git: ee0aa1ce12b3 - main - caroot: add new certs

From: Kyle Evans <kevans_at_FreeBSD.org>
Date: Sun, 25 Jun 2023 23:49:14 UTC
The branch main has been updated by kevans:

URL: https://cgit.FreeBSD.org/src/commit/?id=ee0aa1ce12b3caea34477a31e9d2111a329e33b9

commit ee0aa1ce12b3caea34477a31e9d2111a329e33b9
Author:     Kyle Evans <kevans@FreeBSD.org>
AuthorDate: 2023-06-25 23:47:49 +0000
Commit:     Kyle Evans <kevans@FreeBSD.org>
CommitDate: 2023-06-25 23:49:07 +0000

    caroot: add new certs
    
    Based on dates, these were likely just missed in the last update... add
    them now.
    
    - Twenty (20) new
---
 secure/caroot/trusted/BJCA_Global_Root_CA1.pem     | 135 ++++++++++++++++++++
 secure/caroot/trusted/BJCA_Global_Root_CA2.pem     |  67 ++++++++++
 secure/caroot/trusted/Certainly_Root_E1.pem        |  66 ++++++++++
 secure/caroot/trusted/Certainly_Root_R1.pem        | 134 ++++++++++++++++++++
 .../caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem   |  79 ++++++++++++
 .../caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem   |  79 ++++++++++++
 .../trusted/DigiCert_TLS_ECC_P384_Root_G5.pem      |  67 ++++++++++
 .../trusted/DigiCert_TLS_RSA4096_Root_G5.pem       | 134 ++++++++++++++++++++
 .../trusted/E-Tugra_Global_Root_CA_ECC_v3.pem      |  73 +++++++++++
 .../trusted/E-Tugra_Global_Root_CA_RSA_v3.pem      | 140 +++++++++++++++++++++
 .../caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem |  68 ++++++++++
 .../caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem | 136 ++++++++++++++++++++
 secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem       | 134 ++++++++++++++++++++
 secure/caroot/trusted/ISRG_Root_X2.pem             |  67 ++++++++++
 .../trusted/Security_Communication_ECC_RootCA1.pem |  67 ++++++++++
 .../trusted/Security_Communication_RootCA3.pem     | 135 ++++++++++++++++++++
 secure/caroot/trusted/Telia_Root_CA_v2.pem         | 138 ++++++++++++++++++++
 secure/caroot/trusted/TunTrust_Root_CA.pem         | 139 ++++++++++++++++++++
 secure/caroot/trusted/vTrus_ECC_Root_CA.pem        |  67 ++++++++++
 secure/caroot/trusted/vTrus_Root_CA.pem            | 134 ++++++++++++++++++++
 20 files changed, 2059 insertions(+)

diff --git a/secure/caroot/trusted/BJCA_Global_Root_CA1.pem b/secure/caroot/trusted/BJCA_Global_Root_CA1.pem
new file mode 100644
index 000000000000..889f140decc8
--- /dev/null
+++ b/secure/caroot/trusted/BJCA_Global_Root_CA1.pem
@@ -0,0 +1,135 @@
+##
+##  BJCA Global Root CA1
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            55:6f:65:e3:b4:d9:90:6a:1b:09:d1:6c:3e:c0:6c:20
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA1
+        Validity
+            Not Before: Dec 19 03:16:17 2019 GMT
+            Not After : Dec 12 03:16:17 2044 GMT
+        Subject: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA1
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:f1:66:08:bd:d9:c5:15:61:cb:84:04:41:a5:69:
+                    37:77:1d:c1:b0:7b:fa:c3:77:48:90:13:72:64:d1:
+                    b8:7c:90:35:9d:18:79:88:e3:97:01:3c:47:81:f2:
+                    0e:a2:98:0d:9e:3f:37:e0:19:b2:90:f2:46:1c:92:
+                    b1:3a:61:ce:fa:b7:46:9e:03:86:d7:33:6e:ed:f7:
+                    45:8c:76:37:de:6e:96:91:f7:d7:7e:2b:87:17:d5:
+                    8b:35:ee:84:91:72:57:dc:60:c3:c3:b9:e7:c7:67:
+                    24:23:4f:63:0a:63:f6:66:7d:4b:55:a7:3f:78:64:
+                    49:69:12:97:e0:4c:0d:d3:09:a0:32:30:3a:fa:9f:
+                    c0:f2:9c:c5:12:2a:2e:1c:b5:04:33:da:a4:38:11:
+                    6a:de:c6:18:f6:47:3a:22:41:87:22:fc:c4:89:28:
+                    54:d8:8c:a5:30:0a:f8:17:16:ca:ac:37:fd:79:a7:
+                    91:17:78:38:99:ad:58:ed:b2:de:cc:89:7d:03:9c:
+                    b3:89:65:e7:e3:3b:b1:22:86:8f:06:6d:78:07:fd:
+                    91:12:7f:b0:6b:1c:89:0d:f9:b8:cb:74:5b:07:c2:
+                    c8:f4:35:d1:64:63:7a:e9:6e:9a:28:d6:30:bd:e6:
+                    1b:dd:15:af:84:ea:9c:c7:ca:f5:0e:ea:f2:5d:29:
+                    87:8f:69:73:39:be:2e:24:6f:45:21:ac:c5:d4:69:
+                    25:06:83:ad:7a:48:85:13:2c:0d:06:b8:6c:79:56:
+                    fc:a3:67:32:81:f5:57:a5:ca:57:42:69:e9:5c:24:
+                    61:ef:e2:30:18:4e:44:98:55:6f:7a:c2:93:d8:19:
+                    b6:de:7c:47:8a:11:4e:49:47:db:28:94:02:0b:94:
+                    4a:2c:f9:12:d0:4f:e8:31:7e:6c:7a:bf:a6:3f:9b:
+                    39:3d:02:16:a3:18:b3:67:ac:5b:3f:2c:83:2b:67:
+                    39:81:5c:b9:7e:94:d5:64:dd:9e:8f:6e:ae:e8:7c:
+                    5b:b4:d7:6a:47:48:d7:7e:b3:d4:2d:8e:56:76:4e:
+                    cf:69:f1:6e:44:6c:d4:24:ea:8d:24:a1:18:bf:bd:
+                    57:fe:a9:99:35:b5:db:10:77:b8:3d:48:ba:d6:c1:
+                    e7:f1:23:3e:d7:df:85:9d:27:3c:d4:40:bd:0a:0c:
+                    bd:f5:e7:8d:25:d6:81:74:87:46:d4:29:75:a2:42:
+                    6c:f7:73:89:e7:7d:bf:7a:4a:1f:d3:22:c9:15:55:
+                    cf:df:6f:7c:55:d0:a4:8b:07:11:37:5f:83:a6:26:
+                    57:a6:01:5b:7e:fe:58:68:07:a9:e9:7a:d9:b9:e8:
+                    ff:50:1f:ab:c2:b4:c0:ce:e8:ea:fd:0f:bd:8d:4d:
+                    b8:bc:71
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                C5:EF:ED:CC:D8:8D:21:C6:48:E4:E3:D7:14:2E:A7:16:93:E5:98:01
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: sha256WithRSAEncryption
+         52:82:ac:21:34:1f:23:f2:a2:d8:f9:b8:af:37:36:20:89:d1:
+         37:03:d6:69:9f:b8:61:10:ba:a2:31:98:59:47:e8:d1:0d:25:
+         1e:15:41:0c:e0:2a:55:d5:57:52:cb:f8:e4:c7:69:a3:1d:4d:
+         71:02:5e:5f:21:45:60:48:5c:09:8e:49:10:c1:04:dc:a9:62:
+         6b:02:f0:43:c8:4e:9d:38:49:74:c9:32:70:54:6d:c1:47:fc:
+         8e:b4:36:9e:d4:9c:bd:dd:20:d6:53:c9:18:a9:b5:56:b9:76:
+         8b:95:67:66:ee:bd:98:fe:ae:ef:be:6e:fb:60:f6:fd:59:c6:
+         2a:1b:3f:23:4a:94:24:30:27:c8:89:bc:eb:44:24:9a:cb:3d:
+         be:4f:d5:7a:ce:8e:17:cb:62:c1:d9:de:1e:0e:7a:ff:43:86:
+         34:52:bc:61:3f:3c:5f:bb:d9:76:b4:53:bc:97:b3:fe:8a:4c:
+         12:2e:2b:f3:d7:ce:e1:a2:ff:dd:7b:70:fb:3b:a1:4d:a4:63:
+         02:fd:38:97:95:3f:05:70:a0:6b:df:62:81:43:8b:b4:59:0d:
+         4a:8c:54:9c:c5:bb:81:9f:cd:7d:a5:ef:0b:25:1e:3a:20:db:
+         1c:fc:1f:98:67:02:0a:d4:73:44:13:db:51:84:1a:55:03:56:
+         e0:00:7e:74:06:ff:38:c4:72:1d:d3:a8:3f:68:31:5d:d3:09:
+         c7:2e:8c:5b:63:e0:e8:dc:1e:d2:ec:61:1e:f2:de:e5:ef:f6:
+         99:76:60:2d:1e:94:72:71:c6:0b:2a:32:c7:92:4e:d5:46:d7:
+         1d:f9:a9:19:0a:c8:fa:95:ce:6d:23:98:aa:0b:38:ad:9a:56:
+         0d:6f:8d:f1:31:00:88:c1:17:9c:cd:19:36:35:fe:55:53:a0:
+         e0:3c:33:5f:96:5e:e2:32:e9:df:33:bb:06:4a:a9:d8:84:73:
+         ce:77:d2:c6:ac:71:e1:5c:a3:1d:0c:bb:0a:df:5f:e2:a3:71:
+         d8:da:37:5a:a0:78:2b:f4:d4:7d:eb:76:ed:f2:61:70:a5:65:
+         9a:d3:89:34:18:ab:fb:72:3e:d7:b4:3d:79:5c:d8:1f:a1:33:
+         7b:d9:82:50:0c:93:17:aa:6c:dc:c2:82:bb:02:57:36:af:98:
+         27:2a:39:50:e1:b0:89:f5:25:97:7e:47:68:10:b4:ec:73:ca:
+         b3:97:d1:24:dc:f6:62:a0:28:d3:b5:a3:b8:64:b7:88:62:42:
+         cf:9d:53:cd:99:be:64:68:8f:4f:1e:12:48:f7:d2:29:c3:98:
+         28:ca:f2:32:0b:93:8c:29:4f:3c:60:32:cd:05:96:61:ec:f2:
+         af:fe:b3:70:2c:2e:a6:f2
+SHA1 Fingerprint=D5:EC:8D:7B:4C:BA:79:F4:E7:E8:CB:9D:6B:AE:77:83:10:03:21:6A
+-----BEGIN CERTIFICATE-----
+MIIFdDCCA1ygAwIBAgIQVW9l47TZkGobCdFsPsBsIDANBgkqhkiG9w0BAQsFADBU
+MQswCQYDVQQGEwJDTjEmMCQGA1UECgwdQkVJSklORyBDRVJUSUZJQ0FURSBBVVRI
+T1JJVFkxHTAbBgNVBAMMFEJKQ0EgR2xvYmFsIFJvb3QgQ0ExMB4XDTE5MTIxOTAz
+MTYxN1oXDTQ0MTIxMjAzMTYxN1owVDELMAkGA1UEBhMCQ04xJjAkBgNVBAoMHUJF
+SUpJTkcgQ0VSVElGSUNBVEUgQVVUSE9SSVRZMR0wGwYDVQQDDBRCSkNBIEdsb2Jh
+bCBSb290IENBMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAPFmCL3Z
+xRVhy4QEQaVpN3cdwbB7+sN3SJATcmTRuHyQNZ0YeYjjlwE8R4HyDqKYDZ4/N+AZ
+spDyRhySsTphzvq3Rp4Dhtczbu33RYx2N95ulpH3134rhxfVizXuhJFyV9xgw8O5
+58dnJCNPYwpj9mZ9S1WnP3hkSWkSl+BMDdMJoDIwOvqfwPKcxRIqLhy1BDPapDgR
+at7GGPZHOiJBhyL8xIkoVNiMpTAK+BcWyqw3/XmnkRd4OJmtWO2y3syJfQOcs4ll
+5+M7sSKGjwZteAf9kRJ/sGsciQ35uMt0WwfCyPQ10WRjeulumijWML3mG90Vr4Tq
+nMfK9Q7q8l0ph49pczm+LiRvRSGsxdRpJQaDrXpIhRMsDQa4bHlW/KNnMoH1V6XK
+V0Jp6VwkYe/iMBhORJhVb3rCk9gZtt58R4oRTklH2yiUAguUSiz5EtBP6DF+bHq/
+pj+bOT0CFqMYs2esWz8sgytnOYFcuX6U1WTdno9uruh8W7TXakdI136z1C2OVnZO
+z2nxbkRs1CTqjSShGL+9V/6pmTW12xB3uD1IutbB5/EjPtffhZ0nPNRAvQoMvfXn
+jSXWgXSHRtQpdaJCbPdzied9v3pKH9MiyRVVz99vfFXQpIsHETdfg6YmV6YBW37+
+WGgHqel62bno/1Afq8K0wM7o6v0PvY1NuLxxAgMBAAGjQjBAMB0GA1UdDgQWBBTF
+7+3M2I0hxkjk49cULqcWk+WYATAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
+AwIBBjANBgkqhkiG9w0BAQsFAAOCAgEAUoKsITQfI/Ki2Pm4rzc2IInRNwPWaZ+4
+YRC6ojGYWUfo0Q0lHhVBDOAqVdVXUsv45Mdpox1NcQJeXyFFYEhcCY5JEMEE3Kli
+awLwQ8hOnThJdMkycFRtwUf8jrQ2ntScvd0g1lPJGKm1Vrl2i5VnZu69mP6u775u
++2D2/VnGKhs/I0qUJDAnyIm860Qkmss9vk/Ves6OF8tiwdneHg56/0OGNFK8YT88
+X7vZdrRTvJez/opMEi4r89fO4aL/3Xtw+zuhTaRjAv04l5U/BXCga99igUOLtFkN
+SoxUnMW7gZ/NfaXvCyUeOiDbHPwfmGcCCtRzRBPbUYQaVQNW4AB+dAb/OMRyHdOo
+P2gxXdMJxy6MW2Pg6Nwe0uxhHvLe5e/2mXZgLR6UcnHGCyoyx5JO1UbXHfmpGQrI
++pXObSOYqgs4rZpWDW+N8TEAiMEXnM0ZNjX+VVOg4DwzX5Ze4jLp3zO7Bkqp2IRz
+znfSxqxx4VyjHQy7Ct9f4qNx2No3WqB4K/TUfet27fJhcKVlmtOJNBir+3I+17Q9
+eVzYH6Eze9mCUAyTF6ps3MKCuwJXNq+YJyo5UOGwifUll35HaBC07HPKs5fRJNz2
+YqAo07WjuGS3iGJCz51TzZm+ZGiPTx4SSPfSKcOYKMryMguTjClPPGAyzQWWYezy
+r/6zcCwupvI=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/BJCA_Global_Root_CA2.pem b/secure/caroot/trusted/BJCA_Global_Root_CA2.pem
new file mode 100644
index 000000000000..da44a530a038
--- /dev/null
+++ b/secure/caroot/trusted/BJCA_Global_Root_CA2.pem
@@ -0,0 +1,67 @@
+##
+##  BJCA Global Root CA2
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            2c:17:08:7d:64:2a:c0:fe:85:18:59:06:cf:b4:4a:eb
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA2
+        Validity
+            Not Before: Dec 19 03:18:21 2019 GMT
+            Not After : Dec 12 03:18:21 2044 GMT
+        Subject: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA2
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:9d:cb:80:91:8d:53:67:b5:b9:50:b1:03:f8:e5:
+                    49:1f:41:22:09:b0:51:52:58:d6:2b:34:8f:c5:12:
+                    46:14:c5:8b:2f:2c:84:ff:2c:6e:a8:d5:f1:09:e3:
+                    03:21:14:c4:43:3d:7c:c1:2c:c4:4b:6a:4a:cd:e9:
+                    87:e0:7d:f6:22:be:fa:4a:51:b8:30:8a:fd:e1:de:
+                    18:12:0a:f6:47:b7:e7:17:bf:27:8a:d4:41:4c:96:
+                    3c:60:96:c1:fd:15:1c
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                D2:4A:B1:51:7F:06:F0:D1:82:1F:4E:6E:5F:AB:83:FC:48:D4:B0:91
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: ecdsa-with-SHA384
+         30:65:02:30:1a:bc:5b:d7:fe:a9:d2:54:0e:4a:5d:d2:6d:b1:
+         40:dc:f4:43:d5:d2:4a:99:19:12:56:80:f7:83:34:e1:35:4e:
+         48:6d:04:0f:57:31:30:30:2d:b1:aa:9d:03:38:db:06:02:31:
+         00:cb:cc:87:53:cb:7a:df:20:51:73:90:c0:a8:5b:61:d0:c5:
+         50:39:fd:85:fe:c1:e3:78:f8:a6:d6:4b:bd:9b:87:8f:0f:e5:
+         d6:53:96:ab:3c:c8:40:da:61:f7:53:a3:f7
+SHA1 Fingerprint=F4:27:86:EB:6E:B8:6D:88:31:67:02:FB:BA:66:A4:53:00:AA:7A:A6
+-----BEGIN CERTIFICATE-----
+MIICJTCCAaugAwIBAgIQLBcIfWQqwP6FGFkGz7RK6zAKBggqhkjOPQQDAzBUMQsw
+CQYDVQQGEwJDTjEmMCQGA1UECgwdQkVJSklORyBDRVJUSUZJQ0FURSBBVVRIT1JJ
+VFkxHTAbBgNVBAMMFEJKQ0EgR2xvYmFsIFJvb3QgQ0EyMB4XDTE5MTIxOTAzMTgy
+MVoXDTQ0MTIxMjAzMTgyMVowVDELMAkGA1UEBhMCQ04xJjAkBgNVBAoMHUJFSUpJ
+TkcgQ0VSVElGSUNBVEUgQVVUSE9SSVRZMR0wGwYDVQQDDBRCSkNBIEdsb2JhbCBS
+b290IENBMjB2MBAGByqGSM49AgEGBSuBBAAiA2IABJ3LgJGNU2e1uVCxA/jlSR9B
+IgmwUVJY1is0j8USRhTFiy8shP8sbqjV8QnjAyEUxEM9fMEsxEtqSs3ph+B99iK+
++kpRuDCK/eHeGBIK9ke35xe/J4rUQUyWPGCWwf0VHKNCMEAwHQYDVR0OBBYEFNJK
+sVF/BvDRgh9Obl+rg/xI1LCRMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMAoGCCqGSM49BAMDA2gAMGUCMBq8W9f+qdJUDkpd0m2xQNz0Q9XSSpkZElaA
+94M04TVOSG0ED1cxMDAtsaqdAzjbBgIxAMvMh1PLet8gUXOQwKhbYdDFUDn9hf7B
+43j4ptZLvZuHjw/l1lOWqzzIQNph91Oj9w==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Certainly_Root_E1.pem b/secure/caroot/trusted/Certainly_Root_E1.pem
new file mode 100644
index 000000000000..0750f7128ae6
--- /dev/null
+++ b/secure/caroot/trusted/Certainly_Root_E1.pem
@@ -0,0 +1,66 @@
+##
+##  Certainly Root E1
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            06:25:33:b1:47:03:33:27:5c:f9:8d:9a:b9:bf:cc:f8
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = US, O = Certainly, CN = Certainly Root E1
+        Validity
+            Not Before: Apr  1 00:00:00 2021 GMT
+            Not After : Apr  1 00:00:00 2046 GMT
+        Subject: C = US, O = Certainly, CN = Certainly Root E1
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:de:6f:f8:7f:1c:df:ed:f9:47:87:86:b1:a4:c0:
+                    8a:f8:82:97:80:ea:8f:c8:4a:5e:2a:7d:88:68:a7:
+                    01:62:14:91:24:7a:5c:9e:a3:17:7d:8a:86:21:34:
+                    18:50:1b:10:de:d0:37:4b:26:c7:19:60:80:e9:34:
+                    bd:60:19:36:40:d6:29:87:09:3c:91:7a:f6:bc:13:
+                    23:dd:59:4e:04:5e:cf:c8:02:1c:18:53:c1:31:d8:
+                    da:20:e9:44:8d:e4:76
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Subject Key Identifier: 
+                F3:28:18:CB:64:75:EE:29:2A:EB:ED:AE:23:58:38:85:EB:C8:22:07
+    Signature Algorithm: ecdsa-with-SHA384
+         30:65:02:31:00:b1:8e:5a:20:c3:b2:19:62:4d:de:b0:4f:df:
+         6e:d2:70:8a:f1:9f:7e:6a:8c:e6:ba:de:83:69:ca:69:b3:a9:
+         05:b5:96:92:17:87:c2:d2:ea:d0:7b:ce:d8:41:5b:7c:ae:02:
+         30:46:de:ea:cb:5d:9a:ec:32:c2:65:16:b0:4c:30:5c:30:f3:
+         da:4e:73:86:06:d8:ce:89:04:48:37:37:f8:dd:33:51:9d:70:
+         af:7b:55:d8:01:2e:7d:05:64:0e:86:b8:91
+SHA1 Fingerprint=F9:E1:6D:DC:01:89:CF:D5:82:45:63:3E:C5:37:7D:C2:EB:93:6F:2B
+-----BEGIN CERTIFICATE-----
+MIIB9zCCAX2gAwIBAgIQBiUzsUcDMydc+Y2aub/M+DAKBggqhkjOPQQDAzA9MQsw
+CQYDVQQGEwJVUzESMBAGA1UEChMJQ2VydGFpbmx5MRowGAYDVQQDExFDZXJ0YWlu
+bHkgUm9vdCBFMTAeFw0yMTA0MDEwMDAwMDBaFw00NjA0MDEwMDAwMDBaMD0xCzAJ
+BgNVBAYTAlVTMRIwEAYDVQQKEwlDZXJ0YWlubHkxGjAYBgNVBAMTEUNlcnRhaW5s
+eSBSb290IEUxMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE3m/4fxzf7flHh4axpMCK
++IKXgOqPyEpeKn2IaKcBYhSRJHpcnqMXfYqGITQYUBsQ3tA3SybHGWCA6TS9YBk2
+QNYphwk8kXr2vBMj3VlOBF7PyAIcGFPBMdjaIOlEjeR2o0IwQDAOBgNVHQ8BAf8E
+BAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQU8ygYy2R17ikq6+2uI1g4
+hevIIgcwCgYIKoZIzj0EAwMDaAAwZQIxALGOWiDDshliTd6wT99u0nCK8Z9+aozm
+ut6Dacpps6kFtZaSF4fC0urQe87YQVt8rgIwRt7qy12a7DLCZRawTDBcMPPaTnOG
+BtjOiQRINzf43TNRnXCve1XYAS59BWQOhriR
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Certainly_Root_R1.pem b/secure/caroot/trusted/Certainly_Root_R1.pem
new file mode 100644
index 000000000000..a4e6f28e33a6
--- /dev/null
+++ b/secure/caroot/trusted/Certainly_Root_R1.pem
@@ -0,0 +1,134 @@
+##
+##  Certainly Root R1
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            8e:0f:f9:4b:90:71:68:65:33:54:f4:d4:44:39:b7:e0
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = US, O = Certainly, CN = Certainly Root R1
+        Validity
+            Not Before: Apr  1 00:00:00 2021 GMT
+            Not After : Apr  1 00:00:00 2046 GMT
+        Subject: C = US, O = Certainly, CN = Certainly Root R1
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:d0:36:d4:1f:ea:dd:ab:e4:d1:b6:e6:fb:22:c0:
+                    dd:13:0d:6a:7b:22:13:1c:97:3c:68:63:66:32:9c:
+                    03:b5:8d:a4:81:83:da:78:30:11:cf:dc:b2:2b:be:
+                    92:bf:8e:e4:c4:13:be:a4:68:4c:da:02:68:16:74:
+                    be:b2:dd:04:e4:6b:2a:dd:37:1f:60:2c:db:f5:f7:
+                    a1:7c:95:b7:0c:70:86:2e:f1:3a:ef:52:f7:cc:d3:
+                    9b:f9:8b:be:0e:df:31:b7:9d:68:5c:92:a6:f5:e5:
+                    f3:0a:34:b5:ff:7b:a2:e4:87:a1:c6:af:17:00:ef:
+                    03:91:ed:a9:1c:4e:71:3d:d2:8b:6c:89:f4:78:86:
+                    e6:6a:49:a0:ce:b5:d2:b0:ab:9b:f6:f4:d4:2e:e3:
+                    72:f9:36:c6:eb:15:b7:25:8c:3a:fc:25:0d:b3:22:
+                    73:21:74:c8:4a:96:61:92:f5:2f:0b:18:a5:f4:ad:
+                    e2:ee:41:bd:01:79:fa:96:8c:8d:17:02:30:b4:f9:
+                    af:78:1a:8c:b4:36:10:10:07:05:70:d0:f4:31:90:
+                    8a:51:c5:86:26:79:b2:11:88:5e:c5:f0:0a:54:cd:
+                    49:a6:bf:02:9c:d2:44:a7:ed:e3:78:ef:46:5e:6d:
+                    71:d1:79:70:1c:46:5f:51:e9:c9:37:dc:5f:7e:69:
