c7:78:90:
+        00:15:2e:8b:ad:51:35:53:07:a8:6b:68:ae:f9:4e:3c:07:26:
+        cd:08:05:70:cc:39:3f:76:bd:a5:d3:67:26:01:86:a6:53:d2:
+        60:3b:7c:43:7f:55:8a:bc:95:1a:c1:28:39:4c:1f:43:d2:91:
+        f4:72:59:8a:b9:56:fc:3f:b4:9d:da:70:9c:76:5a:8c:43:50:
+        ee:8e:30:72:4d:df:ff:49:f7:c6:a9:67:d9:6d:ac:02:11:e2:
+        3a:16:25:a7:58:08:cb:6f:53:41:9c:48:38:47:68:33:d1:d7:
+        c7:8f:d4:74:21:d4:c3:05:90:7a:ff:ce:96:88:b1:15:29:5d:
+        23:ab:d0:60:a1:12:4f:de:f4:17:cd:32:e5:c9:bf:c8:43:ad:
+        fd:2e:8e:f1:af:e2:f4:98:fa:12:1f:20:d8:c0:a7:0c:85:c5:
+        90:f4:3b:2d:96:26:b1:2c:be:4c:ab:eb:b1:d2:8a:c9:db:78:
+        13:0f:1e:09:9d:6d:8f:00:9f:02:da:c1:fa:1f:7a:7a:09:c4:
+        4a:e6:88:2a:97:9f:89:8b:fd:37:5f:5f:3a:ce:38:59:86:4b:
+        af:71:0b:b4:d8:f2:70:4f:9f:32:13:e3:b0:a7:57:e5:da:da:
+        43:cb:84:34:f2:28:c4:ea:6d:f4:2a:ef:c1:6b:76:da:fb:7e:
+        bb:85:3c:d2:53:c2:4d:be:71:e1:45:d1:fd:23:67:0d:13:75:
+        fb:cf:65:67:22:9d:ae:b0:09:d1:09:ff:1d:34:bf:fe:23:97:
+        37:d2:39:fa:3d:0d:06:0b:b4:db:3b:a3:ab:6f:5c:1d:b6:7e:
+        e8:b3:82:34:ed:06:5c:24
 SHA1 Fingerprint=51:C6:E7:08:49:06:6E:F3:92:D4:5C:A0:0D:6D:A3:62:8F:C3:52:39
 -----BEGIN CERTIFICATE-----
 MIIGSzCCBDOgAwIBAgIIamg+nFGby1MwDQYJKoZIhvcNAQELBQAwgbIxCzAJBgNV
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem b/secure/caroot/blacklisted/E-Tugra_Global_Root_CA_ECC_v3.pem
similarity index 86%
rename from secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
rename to secure/caroot/blacklisted/E-Tugra_Global_Root_CA_ECC_v3.pem
index 3e58355e78a5..80e67454926a 100644
--- a/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
+++ b/secure/caroot/blacklisted/E-Tugra_Global_Root_CA_ECC_v3.pem
@@ -39,19 +39,19 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
-                keyid:FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
-
+                FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
             X509v3 Subject Key Identifier: 
                 FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: ecdsa-with-SHA384
-         30:66:02:31:00:e6:05:58:69:61:e5:2d:ca:0d:cb:f1:19:08:
-         bd:d6:fd:51:92:1a:7e:63:54:04:90:91:9a:35:91:39:99:fa:
-         07:a9:66:93:ba:c8:68:d4:8a:3f:fa:ed:6e:16:02:27:b7:02:
-         31:00:dd:5a:17:2b:76:1d:65:42:96:a6:ac:5d:8a:79:56:d8:
-         8a:1b:df:9a:de:5f:c7:50:8f:b1:5b:71:0c:26:df:6a:40:00:
-         ec:33:91:21:71:be:68:e4:23:a4:d9:ad:a1:37
+    Signature Value:
+        30:66:02:31:00:e6:05:58:69:61:e5:2d:ca:0d:cb:f1:19:08:
