Changeset da0166b2
- Timestamp:
- 11/22/2016 05:41:16 AM (7 years ago)
- Branches:
- 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 12.0, 12.1, 8.0, 8.1, 8.2, 8.3, 8.4, 9.0, 9.1, basic, bdubbs/svn, elogind, kea, ken/TL2024, ken/inkscape-core-mods, ken/tuningfonts, lazarus, lxqt, nosym, perl-modules, plabs/newcss, plabs/python-mods, python3.11, qt5new, rahul/power-profiles-daemon, renodr/vulkan-addition, trunk, upgradedb, xry111/intltool, xry111/llvm18, xry111/soup3, xry111/test-20220226, xry111/xf86-video-removal
- Children:
- d74c5dc
- Parents:
- 9d2c282
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
postlfs/security/cacerts.xml
r9d2c282 rda0166b2 37 37 <para>Establishing trust with a CA involves validating things like company 38 38 address, ownership, contact information, etc., and ensuring that the CA has 39 followed best practices, such as u dergoing periodic security audits by40 independent invest egators and maintaining an always avaialable certificate39 followed best practices, such as undergoing periodic security audits by 40 independent investigators and maintaining an always available certificate 41 41 revocation list. This is well outside the scope of BLFS (as it is for most 42 42 Linux distributions). The certificate store provided here is taken from the … … 105 105 for use in multiple certificate stores (if the associated applications are 106 106 present on the system). Additionally, any local certificates stored in 107 <filename>/etc/ssl/local</filename> will be imported to the cer itificate107 <filename>/etc/ssl/local</filename> will be imported to the certificate 108 108 stores. Certificates in this directory should be stored as PEM encoded 109 109 <application>OpenSSL</application> trusted certificates.</para> … … 140 140 141 141 <para>As the <systemitem class="username">root</systemitem> user, make sure 142 that certdata.txt is in the current direc otry, and update the certificate142 that certdata.txt is in the current directory, and update the certificate 143 143 stores with the following command:</para> 144 144 … … 154 154 <para>The <filename>certdata.txt</filename> file provided by BLFS is 155 155 obtained from the mozilla-release branch, and is modified to provide a 156 simple dated revision. This will be the correct ver ision for most156 simple dated revision. This will be the correct version for most 157 157 systems. There are, however, several other variants of the file available 158 158 for use that might be preferred for one reason or another, including all 159 Mozilla products in this book. RedHat and OpenSUSE, for insta ce, use the159 Mozilla products in this book. RedHat and OpenSUSE, for instance, use the 160 160 version included in <xref linkend="nss"/>. Additional download locations 161 161 are available at:</para> … … 168 168 </listitem> 169 169 <listitem> 170 <para>NSS (this is the latest availa lbe version):170 <para>NSS (this is the latest available version): 171 171 <ulink url="&certhost;projects/nss/raw-file/tip/lib&certpath;"/> 172 172 </para>
Note:
See TracChangeset
for help on using the changeset viewer.