+                    7b:41:df:34:45:e0:3b:84:f4:a1:8a:0a:36:9e:37:
+                    cc:62:52:e1:89:0d:28:f9:7a:23:b1:0d:3d:3d:9a:
+                    fd:9d:81:ef:2c:90:c0:7b:44:4e:bb:49:e0:0e:4a:
+                    56:92:bc:cb:b5:dd:79:17:89:91:de:61:89:74:92:
+                    a8:e3:32:85:be:4e:85:a4:4b:59:cb:2b:c5:78:8e:
+                    71:54:d0:02:37:99:8c:e5:49:ea:e0:54:72:a4:11:
+                    06:2f:0b:8c:c1:5b:be:b5:a1:b0:53:6e:9c:b8:60:
+                    91:1f:59:6b:f9:2d:f4:94:0a:97:b5:ec:c5:76:03:
+                    54:1b:65:52:ba:4c:92:56:51:35:a0:40:d8:29:db:
+                    ae:52:76:3b:2d:30:40:9b:8a:d0:42:56:b4:b7:88:
+                    01:a4:87:3b:53:96:cd:a3:16:8f:f3:66:aa:17:b1:
+                    c7:60:e0:c1:43:05:0c:ee:9b:5b:60:6f:06:5c:87:
+                    5b:27:f9:40:11:9e:9c:33:c1:b7:e5:35:57:05:7f:
+                    27:ce:17:20:8c:1c:fc:f1:fb:da:31:29:49:ed:f5:
+                    0b:84:a7:4f:c1:f6:4e:c2:28:9c:fa:ee:e0:af:07:
+                    fb:33:11:7a:21:4f:0b:21:10:b6:40:3a:ab:22:3a:
+                    04:9c:8b:9b:84:86:72:9a:d2:a7:a5:c4:b4:75:91:
+                    a9:2b:23
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Subject Key Identifier: 
+                E0:AA:3F:25:8D:9F:44:5C:C1:3A:E8:2E:AE:77:4C:84:3E:67:0C:F4
+    Signature Algorithm: sha256WithRSAEncryption
+         b9:57:af:b8:12:da:57:83:8f:68:0b:33:1d:03:53:55:f4:95:
+         70:e4:2b:3d:b0:39:eb:fa:89:62:fd:f7:d6:18:04:2f:21:34:
+         dd:f1:68:f0:d5:96:5a:de:c2:80:a3:c1:8d:c6:6a:f7:59:77:
+         ae:15:64:cf:5b:79:05:77:66:ea:8c:d3:6b:0d:dd:f1:59:2c:
+         c1:33:a5:30:80:15:45:07:45:1a:31:22:b6:92:00:ab:99:4d:
+         3a:8f:77:af:a9:22:ca:2f:63:ca:15:d6:c7:c6:f0:3d:6c:fc:
+         1c:0d:98:10:61:9e:11:a2:22:d7:0a:f2:91:7a:6b:39:0e:2f:
+         30:c3:36:49:9f:e0:e9:0f:02:44:50:37:94:55:7d:ea:9f:f6:
+         3b:ba:94:a5:4c:e9:bc:3e:51:b4:e8:ca:92:36:54:6d:5c:25:
+         28:da:dd:ad:14:fd:d3:ee:e2:22:05:eb:d0:f2:b7:68:12:d7:
+         5a:8a:41:1a:c6:92:a5:5a:3b:63:45:4f:bf:e1:3a:77:22:2f:
+         5c:bf:46:f9:5a:03:85:13:42:5f:ca:de:53:d7:62:b5:a6:35:
+         04:c2:47:ff:99:fd:84:df:5c:ce:e9:5e:80:28:41:f2:7d:e7:
+         1e:90:d8:4f:76:3e:82:3c:0d:fc:a5:03:fa:7b:1a:d9:45:1e:
+         60:da:c4:8e:f9:fc:2b:c9:7b:95:c5:2a:ff:aa:89:df:82:31:
+         0f:72:ff:0c:27:d7:0a:1e:56:00:50:1e:0c:90:c1:96:b5:d8:
+         14:85:bb:a7:0d:16:c1:f8:07:24:1b:ba:85:a1:1a:05:09:80:
+         ba:95:63:c9:3a:ec:25:9f:7f:9d:ba:a4:47:15:9b:44:70:f1:
+         6a:4b:d6:38:5e:43:f3:18:7e:50:6e:e9:5a:28:e6:65:e6:77:
+         1b:3a:fd:1d:be:03:26:a3:db:d4:e1:bb:7e:96:27:2b:1d:ee:
+         a4:fb:da:25:54:13:03:de:39:c6:c3:1f:4d:90:ec:8f:1b:4a:
+         d2:1c:ed:85:95:38:50:79:46:d6:c1:90:50:31:a9:5c:9a:6e:
+         1d:f5:33:56:8b:a7:99:d2:f2:c8:2c:33:93:92:30:c7:4e:8c:
+         65:33:10:64:17:fd:24:17:96:d1:8d:c2:3a:6a:2b:eb:13:8b:
+         44:f2:21:f3:4a:1a:b7:77:5f:d7:ed:88:a4:72:e5:39:1f:95:
+         9d:be:67:c1:70:11:3d:bb:f4:f8:49:b7:e3:26:97:3a:9f:d2:
+         5f:7c:fb:c0:99:7c:39:29:e0:7b:1d:bf:0d:a7:8f:d2:29:34:
+         6e:24:15:cb:de:90:5e:bf:1a:c4:66:ea:c2:e6:ba:39:5f:8a:
+         99:a9:41:59:07:b0:2c:af
+SHA1 Fingerprint=A0:50:EE:0F:28:71:F4:27:B2:12:6D:6F:50:96:25:BA:CC:86:42:AF
+-----BEGIN CERTIFICATE-----
+MIIFRzCCAy+gAwIBAgIRAI4P+UuQcWhlM1T01EQ5t+AwDQYJKoZIhvcNAQELBQAw
+PTELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUNlcnRhaW5seTEaMBgGA1UEAxMRQ2Vy
+dGFpbmx5IFJvb3QgUjEwHhcNMjEwNDAxMDAwMDAwWhcNNDYwNDAxMDAwMDAwWjA9
+MQswCQYDVQQGEwJVUzESMBAGA1UEChMJQ2VydGFpbmx5MRowGAYDVQQDExFDZXJ0
+YWlubHkgUm9vdCBSMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANA2
+1B/q3avk0bbm+yLA3RMNansiExyXPGhjZjKcA7WNpIGD2ngwEc/csiu+kr+O5MQT
+vqRoTNoCaBZ0vrLdBORrKt03H2As2/X3oXyVtwxwhi7xOu9S98zTm/mLvg7fMbed
+aFySpvXl8wo0tf97ouSHocavFwDvA5HtqRxOcT3Si2yJ9HiG5mpJoM610rCrm/b0
+1C7jcvk2xusVtyWMOvwlDbMicyF0yEqWYZL1LwsYpfSt4u5BvQF5+paMjRcCMLT5
+r3gajLQ2EBAHBXDQ9DGQilHFhiZ5shGIXsXwClTNSaa/ApzSRKft43jvRl5tcdF5
+cBxGX1HpyTfcX35pe0HfNEXgO4T0oYoKNp43zGJS4YkNKPl6I7ENPT2a/Z2B7yyQ
+wHtETrtJ4A5KVpK8y7XdeReJkd5hiXSSqOMyhb5OhaRLWcsrxXiOcVTQAjeZjOVJ
+6uBUcqQRBi8LjMFbvrWhsFNunLhgkR9Za/kt9JQKl7XsxXYDVBtlUrpMklZRNaBA
+2CnbrlJ2Oy0wQJuK0EJWtLeIAaSHO1OWzaMWj/Nmqhexx2DgwUMFDO6bW2BvBlyH
+Wyf5QBGenDPBt+U1VwV/J84XIIwc/PH72jEpSe31C4SnT8H2TsIonPru4K8H+zMR
+eiFPCyEQtkA6qyI6BJyLm4SGcprSp6XEtHWRqSsjAgMBAAGjQjBAMA4GA1UdDwEB
+/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTgqj8ljZ9EXME66C6u
+d0yEPmcM9DANBgkqhkiG9w0BAQsFAAOCAgEAuVevuBLaV4OPaAszHQNTVfSVcOQr
+PbA56/qJYv331hgELyE03fFo8NWWWt7CgKPBjcZq91l3rhVkz1t5BXdm6ozTaw3d
+8VkswTOlMIAVRQdFGjEitpIAq5lNOo93r6kiyi9jyhXWx8bwPWz8HA2YEGGeEaIi
+1wrykXprOQ4vMMM2SZ/g6Q8CRFA3lFV96p/2O7qUpUzpvD5RtOjKkjZUbVwlKNrd
+rRT90+7iIgXr0PK3aBLXWopBGsaSpVo7Y0VPv+E6dyIvXL9G+VoDhRNCX8reU9di
+taY1BMJH/5n9hN9czulegChB8n3nHpDYT3Y+gjwN/KUD+nsa2UUeYNrEjvn8K8l7
+lcUq/6qJ34IxD3L/DCfXCh5WAFAeDJDBlrXYFIW7pw0WwfgHJBu6haEaBQmAupVj
+yTrsJZ9/nbqkRxWbRHDxakvWOF5D8xh+UG7pWijmZeZ3Gzr9Hb4DJqPb1OG7fpYn
+Kx3upPvaJVQTA945xsMfTZDsjxtK0hzthZU4UHlG1sGQUDGpXJpuHfUzVounmdLy
+yCwzk5Iwx06MZTMQZBf9JBeW0Y3COmor6xOLRPIh80oat3df1+2IpHLlOR+Vnb5n
+wXARPbv0+Em34yaXOp/SX3z7wJl8OSngex2/DaeP0ik0biQVy96QXr8axGbqwua6
+OV+KmalBWQewLK8=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem b/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem
new file mode 100644
index 000000000000..758d61032898
--- /dev/null