+        bd:d6:fd:51:92:1a:7e:63:54:04:90:91:9a:35:91:39:99:fa:
+        07:a9:66:93:ba:c8:68:d4:8a:3f:fa:ed:6e:16:02:27:b7:02:
+        31:00:dd:5a:17:2b:76:1d:65:42:96:a6:ac:5d:8a:79:56:d8:
+        8a:1b:df:9a:de:5f:c7:50:8f:b1:5b:71:0c:26:df:6a:40:00:
+        ec:33:91:21:71:be:68:e4:23:a4:d9:ad:a1:37
 SHA1 Fingerprint=8A:2F:AF:57:53:B1:B0:E6:A1:04:EC:5B:6A:69:71:6D:F6:1C:E2:84
 -----BEGIN CERTIFICATE-----
 MIICpTCCAiqgAwIBAgIUJkYZdzHhT28oNt45UYbm1JeIIsEwCgYIKoZIzj0EAwMw
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem b/secure/caroot/blacklisted/E-Tugra_Global_Root_CA_RSA_v3.pem
similarity index 75%
rename from secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
rename to secure/caroot/blacklisted/E-Tugra_Global_Root_CA_RSA_v3.pem
index d48fb141df67..fd076cdd2649 100644
--- a/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
+++ b/secure/caroot/blacklisted/E-Tugra_Global_Root_CA_RSA_v3.pem
@@ -24,7 +24,7 @@ Certificate:
         Subject: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA RSA v3
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
-                RSA Public-Key: (4096 bit)
+                Public-Key: (4096 bit)
                 Modulus:
                     00:a2:66:f0:89:b7:72:7b:ee:09:c9:63:d2:d3:43:
                     dd:5e:c3:a6:84:38:4a:f1:8d:81:bb:14:bd:47:e8:
@@ -66,42 +66,42 @@ Certificate:
             X509v3 Basic Constraints: critical
                 CA:TRUE
             X509v3 Authority Key Identifier: 
-                keyid:B2:B4:AE:E6:2D:F7:26:D5:AA:75:2D:76:4B:C0:1B:53:21:D0:48:EF
-
+                B2:B4:AE:E6:2D:F7:26:D5:AA:75:2D:76:4B:C0:1B:53:21:D0:48:EF
             X509v3 Subject Key Identifier: 
                 B2:B4:AE:E6:2D:F7:26:D5:AA:75:2D:76:4B:C0:1B:53:21:D0:48:EF
             X509v3 Key Usage: critical
                 Certificate Sign, CRL Sign
     Signature Algorithm: sha256WithRSAEncryption
-         89:a8:72:7f:8c:eb:ce:2e:18:c4:10:80:2d:10:0c:ff:fb:14:
-         cd:04:e0:14:3c:4e:9a:fb:9f:29:bf:22:9e:57:b9:82:73:12:
-         63:26:b5:cc:90:e9:d2:2a:29:ee:9c:2d:cc:2c:99:be:45:27:
-         e4:b1:71:ed:e4:38:95:31:41:f2:7d:7a:63:78:df:ca:36:16:
-         2f:82:88:9f:bc:11:47:4f:76:4d:c8:2d:8e:eb:df:2d:7c:4e:
-         3b:da:ae:f6:e3:da:5d:14:a6:ae:e8:85:44:9d:06:6e:8e:fb:
-         ef:7a:4a:6a:2d:2b:28:18:fe:bf:90:2c:75:16:9f:0f:ea:96:
-         7d:05:ee:9b:13:a5:44:6c:f8:03:d0:dd:23:e1:fd:03:12:12:
-         08:f4:18:34:b3:e0:37:0b:77:11:01:48:bf:61:b4:b5:f8:19:
-         d9:cb:4d:ea:a3:8c:ef:fd:f0:06:b5:6d:92:f4:4a:61:50:84:
-         ed:ec:49:d3:e4:be:68:e6:2e:e3:31:0b:54:0b:1a:92:d6:82:
-         d8:b6:a2:65:3c:66:04:f9:55:da:6c:fb:db:b5:14:66:4d:94:
-         83:3b:cd:1e:a6:2b:b2:fe:77:40:86:ab:e7:df:0a:c9:fd:f6:
-         dd:87:56:18:d8:b0:2c:55:60:96:fa:08:7e:52:90:f5:4b:a6:
-         2e:87:7c:cb:20:db:06:3e:a0:5d:03:77:7d:a2:3c:13:1b:29:
-         a2:13:55:a0:3d:14:22:af:6f:b8:d0:9a:1b:72:dd:05:01:8d:
-         86:60:bf:a4:67:ee:b5:a5:0d:d1:7f:e6:1a:2b:62:66:c3:07:
-         ba:e7:a0:48:1c:38:c3:e9:45:fb:a7:7f:fc:ed:02:68:1a:ca:
-         77:12:77:a6:00:55:28:14:ec:d6:c7:12:a2:1b:65:42:e9:91:
-         e8:cb:3e:87:89:54:5d:d9:af:9d:97:9c:69:e7:0a:ff:0f:5a:
-         78:8b:63:2a:4c:7d:47:94:3f:de:4b:e9:53:d0:30:f1:c5:f6:
-         9e:49:df:3b:a0:91:a3:a3:fe:cd:58:cc:ea:df:af:6f:28:3b:
-         a0:69:9b:8f:ec:ac:ae:2b:54:9d:9b:04:b1:47:20:af:96:12:
-         3e:63:94:1d:04:e7:2e:bb:86:c7:0c:9a:88:bf:76:47:ef:f7:
-         b0:0b:97:66:d2:44:cf:60:52:07:e1:d5:2c:4a:3a:27:61:77:
-         ca:d7:8f:e7:87:0e:30:ff:0c:bb:04:e2:61:c3:a2:c8:97:61:
-         8e:b4:30:6a:3c:6d:c2:07:5f:4a:73:2f:3f:f9:16:8a:01:66:
-         ef:ba:91:ca:52:57:7b:ae:d4:e6:0f:dd:0b:7a:7f:8b:9e:26:
-         20:cf:3b:ef:81:71:83:59
+    Signature Value:
+        89:a8:72:7f:8c:eb:ce:2e:18:c4:10:80:2d:10:0c:ff:fb:14:
+        cd:04:e0:14:3c:4e:9a:fb:9f:29:bf:22:9e:57:b9:82:73:12:
+        63:26:b5:cc:90:e9:d2:2a:29:ee:9c:2d:cc:2c:99:be:45:27:
+        e4:b1:71:ed:e4:38:95:31:41:f2:7d:7a:63:78:df:ca:36:16:
+        2f:82:88:9f:bc:11:47:4f:76:4d:c8:2d:8e:eb:df:2d:7c:4e:
+        3b:da:ae:f6:e3:da:5d:14:a6:ae:e8:85:44:9d:06:6e:8e:fb:
+        ef:7a:4a:6a:2d:2b:28:18:fe:bf:90:2c:75:16:9f:0f:ea:96:
+        7d:05:ee:9b:13:a5:44:6c:f8:03:d0:dd:23:e1:fd:03:12:12:
+        08:f4:18:34:b3:e0:37:0b:77:11:01:48:bf:61:b4:b5:f8:19:
+        d9:cb:4d:ea:a3:8c:ef:fd:f0:06:b5:6d:92:f4:4a:61:50:84:
+        ed:ec:49:d3:e4:be:68:e6:2e:e3:31:0b:54:0b:1a:92:d6:82:
+        d8:b6:a2:65:3c:66:04:f9:55:da:6c:fb:db:b5:14:66:4d:94:
+        83:3b:cd:1e:a6:2b:b2:fe:77:40:86:ab:e7:df:0a:c9:fd:f6:
+        dd:87:56:18:d8:b0:2c:55:60:96:fa:08:7e:52:90:f5:4b:a6:
+        2e:87:7c:cb:20:db:06:3e:a0:5d:03:77:7d:a2:3c:13:1b:29:
+        a2:13:55:a0:3d:14:22:af:6f:b8:d0:9a:1b:72:dd:05:01:8d:
+        86:60:bf:a4:67:ee:b5:a5:0d:d1:7f:e6:1a:2b:62:66:c3:07:
+        ba:e7:a0:48:1c:38:c3:e9:45:fb:a7:7f:fc:ed:02:68:1a:ca:
+        77:12:77:a6:00:55:28:14:ec:d6:c7:12:a2:1b:65:42:e9:91:
*** 10683 LINES SKIPPED ***



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202309112202.38BM2skI006276>