svn commit: r360395 - in stable: 11/secure/caroot/trusted 12/secure/caroot/trusted

Kyle Evans kevans at FreeBSD.org
Mon Apr 27 21:41:02 UTC 2020


Author: kevans
Date: Mon Apr 27 21:41:00 2020
New Revision: 360395
URL: https://svnweb.freebsd.org/changeset/base/360395

Log:
  MFC r353095, r355376: add root bundle
  
  r353095:
  caroot: commit initial bundle
  
  Interested users can blacklist any/all of these with certctl(8), examples:
  
  - mv /usr/share/certs/trusted/... /usr/share/certs/blacklisted/...; \
      certctl rehash
  - certctl blacklist /usr/share/certs/trusted/*; \
      certctl rehash
  
  Certs can be easily examined after installation with `certctl list`, and
  certctl blacklist will accept the hashed filename as output by list or as
  seen in /etc/ssl/certs
  
  r355376:
  caroot update to latest tip: one (1) addition, none (0) removed
  
  Added:
  - Entrust Root Certification Authority - G4
  
  Relnotes:	yes, please

Added:
  stable/11/secure/caroot/trusted/ACCVRAIZ1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ACCVRAIZ1.pem
  stable/11/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
  stable/11/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
  stable/11/secure/caroot/trusted/AddTrust_External_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AddTrust_External_Root.pem
  stable/11/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem
  stable/11/secure/caroot/trusted/AffirmTrust_Commercial.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Commercial.pem
  stable/11/secure/caroot/trusted/AffirmTrust_Networking.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Networking.pem
  stable/11/secure/caroot/trusted/AffirmTrust_Premium.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Premium.pem
  stable/11/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
  stable/11/secure/caroot/trusted/Amazon_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_1.pem
  stable/11/secure/caroot/trusted/Amazon_Root_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_2.pem
  stable/11/secure/caroot/trusted/Amazon_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_3.pem
  stable/11/secure/caroot/trusted/Amazon_Root_CA_4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_4.pem
  stable/11/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
  stable/11/secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
  stable/11/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
  stable/11/secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
  stable/11/secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
  stable/11/secure/caroot/trusted/CA_Disig_Root_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/CA_Disig_Root_R2.pem
  stable/11/secure/caroot/trusted/CFCA_EV_ROOT.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/CFCA_EV_ROOT.pem
  stable/11/secure/caroot/trusted/COMODO_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_Certification_Authority.pem
  stable/11/secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
  stable/11/secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
  stable/11/secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
  stable/11/secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
  stable/11/secure/caroot/trusted/Certigna.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certigna.pem
  stable/11/secure/caroot/trusted/Certigna_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certigna_Root_CA.pem
  stable/11/secure/caroot/trusted/Certum_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Root_CA.pem
  stable/11/secure/caroot/trusted/Certum_Trusted_Network_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Trusted_Network_CA.pem
  stable/11/secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
  stable/11/secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
  stable/11/secure/caroot/trusted/Comodo_AAA_Services_root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Comodo_AAA_Services_root.pem
  stable/11/secure/caroot/trusted/Cybertrust_Global_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Cybertrust_Global_Root.pem
  stable/11/secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
  stable/11/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
  stable/11/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
  stable/11/secure/caroot/trusted/DST_Root_CA_X3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DST_Root_CA_X3.pem
  stable/11/secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
  stable/11/secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
  stable/11/secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
  stable/11/secure/caroot/trusted/DigiCert_Global_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_CA.pem
  stable/11/secure/caroot/trusted/DigiCert_Global_Root_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_G2.pem
  stable/11/secure/caroot/trusted/DigiCert_Global_Root_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_G3.pem
  stable/11/secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
  stable/11/secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
  stable/11/secure/caroot/trusted/E-Tugra_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/E-Tugra_Certification_Authority.pem
  stable/11/secure/caroot/trusted/EC-ACC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/EC-ACC.pem
  stable/11/secure/caroot/trusted/EE_Certification_Centre_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/EE_Certification_Centre_Root_CA.pem
  stable/11/secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
  stable/11/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
  stable/11/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
  stable/11/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
     - copied unchanged from r355376, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
  stable/11/secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
  stable/11/secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
  stable/11/secure/caroot/trusted/GTS_Root_R1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R1.pem
  stable/11/secure/caroot/trusted/GTS_Root_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R2.pem
  stable/11/secure/caroot/trusted/GTS_Root_R3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R3.pem
  stable/11/secure/caroot/trusted/GTS_Root_R4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R4.pem
  stable/11/secure/caroot/trusted/GeoTrust_Global_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Global_CA.pem
  stable/11/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem
  stable/11/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
  stable/11/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
  stable/11/secure/caroot/trusted/GeoTrust_Universal_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Universal_CA.pem
