Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 26 Jun 2018 09:22:41 +0000
From:      bugzilla-noreply@freebsd.org
To:        java@FreeBSD.org
Subject:   [Bug 229329] java/openjdk8: allow user to trust extra local certificates
Message-ID:  <bug-229329-8522-g7Pjn2hDzC@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-229329-8522@https.bugs.freebsd.org/bugzilla/>
References:  <bug-229329-8522@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D229329

--- Comment #5 from Michael Osipov <1983-01-06@gmx.net> ---
(In reply to Palle Girgensohn from comment #4)

Switching to security/ca_root_nss would solve my problem if and only if bug
160387 would be resolved. It would make cert usage on the system consistent
across implementations within a company.

What I did for the moment is

> $ svn diff /usr/ports/security/ca_root_nss/
> Index: /usr/ports/security/ca_root_nss/Makefile
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> --- /usr/ports/security/ca_root_nss/Makefile    (Revision 473303)
> +++ /usr/ports/security/ca_root_nss/Makefile    (Arbeitskopie)
> @@ -54,6 +54,7 @@
>                 ${PERL} ${WRKDIR}/${BUNDLE_PROCESSOR} \
>             < ${WRKDIR}/certdata.txt > \
>             ${WRKDIR}/ca-root-nss.crt
> +       @${CAT} ${FILESDIR}/siemens_ca_certificates.pem >> ${WRKDIR}/ca-r=
oot-nss.crt
>=20
>  do-install:
>         ${MKDIR} ${STAGEDIR}${PREFIX}/${CERTDIR}


Ignoring cert errors is absolutely not an option.

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-229329-8522-g7Pjn2hDzC>