Fri Jun 10 13:14:10 2022 UTC ()
security/ca-certificates: Clarify and adjust language

Point out that this is from Debian and that Debian's policy is unclear
(it's not on HOMEPAGE at least; they probably do have one).

Note that modification outside of the package's files is either to
base or to pkgsrc openssl.

Clarify that there's a supported way to exclude particular certs as
trust anchors.


(gdt)
diff -r1.3 -r1.4 pkgsrc/security/ca-certificates/DESCR

cvs diff -r1.3 -r1.4 pkgsrc/security/ca-certificates/DESCR (expand / switch to unified diff)

--- pkgsrc/security/ca-certificates/DESCR 2021/07/20 12:59:06 1.3
+++ pkgsrc/security/ca-certificates/DESCR 2022/06/10 13:14:10 1.4
@@ -1,12 +1,20 @@ @@ -1,12 +1,20 @@
1This package provides the certificates distributed by the Mozilla 1This package provides the root certificates distributed by the Mozilla
2Project and will, by default, install certificates trusted by the 2Project as curated by Debian in their package of the same name, along
3Mozilla Project in the system OpenSSL certificate store. Modification 3with tools to manage the set of configured trust anchors for openssl.
4of system configuration files is very irregular as pkgsrc should not 
5write anything outside of ${PREFIX}. 
6 4
7The sysadmin can configure the list of trusted certificates and also 5\todo Explain if Debian adds or removes, or if this is exactly the
8add local certificates as needed by editing ca-certificates.conf and 6same set.
9re-running update-ca-certificates. 7
 8NB: Installing this package will modify the configuration of the
 9openssl implementation used by pkgsrc, which is either the base system
 10openssl or pkgsrc openssl. The modification is configuring every
 11certificate as a trust anchor. Modification of system configuration
 12files is very irregular as pkgsrc should not write anything outside of
 13${PREFIX}.
 14
 15The sysadmin can exclude CA certificates from the list of trust
 16anchors and also add local certificates as configured trust anchors by
 17editing ca-certificates.conf and re-running update-ca-certificates.
10 18
11See also the mozilla-rootcerts and mozilla-rootcerts-openssl packages 19See also the mozilla-rootcerts and mozilla-rootcerts-openssl packages
12for an alternative approach. 20for an alternative approach.