  stable/11/secure/caroot/trusted/GeoTrust_Universal_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Universal_CA_2.pem
  stable/11/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
  stable/11/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
  stable/11/secure/caroot/trusted/GlobalSign_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA.pem
  stable/11/secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
  stable/11/secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
  stable/11/secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
  stable/11/secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
  stable/11/secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
  stable/11/secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
  stable/11/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
  stable/11/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
  stable/11/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
  stable/11/secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
  stable/11/secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
  stable/11/secure/caroot/trusted/ISRG_Root_X1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ISRG_Root_X1.pem
  stable/11/secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
  stable/11/secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
  stable/11/secure/caroot/trusted/Izenpe_com.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Izenpe_com.pem
  stable/11/secure/caroot/trusted/LuxTrust_Global_Root_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/LuxTrust_Global_Root_2.pem
  stable/11/secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
  stable/11/secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
  stable/11/secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
  stable/11/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
  stable/11/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
  stable/11/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_2.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_3.pem
  stable/11/secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
  stable/11/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
  stable/11/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
  stable/11/secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
  stable/11/secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
  stable/11/secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
  stable/11/secure/caroot/trusted/SecureSign_RootCA11.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SecureSign_RootCA11.pem
  stable/11/secure/caroot/trusted/SecureTrust_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SecureTrust_CA.pem
  stable/11/secure/caroot/trusted/Secure_Global_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Secure_Global_CA.pem
  stable/11/secure/caroot/trusted/Security_Communication_RootCA2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Security_Communication_RootCA2.pem
  stable/11/secure/caroot/trusted/Security_Communication_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Security_Communication_Root_CA.pem
  stable/11/secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
  stable/11/secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
  stable/11/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G2.pem
  stable/11/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
  stable/11/secure/caroot/trusted/Starfield_Class_2_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Class_2_CA.pem
  stable/11/secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
  stable/11/secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
  stable/11/secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
  stable/11/secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
  stable/11/secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
  stable/11/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
  stable/11/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
  stable/11/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
  stable/11/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
  stable/11/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
  stable/11/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
  stable/11/secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
  stable/11/secure/caroot/trusted/TWCA_Global_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TWCA_Global_Root_CA.pem
  stable/11/secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
  stable/11/secure/caroot/trusted/Taiwan_GRCA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Taiwan_GRCA.pem
  stable/11/secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
  stable/11/secure/caroot/trusted/TrustCor_ECA-1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_ECA-1.pem
  stable/11/secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
  stable/11/secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
  stable/11/secure/caroot/trusted/Trustis_FPS_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Trustis_FPS_Root_CA.pem
  stable/11/secure/caroot/trusted/UCA_Extended_Validation_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/UCA_Extended_Validation_Root.pem
  stable/11/secure/caroot/trusted/UCA_Global_G2_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/UCA_Global_G2_Root.pem
  stable/11/secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
  stable/11/secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
  stable/11/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
  stable/11/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
  stable/11/secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
  stable/11/secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
  stable/11/secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
  stable/11/secure/caroot/trusted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
  stable/11/secure/caroot/trusted/XRamp_Global_CA_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/XRamp_Global_CA_Root.pem
  stable/11/secure/caroot/trusted/certSIGN_ROOT_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/certSIGN_ROOT_CA.pem
  stable/11/secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
  stable/11/secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
  stable/11/secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
  stable/11/secure/caroot/trusted/emSign_Root_CA_-_C1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_Root_CA_-_C1.pem
  stable/11/secure/caroot/trusted/emSign_Root_CA_-_G1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_Root_CA_-_G1.pem
  stable/11/secure/caroot/trusted/thawte_Primary_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA.pem
  stable/11/secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem
  stable/11/secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem
Modified:
Directory Properties:
  stable/11/   (props changed)

