#1107237 Migrate 20240203 to stable

#1107237#5
Date:
2025-06-03 12:18:25 UTC
From:
To:
Version 20240203 contains new CAs, most notably Sectigo Public Server
Authentication Root. Sectigo seems to have recently started issuing
certificates with this new root certificate. Please consider migrating
20240203 to stable, as its absence will most definitely cause userland
issues.

#1107237#10
Date:
2025-06-05 11:25:35 UTC
From:
To:
I can attest to this. I have just been issued a certificate by Sectigo with the new CA. All our Bookworm servers now refuse to communicate with the server this certificate is used on.
#1107237#15
Date:
2025-06-11 13:58:19 UTC
From:
To:
At  March 1st, May 15th and June 2nd, Sectigo transitioned to new root
certificates that are not included in the current stable ca-certificates
package. This means that any new Sectigo certificate will not be trusted by
Debian bookworm, which is starting to result in errors and will continue to
get worse as expiring certificates are replaced with new ones.

See also
https://www.sectigo.com/faqs/detail/Sectigo-Public-Intermediates-and-Roots/kA0Uj0000003eov


Although this can be mitigated by either manually installing the new root
certificates on each machine, or by adding the testing/trixy repository to
get 20250419, or downloading the .deb and manually install it; it would be
highly preferred if a more recent version is included in bookworm.

Tom

#1107237#20
Date:
2025-07-03 06:28:36 UTC
From:
To:
I noticed yesterday that an updated ca-certificates package was installed during a routine update, which contains the new Sectigo CA root. Thanks for providing this update!
#1107237#25
Date:
2025-12-17 12:04:09 UTC
From:
To:
Hello,

El 03/06/25 a las 14:18, William David Edwards escribió:
since bookworm was the stable version when this bug was filed, on
2025-06-03.

This was fixed with 20230311+deb12u1:
https://tracker.debian.org/news/1648789/accepted-ca-certificates-20230311deb12u1-source-into-proposed-updates/,
and actually could be (force)merged with #1095913.

I don't want to step on the maintainer's toes, so unless Julien agrees
on that, I am not planning to change the status of this bug.

Best,

#1107237#30
Date:
2026-02-23 16:40:38 UTC
From:
To:
I think there's 2 issues at play here:
- the specific case of that Sectigo root, which as you said was resolved
- what to do about new CA certificates in stable more generally.
Historically root CAs were around for decades, so updating the trust
store once every couple of years was more than sufficient. In recent
years CA lifetimes have reduced significantly, so this has become an
issue.  I would like to start updating the package more regularly, but
have been struggling to find the spare time to even keep up in unstable
so far...

Cheers,
Julien

#1107237#43
Date:
2026-02-23 18:16:10 UTC
From:
To:
Thanks for your answer, Julien.

El 23/02/26 a las 17:40, Julien Cristau escribió:

You're right!

Would you like to have some help on that?


Regarding what to do about changes in CA certificates in maintained
Debian releases, I wonder what is the best approach (version backports
from testing versus picking new CA certificates and changes from
testing).  I know that there have been regressions because of new
versions, e.g. #962596, but I am not sure that cherry-picking changes is
less risky.  Do you have any thoughts on that?

All the best,

#1107237#48
Date:
2026-07-10 09:12:47 UTC
From:
To:
Hello,

Telekom Security TLS RSA Root 2023 is actively used too now and is not
included in the Debian 12 trust store. This breaks requests from Debian 12
clients not trusting this root CA.

ca-certificates 20241223 (in Trixie) has the needed root CA included.


Best regards
Jan

#1107237#53
Date:
2026-08-10 08:18:26 UTC
From:
To:
version: 20250419~deb12u1