+++ b/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem
@@ -0,0 +1,79 @@
+##
+##  D-TRUST BR Root CA 1 2020
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            7c:c9:8f:2b:84:d7:df:ea:0f:c9:65:9a:d3:4b:4d:96
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST BR Root CA 1 2020
+        Validity
+            Not Before: Feb 11 09:45:00 2020 GMT
+            Not After : Feb 11 09:44:59 2035 GMT
+        Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST BR Root CA 1 2020
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:c6:cb:c7:28:d1:fb:84:f5:9a:ef:42:14:20:e1:
+                    43:6b:6e:75:ad:fc:2b:03:84:d4:76:93:25:d7:59:
+                    3b:41:65:6b:1e:e6:34:2a:bb:74:f6:12:ce:e8:6d:
+                    e7:ab:e4:3c:4e:3f:44:08:8b:cd:16:71:cb:bf:92:
+                    99:f4:a4:d7:3c:50:54:52:90:85:83:78:94:67:67:
+                    a3:1c:09:19:3d:75:34:85:de:ed:60:7d:c7:0c:b4:
+                    41:52:b9:6e:e5:ee:42
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Subject Key Identifier: 
+                73:91:10:AB:FF:55:B3:5A:7C:09:25:D5:B2:BA:08:A0:6B:AB:1F:6D
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.d-trust.net/crl/d-trust_br_root_ca_1_2020.crl
+
+                Full Name:
+                  URI:ldap://directory.d-trust.net/CN=D-TRUST%20BR%20Root%20CA%201%202020,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+
+    Signature Algorithm: ecdsa-with-SHA384
+         30:66:02:31:00:94:90:2d:13:fa:e1:63:f8:61:63:e8:ad:85:
+         78:54:91:9c:b8:93:38:3e:1a:41:da:40:16:53:42:08:ca:2f:
+         8e:f1:3e:81:56:c0:aa:d8:ed:18:c4:b0:ae:f4:3e:fa:26:02:
+         31:00:f3:28:e2:c6:db:2b:99:fb:b7:51:b8:24:a3:a4:94:7a:
+         1a:3f:e6:36:e2:03:57:33:8a:30:cb:82:c7:d6:14:11:d5:75:
+         63:5b:14:95:9c:1f:01:cf:d8:d5:72:a7:0f:3b
+SHA1 Fingerprint=1F:5B:98:F0:E3:B5:F7:74:3C:ED:E6:B0:36:7D:32:CD:F4:09:41:67
+-----BEGIN CERTIFICATE-----
+MIIC2zCCAmCgAwIBAgIQfMmPK4TX3+oPyWWa00tNljAKBggqhkjOPQQDAzBIMQsw
+CQYDVQQGEwJERTEVMBMGA1UEChMMRC1UcnVzdCBHbWJIMSIwIAYDVQQDExlELVRS
+VVNUIEJSIFJvb3QgQ0EgMSAyMDIwMB4XDTIwMDIxMTA5NDUwMFoXDTM1MDIxMTA5
+NDQ1OVowSDELMAkGA1UEBhMCREUxFTATBgNVBAoTDEQtVHJ1c3QgR21iSDEiMCAG
+A1UEAxMZRC1UUlVTVCBCUiBSb290IENBIDEgMjAyMDB2MBAGByqGSM49AgEGBSuB
+BAAiA2IABMbLxyjR+4T1mu9CFCDhQ2tuda38KwOE1HaTJddZO0Flax7mNCq7dPYS
+zuht56vkPE4/RAiLzRZxy7+SmfSk1zxQVFKQhYN4lGdnoxwJGT11NIXe7WB9xwy0
+QVK5buXuQqOCAQ0wggEJMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFHOREKv/
+VbNafAkl1bK6CKBrqx9tMA4GA1UdDwEB/wQEAwIBBjCBxgYDVR0fBIG+MIG7MD6g
+PKA6hjhodHRwOi8vY3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X2JyX3Jvb3Rf
+Y2FfMV8yMDIwLmNybDB5oHegdYZzbGRhcDovL2RpcmVjdG9yeS5kLXRydXN0Lm5l
+dC9DTj1ELVRSVVNUJTIwQlIlMjBSb290JTIwQ0ElMjAxJTIwMjAyMCxPPUQtVHJ1
+c3QlMjBHbWJILEM9REU/Y2VydGlmaWNhdGVyZXZvY2F0aW9ubGlzdDAKBggqhkjO
+PQQDAwNpADBmAjEAlJAtE/rhY/hhY+ithXhUkZy4kzg+GkHaQBZTQgjKL47xPoFW
+wKrY7RjEsK70PvomAjEA8yjixtsrmfu3Ubgko6SUeho/5jbiA1czijDLgsfWFBHV
+dWNbFJWcHwHP2NVypw87
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem b/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem
new file mode 100644
index 000000000000..76991855eaa1
--- /dev/null
+++ b/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem
@@ -0,0 +1,79 @@
+##
+##  D-TRUST EV Root CA 1 2020
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            5f:02:41:d7:7a:87:7c:4c:03:a3:ac:96:8d:fb:ff:d0
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST EV Root CA 1 2020
+        Validity
+            Not Before: Feb 11 10:00:00 2020 GMT
+            Not After : Feb 11 09:59:59 2035 GMT
+        Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST EV Root CA 1 2020
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:f1:0b:dd:86:43:20:19:df:97:85:e8:22:4a:9b:
+                    cf:9d:98:bf:b4:05:26:c9:cb:e3:a6:d2:8f:c5:9e:
+                    78:7b:31:89:a9:89:ad:27:3c:65:10:82:fc:df:c3:
+                    9d:4e:f0:33:23:c4:d2:32:f5:1c:b0:df:33:17:5d:
+                    c5:f0:b1:8a:f9:ef:b9:b7:14:ca:29:4a:c2:0f:a9:
+                    7f:75:65:49:2a:30:67:f4:64:f7:d6:1a:77:da:c3:
+                    c2:97:61:42:7b:49:ad
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Subject Key Identifier: 
+                7F:10:01:16:37:3A:A4:28:E4:50:F8:A4:F7:EC:6B:32:B6:FE:E9:8B
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.d-trust.net/crl/d-trust_ev_root_ca_1_2020.crl
+
+                Full Name:
+                  URI:ldap://directory.d-trust.net/CN=D-TRUST%20EV%20Root%20CA%201%202020,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+
+    Signature Algorithm: ecdsa-with-SHA384
+         30:66:02:31:00:ca:3c:c6:2a:75:c2:5e:75:62:39:36:00:60:
+         5a:8b:c1:93:99:cc:d9:db:41:3b:3b:87:99:17:3b:d5:cc:4f:
+         ca:22:f7:a0:80:cb:f9:b4:b1:1b:56:f5:72:d2:fc:19:d1:02:
+         31:00:91:f7:30:93:3f:10:46:2b:71:a4:d0:3b:44:9b:c0:29:
+         02:05:b2:41:77:51:f3:79:5a:9e:8e:14:a0:4e:42:d2:5b:81:
+         f3:34:6a:03:e7:22:38:50:5b:ed:19:4f:43:16
+SHA1 Fingerprint=61:DB:8C:21:59:69:03:90:D8:7C:9C:12:86:54:CF:9D:3D:F4:DD:07
+-----BEGIN CERTIFICATE-----
+MIIC2zCCAmCgAwIBAgIQXwJB13qHfEwDo6yWjfv/0DAKBggqhkjOPQQDAzBIMQsw
+CQYDVQQGEwJERTEVMBMGA1UEChMMRC1UcnVzdCBHbWJIMSIwIAYDVQQDExlELVRS
+VVNUIEVWIFJvb3QgQ0EgMSAyMDIwMB4XDTIwMDIxMTEwMDAwMFoXDTM1MDIxMTA5
+NTk1OVowSDELMAkGA1UEBhMCREUxFTATBgNVBAoTDEQtVHJ1c3QgR21iSDEiMCAG
+A1UEAxMZRC1UUlVTVCBFViBSb290IENBIDEgMjAyMDB2MBAGByqGSM49AgEGBSuB