Changes in other areas also in this revision:
Added:
  stable/12/secure/caroot/trusted/ACCVRAIZ1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ACCVRAIZ1.pem
  stable/12/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem
  stable/12/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem
  stable/12/secure/caroot/trusted/AddTrust_External_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AddTrust_External_Root.pem
  stable/12/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem
  stable/12/secure/caroot/trusted/AffirmTrust_Commercial.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Commercial.pem
  stable/12/secure/caroot/trusted/AffirmTrust_Networking.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Networking.pem
  stable/12/secure/caroot/trusted/AffirmTrust_Premium.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Premium.pem
  stable/12/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem
  stable/12/secure/caroot/trusted/Amazon_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_1.pem
  stable/12/secure/caroot/trusted/Amazon_Root_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_2.pem
  stable/12/secure/caroot/trusted/Amazon_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_3.pem
  stable/12/secure/caroot/trusted/Amazon_Root_CA_4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Amazon_Root_CA_4.pem
  stable/12/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Atos_TrustedRoot_2011.pem
  stable/12/secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
  stable/12/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Baltimore_CyberTrust_Root.pem
  stable/12/secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Buypass_Class_2_Root_CA.pem
  stable/12/secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Buypass_Class_3_Root_CA.pem
  stable/12/secure/caroot/trusted/CA_Disig_Root_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/CA_Disig_Root_R2.pem
  stable/12/secure/caroot/trusted/CFCA_EV_ROOT.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/CFCA_EV_ROOT.pem
  stable/12/secure/caroot/trusted/COMODO_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_Certification_Authority.pem
  stable/12/secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_ECC_Certification_Authority.pem
  stable/12/secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/COMODO_RSA_Certification_Authority.pem
  stable/12/secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Camerfirma_Chambers_of_Commerce_Root.pem
  stable/12/secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Camerfirma_Global_Chambersign_Root.pem
  stable/12/secure/caroot/trusted/Certigna.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certigna.pem
  stable/12/secure/caroot/trusted/Certigna_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certigna_Root_CA.pem
  stable/12/secure/caroot/trusted/Certum_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Root_CA.pem
  stable/12/secure/caroot/trusted/Certum_Trusted_Network_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Trusted_Network_CA.pem
  stable/12/secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Certum_Trusted_Network_CA_2.pem
  stable/12/secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Chambers_of_Commerce_Root_-_2008.pem
  stable/12/secure/caroot/trusted/Comodo_AAA_Services_root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Comodo_AAA_Services_root.pem
  stable/12/secure/caroot/trusted/Cybertrust_Global_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Cybertrust_Global_Root.pem
  stable/12/secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_CA_3_2013.pem
  stable/12/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_2009.pem
  stable/12/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
  stable/12/secure/caroot/trusted/DST_Root_CA_X3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DST_Root_CA_X3.pem
  stable/12/secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_CA.pem
  stable/12/secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_G2.pem
  stable/12/secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Assured_ID_Root_G3.pem
  stable/12/secure/caroot/trusted/DigiCert_Global_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_CA.pem
  stable/12/secure/caroot/trusted/DigiCert_Global_Root_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_G2.pem
  stable/12/secure/caroot/trusted/DigiCert_Global_Root_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Global_Root_G3.pem
  stable/12/secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_High_Assurance_EV_Root_CA.pem
  stable/12/secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/DigiCert_Trusted_Root_G4.pem
  stable/12/secure/caroot/trusted/E-Tugra_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/E-Tugra_Certification_Authority.pem
  stable/12/secure/caroot/trusted/EC-ACC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/EC-ACC.pem
  stable/12/secure/caroot/trusted/EE_Certification_Centre_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/EE_Certification_Centre_Root_CA.pem
  stable/12/secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority.pem
  stable/12/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_EC1.pem
  stable/12/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G2.pem
  stable/12/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
     - copied unchanged from r355376, head/secure/caroot/trusted/Entrust_Root_Certification_Authority_-_G4.pem
  stable/12/secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Entrust_net_Premium_2048_Secure_Server_CA.pem
  stable/12/secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GDCA_TrustAUTH_R5_ROOT.pem
  stable/12/secure/caroot/trusted/GTS_Root_R1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R1.pem
  stable/12/secure/caroot/trusted/GTS_Root_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R2.pem
  stable/12/secure/caroot/trusted/GTS_Root_R3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R3.pem
  stable/12/secure/caroot/trusted/GTS_Root_R4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GTS_Root_R4.pem
  stable/12/secure/caroot/trusted/GeoTrust_Global_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Global_CA.pem
  stable/12/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority.pem
  stable/12/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G2.pem
  stable/12/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Primary_Certification_Authority_-_G3.pem
  stable/12/secure/caroot/trusted/GeoTrust_Universal_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Universal_CA.pem
  stable/12/secure/caroot/trusted/GeoTrust_Universal_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GeoTrust_Universal_CA_2.pem
  stable/12/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R4.pem
  stable/12/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_ECC_Root_CA_-_R5.pem
  stable/12/secure/caroot/trusted/GlobalSign_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA.pem
  stable/12/secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R2.pem
  stable/12/secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R3.pem
  stable/12/secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/GlobalSign_Root_CA_-_R6.pem
  stable/12/secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Global_Chambersign_Root_-_2008.pem
  stable/12/secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Go_Daddy_Class_2_CA.pem
  stable/12/secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Go_Daddy_Root_Certificate_Authority_-_G2.pem
