- Package:
- ca-certificates
- Source:
- ca-certificates
- Submitter:
- Kurt Roeckx
- Date:
- 2025-07-09 20:11:03 UTC
- Severity:
- normal
Hi, It seems that you revered the removal of some certificates. However they did not get installed again. It seems they were excluded in /etc/ca-certificates.conf for some reason, and so not added again. Kurt
Is this between 20140223 -> 20140325? Yes, Mozilla reverted their removal of 1024-bit certificates, and I see that upon certificate removal, the removed certificates are set with a '!' in ca-certificates.conf. That '!' remains in place in the config file, and when the certificate files were installed with the upgrade, they weren't actually re-linked in /etc/ssl/certs/ and considered disabled. Bleh. Thanks for the bug report, Kurt!
Hi, We tracked down a bug that's causing Facebook to display improperly in Epiphany [1] to this issue, so this seems fairly serious (though fortunately it probably only affects users who updated during February or March). Hopefully you'll be able to fix this automatically, but if not it might be a good idea to announce it so that users can fix it manually. Have a great day! [1] https://bugzilla.gnome.org/show_bug.cgi?id=735365
Is this an Epiphany-only issue? I'm having problems displaying Facebook with the MiniBrowser from webkit 2.6.2. Or is it a different issue? Berto
I need help with my mbox could you tell me a lol about it
On Debian GNU/Linux 12 (bookworm) install ca-certificates package and
checked the /etc/ssl/certs directory .pem files, noticed some of the
certificate expired.
These certificates expired in 2023,but this package still has these certs.
What is the right way to clean up these expired certificates?
Not After : Mar 3 12:09:48 2023 GMT
./E-Tugra_Certification_Authority.pem
Not After : May 15 04:52:29 2023 GMT
./Hongkong_Post_Root_CA_1.pem
Not After : Sep 30 04:20:49 2023 GMT
./Security_Communication_Root_CA.pem
Please clean-up this expired certificates
Thanks