+BAAiA2IABPEL3YZDIBnfl4XoIkqbz52Yv7QFJsnL46bSj8WeeHsxiamJrSc8ZRCC
+/N/DnU7wMyPE0jL1HLDfMxddxfCxivnvubcUyilKwg+pf3VlSSowZ/Rk99Yad9rD
+wpdhQntJraOCAQ0wggEJMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFH8QARY3
+OqQo5FD4pPfsazK2/umLMA4GA1UdDwEB/wQEAwIBBjCBxgYDVR0fBIG+MIG7MD6g
+PKA6hjhodHRwOi8vY3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X2V2X3Jvb3Rf
+Y2FfMV8yMDIwLmNybDB5oHegdYZzbGRhcDovL2RpcmVjdG9yeS5kLXRydXN0Lm5l
+dC9DTj1ELVRSVVNUJTIwRVYlMjBSb290JTIwQ0ElMjAxJTIwMjAyMCxPPUQtVHJ1
+c3QlMjBHbWJILEM9REU/Y2VydGlmaWNhdGVyZXZvY2F0aW9ubGlzdDAKBggqhkjO
+PQQDAwNpADBmAjEAyjzGKnXCXnViOTYAYFqLwZOZzNnbQTs7h5kXO9XMT8oi96CA
+y/m0sRtW9XLS/BnRAjEAkfcwkz8QRitxpNA7RJvAKQIFskF3UfN5Wp6OFKBOQtJb
+gfM0agPnIjhQW+0ZT0MW
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem b/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem
new file mode 100644
index 000000000000..a6f2e6a0c771
--- /dev/null
+++ b/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem
@@ -0,0 +1,67 @@
+##
+##  DigiCert TLS ECC P384 Root G5
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            09:e0:93:65:ac:f7:d9:c8:b9:3e:1c:0b:04:2a:2e:f3
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS ECC P384 Root G5
+        Validity
+            Not Before: Jan 15 00:00:00 2021 GMT
+            Not After : Jan 14 23:59:59 2046 GMT
+        Subject: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS ECC P384 Root G5
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:c1:44:a1:cf:11:97:50:9a:de:23:82:35:07:cd:
+                    d0:cb:18:9d:d2:f1:7f:77:35:4f:3b:dd:94:72:52:
+                    ed:c2:3b:f8:ec:fa:7b:6b:58:20:ec:99:ae:c9:fc:
+                    68:b3:75:b9:db:09:ec:c8:13:f5:4e:c6:0a:1d:66:
+                    30:4c:bb:1f:47:0a:3c:61:10:42:29:7c:a5:08:0e:
+                    e0:22:e9:d3:35:68:ce:9b:63:9f:84:b5:99:4d:58:
+                    a0:8e:f5:54:e7:95:c9
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                C1:51:45:50:59:AB:3E:E7:2C:5A:FA:20:22:12:07:80:88:7C:11:6A
+            X509v3 Key Usage: critical
+                Digital Signature, Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+    Signature Algorithm: ecdsa-with-SHA384
+         30:65:02:31:00:89:6a:8d:47:e7:ec:fc:6e:55:03:d9:67:6c:
+         26:4e:83:c6:fd:c9:fb:2b:13:bc:b7:7a:8c:b4:65:d2:69:69:
+         63:13:63:3b:26:50:2e:01:a1:79:06:91:9d:48:bf:c2:be:02:
+         30:47:c3:15:7b:b1:a0:91:99:49:93:a8:3c:7c:e8:46:06:8b:
+         2c:f2:31:00:94:9d:62:c8:89:bd:19:84:14:e9:a5:fb:01:b8:
+         0d:76:43:8c:2e:53:cb:7c:df:0c:17:96:50
+SHA1 Fingerprint=17:F3:DE:5E:9F:0F:19:E9:8E:F6:1F:32:26:6E:20:C4:07:AE:30:EE
+-----BEGIN CERTIFICATE-----
+MIICGTCCAZ+gAwIBAgIQCeCTZaz32ci5PhwLBCou8zAKBggqhkjOPQQDAzBOMQsw
+CQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xJjAkBgNVBAMTHURp
+Z2lDZXJ0IFRMUyBFQ0MgUDM4NCBSb290IEc1MB4XDTIxMDExNTAwMDAwMFoXDTQ2
+MDExNDIzNTk1OVowTjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDkRpZ2lDZXJ0LCBJ
+bmMuMSYwJAYDVQQDEx1EaWdpQ2VydCBUTFMgRUNDIFAzODQgUm9vdCBHNTB2MBAG
+ByqGSM49AgEGBSuBBAAiA2IABMFEoc8Rl1Ca3iOCNQfN0MsYndLxf3c1TzvdlHJS
+7cI7+Oz6e2tYIOyZrsn8aLN1udsJ7MgT9U7GCh1mMEy7H0cKPGEQQil8pQgO4CLp
+0zVozptjn4S1mU1YoI71VOeVyaNCMEAwHQYDVR0OBBYEFMFRRVBZqz7nLFr6ICIS
+B4CIfBFqMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MAoGCCqGSM49
+BAMDA2gAMGUCMQCJao1H5+z8blUD2WdsJk6Dxv3J+ysTvLd6jLRl0mlpYxNjOyZQ
+LgGheQaRnUi/wr4CMEfDFXuxoJGZSZOoPHzoRgaLLPIxAJSdYsiJvRmEFOml+wG4
+DXZDjC5Ty3zfDBeWUA==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem b/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem
new file mode 100644
index 000000000000..cb58c6a21418
--- /dev/null
+++ b/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem
@@ -0,0 +1,134 @@
+##
+##  DigiCert TLS RSA4096 Root G5
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a
+        Signature Algorithm: sha384WithRSAEncryption
+        Issuer: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS RSA4096 Root G5
+        Validity
+            Not Before: Jan 15 00:00:00 2021 GMT
+            Not After : Jan 14 23:59:59 2046 GMT
+        Subject: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS RSA4096 Root G5
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:b3:d0:f4:c9:79:11:9d:fd:fc:66:81:e7:cc:d5:
+                    e4:bc:ec:81:3e:6a:35:8e:2e:b7:e7:de:af:f9:07:
+                    4d:cf:30:9d:ea:09:0b:99:bd:6c:57:da:18:4a:b8:
+                    78:ac:3a:39:a8:a6:48:ac:2e:72:e5:bd:eb:f1:1a:
+                    cd:e7:a4:03:a9:3f:11:b4:d8:2f:89:16:fb:94:01:
+                    3d:bb:2f:f8:13:05:a1:78:1c:8e:28:e0:45:e0:83:
+                    f4:59:1b:95:b3:ae:7e:03:45:e5:be:c2:42:fe:ee:
+                    f2:3c:b6:85:13:98:32:9d:16:a8:29:c2:0b:1c:38:
+                    dc:9f:31:77:5c:bf:27:a3:fc:27:ac:b7:2b:bd:74:
+                    9b:17:2d:f2:81:da:5d:b0:e1:23:17:3e:88:4a:12:
+                    23:d0:ea:cf:9d:de:03:17:b1:42:4a:a0:16:4c:a4:
+                    6d:93:e9:3f:3a:ee:3a:7c:9d:58:9d:f4:4e:8f:fc:
+                    3b:23:c8:6d:b8:e2:05:da:cc:eb:ec:c3:31:f4:d7:
+                    a7:29:54:80:cf:44:5b:4c:6f:30:9e:f3:cc:dd:1f:
+                    94:43:9d:4d:7f:70:70:0d:d4:3a:d1:37:f0:6c:9d:
+                    9b:c0:14:93:58:ef:cd:41:38:75:bc:13:03:95:7c:
+                    7f:e3:5c:e9:d5:0d:d5:e2:7c:10:62:aa:6b:f0:3d:
+                    76:f3:3f:a3:e8:b0:c1:fd:ef:aa:57:4d:ac:86:a7:
+                    18:b4:29:c1:2c:0e:bf:64:be:29:8c:d8:02:2d:cd:
+                    5c:2f:f2:7f:ef:15:f4:0c:15:ac:0a:b0:f1:d3:0d:
+                    4f:6a:4d:77:97:01:a0:f1:66:b7:b7:ce:ef:ce:ec:
+                    ec:a5:75:ca:ac:e3:e1:63:f7:b8:a1:04:c8:bc:7b:
+                    3f:5d:2d:16:22:56:ed:48:49:fe:a7:2f:79:30:25:
+                    9b:ba:6b:2d:3f:9d:3b:c4:17:e7:1d:2e:fb:f2:cf:
+                    a6:fc:e3:14:2c:96:98:21:8c:b4:91:e9:19:60:83:
+                    f2:30:2b:06:73:50:d5:98:3b:06:e9:c7:8a:0c:60:
+                    8c:28:f8:52:9b:6e:e1:f6:4d:bb:06:24:9b:d7:2b:
+                    26:3f:fd:2a:2f:71:f5:d6:24:be:7f:31:9e:0f:6d:
+                    e8:8f:4f:4d:a3:3f:ff:35:ea:df:49:5e:41:8f:86:
+                    f9:f1:77:79:4b:1b:b4:a3:5e:2f:fb:46:02:d0:66:
+                    13:5e:5e:85:4f:ce:d8:70:88:7b:ce:01:b5:96:97:
+                    d7:cd:7d:fd:82:f8:c2:24:c1:ca:01:39:4f:8d:a2:
+                    c1:14:40:1f:9c:66:d5:0c:09:46:d6:f2:d0:d1:48:
+                    76:56:3a:43:cb:b6:0a:11:39:ba:8c:13:6c:06:b5:
+                    9e:cf:eb
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                51:33:1C:ED:36:40:AF:17:D3:25:CD:69:68:F2:AF:4E:23:3E:B3:41
+            X509v3 Key Usage: critical
+                Digital Signature, Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+    Signature Algorithm: sha384WithRSAEncryption
+         60:a6:af:5b:5f:57:da:89:db:4b:50:a9:c4:23:35:21:ff:d0:
+         61:30:84:91:b7:3f:10:cf:25:8e:c9:bf:46:34:d9:c1:21:26:
+         1c:70:19:72:1e:a3:c9:87:fe:a9:43:64:96:3a:c8:53:04:0a:
+         b6:41:bb:c4:47:00:d9:9f:18:18:3b:b2:0e:f3:34:ea:24:f7:
+         dd:af:20:60:ae:92:28:5f:36:e7:5d:e4:de:c7:3c:db:50:39:
+         ad:bb:3d:28:4d:96:7c:76:c6:5b:f4:c1:db:14:a5:ab:19:62:
+         07:18:40:5f:97:91:dc:9c:c7:ab:b5:51:0d:e6:69:53:55:cc:
+         39:7d:da:c5:11:55:72:c5:3b:8b:89:f8:34:2d:a4:17:e5:17:
+         e6:99:7d:30:88:21:37:cd:30:17:3d:b8:f2:bc:a8:75:a0:43:
+         dc:3e:89:4b:90:ae:6d:03:e0:1c:a3:a0:96:09:bb:7d:a3:b7:
+         2a:10:44:4b:46:07:34:63:ed:31:b9:04:ee:a3:9b:9a:ae:e6:
+         31:78:f4:ea:24:61:3b:ab:58:64:ff:bb:87:27:62:25:81:df:
+         dc:a1:2f:f6:ed:a7:ff:7a:8f:51:2e:30:f8:a4:01:d2:85:39:
+         5f:01:99:96:6f:5a:5b:70:19:46:fe:86:60:3e:ad:80:10:09:
+         dd:39:25:2f:58:7f:bb:d2:74:f0:f7:46:1f:46:39:4a:d8:53:
+         d0:f3:2e:3b:71:a5:d4:6f:fc:f3:67:e4:07:8f:dd:26:19:e1:
+         8d:5b:fa:a3:93:11:9b:e9:c8:3a:c3:55:68:9a:92:e1:52:76:
+         38:e8:e1:ba:bd:fb:4f:d5:ef:b3:e7:48:83:31:f0:82:21:e3:
+         b6:be:a7:ab:6f:ef:9f:df:4c:cf:01:b8:62:6a:23:3d:e7:09:
+         4d:80:1b:7b:30:a4:c3:dd:07:7f:34:be:a4:26:b2:f6:41:e8:
+         09:1d:e3:20:98:aa:37:4f:ff:f7:f1:e2:29:70:31:47:3f:74:
+         d0:14:16:fa:21:8a:02:d5:8a:09:94:77:2e:f2:59:28:8b:7c:
+         50:92:0a:66:78:38:83:75:c4:b5:5a:a8:11:c6:e5:c1:9d:66:
+         55:cf:53:c4:af:d7:75:85:a9:42:13:56:ec:21:77:81:93:5a:
+         0c:ea:96:d9:49:ca:a1:08:f2:97:3b:6d:9b:04:18:24:44:8e:
+         7c:01:f2:dc:25:d8:5e:86:9a:b1:39:db:f5:91:32:6a:d1:a6:
+         70:8a:a2:f7:de:a4:45:85:26:a8:1e:8c:5d:29:5b:c8:4b:d8:
+         9a:6a:03:5e:70:f2:85:4f:6c:4b:68:2f:ca:54:f6:8c:da:32:
+         fe:c3:6b:83:3f:38:c6:7e
+SHA1 Fingerprint=A7:88:49:DC:5D:7C:75:8C:8C:DE:39:98:56:B3:AA:D0:B2:A5:71:35
+-----BEGIN CERTIFICATE-----
+MIIFZjCCA06gAwIBAgIQCPm0eKj6ftpqMzeJ3nzPijANBgkqhkiG9w0BAQwFADBN
+MQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xJTAjBgNVBAMT
+HERpZ2lDZXJ0IFRMUyBSU0E0MDk2IFJvb3QgRzUwHhcNMjEwMTE1MDAwMDAwWhcN
+NDYwMTE0MjM1OTU5WjBNMQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQs
+IEluYy4xJTAjBgNVBAMTHERpZ2lDZXJ0IFRMUyBSU0E0MDk2IFJvb3QgRzUwggIi
+MA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCz0PTJeRGd/fxmgefM1eS87IE+
+ajWOLrfn3q/5B03PMJ3qCQuZvWxX2hhKuHisOjmopkisLnLlvevxGs3npAOpPxG0
+2C+JFvuUAT27L/gTBaF4HI4o4EXgg/RZG5Wzrn4DReW+wkL+7vI8toUTmDKdFqgp
+wgscONyfMXdcvyej/Cestyu9dJsXLfKB2l2w4SMXPohKEiPQ6s+d3gMXsUJKoBZM
+pG2T6T867jp8nVid9E6P/DsjyG244gXazOvswzH016cpVIDPRFtMbzCe88zdH5RD
+nU1/cHAN1DrRN/BsnZvAFJNY781BOHW8EwOVfH/jXOnVDdXifBBiqmvwPXbzP6Po
+sMH976pXTayGpxi0KcEsDr9kvimM2AItzVwv8n/vFfQMFawKsPHTDU9qTXeXAaDx
+Zre3zu/O7Oyldcqs4+Fj97ihBMi8ez9dLRYiVu1ISf6nL3kwJZu6ay0/nTvEF+cd
+Lvvyz6b84xQslpghjLSR6Rlgg/IwKwZzUNWYOwbpx4oMYIwo+FKbbuH2TbsGJJvX
+KyY//SovcfXWJL5/MZ4PbeiPT02jP/816t9JXkGPhvnxd3lLG7SjXi/7RgLQZhNe
+XoVPzthwiHvOAbWWl9fNff2C+MIkwcoBOU+NosEUQB+cZtUMCUbW8tDRSHZWOkPL
+tgoRObqME2wGtZ7P6wIDAQABo0IwQDAdBgNVHQ4EFgQUUTMc7TZArxfTJc1paPKv
+TiM+s0EwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcN
+AQEMBQADggIBAGCmr1tfV9qJ20tQqcQjNSH/0GEwhJG3PxDPJY7Jv0Y02cEhJhxw
+GXIeo8mH/qlDZJY6yFMECrZBu8RHANmfGBg7sg7zNOok992vIGCukihfNudd5N7H
+PNtQOa27PShNlnx2xlv0wdsUpasZYgcYQF+Xkdycx6u1UQ3maVNVzDl92sURVXLF
+O4uJ+DQtpBflF+aZfTCIITfNMBc9uPK8qHWgQ9w+iUuQrm0D4ByjoJYJu32jtyoQ
+REtGBzRj7TG5BO6jm5qu5jF49OokYTurWGT/u4cnYiWB39yhL/btp/96j1EuMPik
+AdKFOV8BmZZvWltwGUb+hmA+rYAQCd05JS9Yf7vSdPD3Rh9GOUrYU9DzLjtxpdRv
+/PNn5AeP3SYZ4Y1b+qOTEZvpyDrDVWiakuFSdjjo4bq9+0/V77PnSIMx8IIh47a+
+p6tv75/fTM8BuGJqIz3nCU2AG3swpMPdB380vqQmsvZB6Akd4yCYqjdP//fx4ilw
+MUc/dNAUFvohigLVigmUdy7yWSiLfFCSCmZ4OIN1xLVaqBHG5cGdZlXPU8Sv13WF
+qUITVuwhd4GTWgzqltlJyqEI8pc7bZsEGCREjnwB8twl2F6GmrE52/WRMmrRpnCK
+ovfepEWFJqgejF0pW8hL2JpqA15w8oVPbEtoL8pU9ozaMv7Da4M/OMZ+
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem b/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
new file mode 100644
index 000000000000..589b4f911531