  stable/12/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
  stable/12/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
  stable/12/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
  stable/12/secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hongkong_Post_Root_CA_1.pem
  stable/12/secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Hongkong_Post_Root_CA_3.pem
  stable/12/secure/caroot/trusted/ISRG_Root_X1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ISRG_Root_X1.pem
  stable/12/secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/IdenTrust_Commercial_Root_CA_1.pem
  stable/12/secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/IdenTrust_Public_Sector_Root_CA_1.pem
  stable/12/secure/caroot/trusted/Izenpe_com.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Izenpe_com.pem
  stable/12/secure/caroot/trusted/LuxTrust_Global_Root_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/LuxTrust_Global_Root_2.pem
  stable/12/secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Microsec_e-Szigno_Root_CA_2009.pem
  stable/12/secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
  stable/12/secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Network_Solutions_Certificate_Authority.pem
  stable/12/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GA_CA.pem
  stable/12/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GB_CA.pem
  stable/12/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/OISTE_WISeKey_Global_Root_GC_CA.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_1_G3.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_2.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_2_G3.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_3.pem
  stable/12/secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/QuoVadis_Root_CA_3_G3.pem
  stable/12/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_ECC.pem
  stable/12/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_EV_Root_Certification_Authority_RSA_R2.pem
  stable/12/secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_Root_Certification_Authority_ECC.pem
  stable/12/secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SSL_com_Root_Certification_Authority_RSA.pem
  stable/12/secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SZAFIR_ROOT_CA2.pem
  stable/12/secure/caroot/trusted/SecureSign_RootCA11.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SecureSign_RootCA11.pem
  stable/12/secure/caroot/trusted/SecureTrust_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SecureTrust_CA.pem
  stable/12/secure/caroot/trusted/Secure_Global_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Secure_Global_CA.pem
  stable/12/secure/caroot/trusted/Security_Communication_RootCA2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Security_Communication_RootCA2.pem
  stable/12/secure/caroot/trusted/Security_Communication_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Security_Communication_Root_CA.pem
  stable/12/secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Sonera_Class_2_Root_CA.pem
  stable/12/secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_EV_Root_CA.pem
  stable/12/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G2.pem
  stable/12/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Staat_der_Nederlanden_Root_CA_-_G3.pem
  stable/12/secure/caroot/trusted/Starfield_Class_2_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Class_2_CA.pem
  stable/12/secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Root_Certificate_Authority_-_G2.pem
  stable/12/secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Starfield_Services_Root_Certificate_Authority_-_G2.pem
  stable/12/secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Gold_CA_-_G2.pem
  stable/12/secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Platinum_CA_-_G2.pem
  stable/12/secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/SwissSign_Silver_CA_-_G2.pem
  stable/12/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem
  stable/12/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem
  stable/12/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem
  stable/12/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem
  stable/12/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_2.pem
  stable/12/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/T-TeleSec_GlobalRoot_Class_3.pem
  stable/12/secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
  stable/12/secure/caroot/trusted/TWCA_Global_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TWCA_Global_Root_CA.pem
  stable/12/secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TWCA_Root_Certification_Authority.pem
  stable/12/secure/caroot/trusted/Taiwan_GRCA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Taiwan_GRCA.pem
  stable/12/secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TeliaSonera_Root_CA_v1.pem
  stable/12/secure/caroot/trusted/TrustCor_ECA-1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_ECA-1.pem
  stable/12/secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_RootCert_CA-1.pem
  stable/12/secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/TrustCor_RootCert_CA-2.pem
  stable/12/secure/caroot/trusted/Trustis_FPS_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Trustis_FPS_Root_CA.pem
  stable/12/secure/caroot/trusted/UCA_Extended_Validation_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/UCA_Extended_Validation_Root.pem
  stable/12/secure/caroot/trusted/UCA_Global_G2_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/UCA_Global_G2_Root.pem
  stable/12/secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/USERTrust_ECC_Certification_Authority.pem
  stable/12/secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/USERTrust_RSA_Certification_Authority.pem
  stable/12/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem
  stable/12/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem
  stable/12/secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/VeriSign_Universal_Root_Certification_Authority.pem
  stable/12/secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem
  stable/12/secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem
  stable/12/secure/caroot/trusted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem
  stable/12/secure/caroot/trusted/XRamp_Global_CA_Root.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/XRamp_Global_CA_Root.pem
  stable/12/secure/caroot/trusted/certSIGN_ROOT_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/certSIGN_ROOT_CA.pem
  stable/12/secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/ePKI_Root_Certification_Authority.pem
  stable/12/secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_ECC_Root_CA_-_C3.pem
  stable/12/secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_ECC_Root_CA_-_G3.pem
  stable/12/secure/caroot/trusted/emSign_Root_CA_-_C1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_Root_CA_-_C1.pem
  stable/12/secure/caroot/trusted/emSign_Root_CA_-_G1.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/emSign_Root_CA_-_G1.pem
  stable/12/secure/caroot/trusted/thawte_Primary_Root_CA.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA.pem
  stable/12/secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA_-_G2.pem
  stable/12/secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem
     - copied unchanged from r353095, head/secure/caroot/trusted/thawte_Primary_Root_CA_-_G3.pem
Modified:
Directory Properties:
  stable/12/   (props changed)

