SSL Certificates in base

Andrea Venturoli ml at
Wed Feb 24 08:58:03 UTC 2021

Hello again.

Sorry if this a dumb question or FAQ: I tried, but failed to find any 
official documentation on this.

In the past, I've always installed security/ca_root_nss to let SSL work, 
as there were no CA certificates in base.
12.2 (and possibly older 12.x, I don't know) already provide several 
certificates in /usr/share/certs/trusted.

How are we expected to deal with this?
Is security/ca_root_nss still needed/suggested?
Is it expected to be obsoleted (although easier to update)?

What's the correct procedure to add additional certificates?
I guess just dropping them in /usr/share/certs/trusted won't be enough...

  bye & Thanks

More information about the freebsd-questions mailing list