--- /dev/null
+++ b/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
@@ -0,0 +1,73 @@
+##
+##  E-Tugra Global Root CA ECC v3
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            26:46:19:77:31:e1:4f:6f:28:36:de:39:51:86:e6:d4:97:88:22:c1
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA ECC v3
+        Validity
+            Not Before: Mar 18 09:46:58 2020 GMT
+            Not After : Mar 12 09:46:58 2045 GMT
+        Subject: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA ECC v3
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:8e:98:29:bf:c7:10:1e:27:db:ab:03:cc:28:2c:
+                    d8:5e:48:19:10:29:cc:cb:59:81:cc:8c:b8:92:17:
+                    89:83:2a:92:f6:c3:a4:1d:4c:62:d5:9f:d6:a0:46:
+                    dc:1c:bc:76:c1:e3:47:d0:5b:13:da:e7:a5:b3:66:
+                    48:e7:21:9a:4a:4f:86:0a:7d:6c:ea:4d:32:80:0a:
+                    b2:7a:09:9b:69:4b:98:81:e2:2e:ec:02:70:96:1f:
+                    fd:f5:46:ce:ca:dc:82
+                ASN1 OID: secp384r1
+                NIST CURVE: P-384
+        X509v3 extensions:
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Authority Key Identifier: 
+                keyid:FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
+
+            X509v3 Subject Key Identifier: 
+                FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: ecdsa-with-SHA384
+         30:66:02:31:00:e6:05:58:69:61:e5:2d:ca:0d:cb:f1:19:08:
+         bd:d6:fd:51:92:1a:7e:63:54:04:90:91:9a:35:91:39:99:fa:
+         07:a9:66:93:ba:c8:68:d4:8a:3f:fa:ed:6e:16:02:27:b7:02:
+         31:00:dd:5a:17:2b:76:1d:65:42:96:a6:ac:5d:8a:79:56:d8:
+         8a:1b:df:9a:de:5f:c7:50:8f:b1:5b:71:0c:26:df:6a:40:00:
+         ec:33:91:21:71:be:68:e4:23:a4:d9:ad:a1:37
+SHA1 Fingerprint=8A:2F:AF:57:53:B1:B0:E6:A1:04:EC:5B:6A:69:71:6D:F6:1C:E2:84
+-----BEGIN CERTIFICATE-----
+MIICpTCCAiqgAwIBAgIUJkYZdzHhT28oNt45UYbm1JeIIsEwCgYIKoZIzj0EAwMw
+gYAxCzAJBgNVBAYTAlRSMQ8wDQYDVQQHEwZBbmthcmExGTAXBgNVBAoTEEUtVHVn
+cmEgRUJHIEEuUy4xHTAbBgNVBAsTFEUtVHVncmEgVHJ1c3QgQ2VudGVyMSYwJAYD
+VQQDEx1FLVR1Z3JhIEdsb2JhbCBSb290IENBIEVDQyB2MzAeFw0yMDAzMTgwOTQ2
+NThaFw00NTAzMTIwOTQ2NThaMIGAMQswCQYDVQQGEwJUUjEPMA0GA1UEBxMGQW5r
+YXJhMRkwFwYDVQQKExBFLVR1Z3JhIEVCRyBBLlMuMR0wGwYDVQQLExRFLVR1Z3Jh
+IFRydXN0IENlbnRlcjEmMCQGA1UEAxMdRS1UdWdyYSBHbG9iYWwgUm9vdCBDQSBF
+Q0MgdjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAASOmCm/xxAeJ9urA8woLNheSBkQ
+KczLWYHMjLiSF4mDKpL2w6QdTGLVn9agRtwcvHbB40fQWxPa56WzZkjnIZpKT4YK
+fWzqTTKACrJ6CZtpS5iB4i7sAnCWH/31Rs7K3IKjYzBhMA8GA1UdEwEB/wQFMAMB
+Af8wHwYDVR0jBBgwFoAU/4Ixcj75xGZsrTie0bBRiKWQzPUwHQYDVR0OBBYEFP+C
+MXI++cRmbK04ntGwUYilkMz1MA4GA1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAwNp
+ADBmAjEA5gVYaWHlLcoNy/EZCL3W/VGSGn5jVASQkZo1kTmZ+gepZpO6yGjUij/6
+7W4WAie3AjEA3VoXK3YdZUKWpqxdinlW2Iob35reX8dQj7FbcQwm32pAAOwzkSFx
+vmjkI6TZraE3
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem b/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
new file mode 100644
index 000000000000..147ba810d1d6
--- /dev/null
+++ b/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
@@ -0,0 +1,140 @@
+##
+##  E-Tugra Global Root CA RSA v3
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  It contains a certificate trusted for server authentication.
+##
+##  Extracted from nss
+##  with $FreeBSD$
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            0d:4d:c5:cd:16:22:95:96:08:7e:b8:0b:7f:15:06:34:fb:79:10:34
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA RSA v3
+        Validity
+            Not Before: Mar 18 09:07:17 2020 GMT
+            Not After : Mar 12 09:07:17 2045 GMT
+        Subject: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA RSA v3
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:a2:66:f0:89:b7:72:7b:ee:09:c9:63:d2:d3:43:
+                    dd:5e:c3:a6:84:38:4a:f1:8d:81:bb:14:bd:47:e8:
+                    40:17:f3:3d:c3:78:45:72:a6:2e:90:de:9a:3a:d4:
+                    20:71:ca:bc:9f:1d:4b:97:0a:c7:31:ba:3e:d7:fe:
+                    25:a9:2a:8e:36:f4:d1:2f:c7:b7:a9:5d:33:dc:30:
+                    70:f8:40:6c:4b:b2:a6:31:61:d1:34:3c:3d:31:7a:
+                    c7:af:c4:a7:a7:84:e1:97:a4:e8:4b:f6:17:7c:ee:
+                    3c:07:ed:e2:8a:57:dc:b6:fb:f8:43:25:50:ea:27:
+                    81:a8:86:bc:8f:52:4a:96:3a:60:1a:96:bb:fd:73:
+                    f4:85:fd:83:fd:7f:84:6d:34:6c:7f:6a:b7:4b:01:
+                    03:bf:ad:69:b7:d7:32:d9:f5:57:6a:e9:86:82:3e:
+                    a5:66:31:b3:16:3d:c2:f3:26:60:32:d3:52:1e:b0:
+                    6c:a4:37:3e:f4:f5:af:eb:e1:df:80:06:cf:2a:41:
+                    e7:66:09:e1:4b:97:e7:77:bd:21:6d:29:b6:67:c3:
+                    2d:7e:ed:d6:79:65:d1:cf:3a:b6:d1:b1:5e:56:61:
+                    50:7a:5a:ce:4e:50:31:80:03:98:47:e7:e4:18:7c:
+                    44:5a:c6:a4:b3:3b:c6:c6:c3:3a:f0:6c:c3:8b:c8:
+                    a4:91:05:f3:f5:d9:b6:aa:06:a1:b7:ab:e4:b1:ea:
+                    21:14:5c:83:a4:fc:ff:b6:50:d3:8c:12:26:99:76:
+                    70:e9:c0:0f:a6:74:fc:bb:d0:1b:78:ce:72:92:e2:
+                    28:9c:bc:e6:e9:09:d8:3a:d3:89:e6:be:2e:77:df:
+                    01:0a:6f:96:f6:e5:8d:3c:4d:52:76:1a:56:e1:73:
+                    7e:17:ac:3d:ad:6c:a3:52:12:18:70:e6:80:4e:33:
+                    f2:7e:26:32:ac:05:8d:38:a4:e6:76:3c:9f:10:69:
+                    0e:6d:9d:d2:c1:79:20:6b:5b:cf:33:8d:d1:94:76:
*** 1231 LINES SKIPPED ***