Copied: stable/11/secure/caroot/trusted/ACCVRAIZ1.pem (from r353095, head/secure/caroot/trusted/ACCVRAIZ1.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/ACCVRAIZ1.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/ACCVRAIZ1.pem)
@@ -0,0 +1,164 @@
+##
+##  ACCVRAIZ1
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 6828503384748696800 (0x5ec3b7a6437fa4e0)
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: CN = ACCVRAIZ1, OU = PKIACCV, O = ACCV, C = ES
+        Validity
+            Not Before: May  5 09:37:37 2011 GMT
+            Not After : Dec 31 09:37:37 2030 GMT
+        Subject: CN = ACCVRAIZ1, OU = PKIACCV, O = ACCV, C = ES
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:9b:a9:ab:bf:61:4a:97:af:2f:97:66:9a:74:5f:
+                    d0:d9:96:fd:cf:e2:e4:66:ef:1f:1f:47:33:c2:44:
+                    a3:df:9a:de:1f:b5:54:dd:15:7c:69:35:11:6f:bb:
+                    c8:0c:8e:6a:18:1e:d8:8f:d9:16:bc:10:48:36:5c:
+                    f0:63:b3:90:5a:5c:24:37:d7:a3:d6:cb:09:71:b9:
+                    f1:01:72:84:b0:7d:db:4d:80:cd:fc:d3:6f:c9:f8:
+                    da:b6:0e:82:d2:45:85:a8:1b:68:a8:3d:e8:f4:44:
+                    6c:bd:a1:c2:cb:03:be:8c:3e:13:00:84:df:4a:48:
+                    c0:e3:22:0a:e8:e9:37:a7:18:4c:b1:09:0d:23:56:
+                    7f:04:4d:d9:17:84:18:a5:c8:da:40:94:73:eb:ce:
+                    0e:57:3c:03:81:3a:9d:0a:a1:57:43:69:ac:57:6d:
+                    79:90:78:e5:b5:b4:3b:d8:bc:4c:8d:28:a1:a7:a3:
+                    a7:ba:02:4e:25:d1:2a:ae:ed:ae:03:22:b8:6b:20:
+                    0f:30:28:54:95:7f:e0:ee:ce:0a:66:9d:d1:40:2d:
+                    6e:22:af:9d:1a:c1:05:19:d2:6f:c0:f2:9f:f8:7b:
+                    b3:02:42:fb:50:a9:1d:2d:93:0f:23:ab:c6:c1:0f:
+                    92:ff:d0:a2:15:f5:53:09:71:1c:ff:45:13:84:e6:
+                    26:5e:f8:e0:88:1c:0a:fc:16:b6:a8:73:06:b8:f0:
+                    63:84:02:a0:c6:5a:ec:e7:74:df:70:ae:a3:83:25:
+                    ea:d6:c7:97:87:93:a7:c6:8a:8a:33:97:60:37:10:
+                    3e:97:3e:6e:29:15:d6:a1:0f:d1:88:2c:12:9f:6f:
+                    aa:a4:c6:42:eb:41:a2:e3:95:43:d3:01:85:6d:8e:
+                    bb:3b:f3:23:36:c7:fe:3b:e0:a1:25:07:48:ab:c9:
+                    89:74:ff:08:8f:80:bf:c0:96:65:f3:ee:ec:4b:68:
+                    bd:9d:88:c3:31:b3:40:f1:e8:cf:f6:38:bb:9c:e4:
+                    d1:7f:d4:e5:58:9b:7c:fa:d4:f3:0e:9b:75:91:e4:
+                    ba:52:2e:19:7e:d1:f5:cd:5a:19:fc:ba:06:f6:fb:
+                    52:a8:4b:99:04:dd:f8:f9:b4:8b:50:a3:4e:62:89:
+                    f0:87:24:fa:83:42:c1:87:fa:d5:2d:29:2a:5a:71:
+                    7a:64:6a:d7:27:60:63:0d:db:ce:49:f5:8d:1f:90:
+                    89:32:17:f8:73:43:b8:d2:5a:93:86:61:d6:e1:75:
+                    0a:ea:79:66:76:88:4f:71:eb:04:25:d6:0a:5a:7a:
+                    93:e5:b9:4b:17:40:0f:b1:b6:b9:f5:de:4f:dc:e0:
+                    b3:ac:3b:11:70:60:84:4a:43:6e:99:20:c0:29:71:
+                    0a:c0:65
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            Authority Information Access: 
+                CA Issuers - URI:http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt
+                OCSP - URI:http://ocsp.accv.es
+
+            X509v3 Subject Key Identifier: 
+                D2:87:B4:E3:DF:37:27:93:55:F6:56:EA:81:E5:36:CC:8C:1E:3F:BD
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Authority Key Identifier: 
+                keyid:D2:87:B4:E3:DF:37:27:93:55:F6:56:EA:81:E5:36:CC:8C:1E:3F:BD
+
+            X509v3 Certificate Policies: 
+                Policy: X509v3 Any Policy
+                  User Notice:
+                    Explicit Text: 
+                  CPS: http://www.accv.es/legislacion_c.htm
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
+
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Subject Alternative Name: 
+                email:accv at accv.es
+    Signature Algorithm: sha1WithRSAEncryption
+         97:31:02:9f:e7:fd:43:67:48:44:14:e4:29:87:ed:4c:28:66:
+         d0:8f:35:da:4d:61:b7:4a:97:4d:b5:db:90:e0:05:2e:0e:c6:
+         79:d0:f2:97:69:0f:bd:04:47:d9:be:db:b5:29:da:9b:d9:ae:
+         a9:99:d5:d3:3c:30:93:f5:8d:a1:a8:fc:06:8d:44:f4:ca:16:
+         95:7c:33:dc:62:8b:a8:37:f8:27:d8:09:2d:1b:ef:c8:14:27:
+         20:a9:64:44:ff:2e:d6:75:aa:6c:4d:60:40:19:49:43:54:63:
+         da:e2:cc:ba:66:e5:4f:44:7a:5b:d9:6a:81:2b:40:d5:7f:f9:
+         01:27:58:2c:c8:ed:48:91:7c:3f:a6:00:cf:c4:29:73:11:36:
+         de:86:19:3e:9d:ee:19:8a:1b:d5:b0:ed:8e:3d:9c:2a:c0:0d:
+         d8:3d:66:e3:3c:0d:bd:d5:94:5c:e2:e2:a7:35:1b:04:00:f6:
+         3f:5a:8d:ea:43:bd:5f:89:1d:a9:c1:b0:cc:99:e2:4d:00:0a:
+         da:c9:27:5b:e7:13:90:5c:e4:f5:33:a2:55:6d:dc:e0:09:4d:
+         2f:b1:26:5b:27:75:00:09:c4:62:77:29:08:5f:9e:59:ac:b6:
+         7e:ad:9f:54:30:22:03:c1:1e:71:64:fe:f9:38:0a:96:18:dd:
+         02:14:ac:23:cb:06:1c:1e:a4:7d:8d:0d:de:27:41:e8:ad:da:
+         15:b7:b0:23:dd:2b:a8:d3:da:25:87:ed:e8:55:44:4d:88:f4:
+         36:7e:84:9a:78:ac:f7:0e:56:49:0e:d6:33:25:d6:84:50:42:
+         6c:20:12:1d:2a:d5:be:bc:f2:70:81:a4:70:60:be:05:b5:9b:
+         9e:04:44:be:61:23:ac:e9:a5:24:8c:11:80:94:5a:a2:a2:b9:
+         49:d2:c1:dc:d1:a7:ed:31:11:2c:9e:19:a6:ee:e1:55:e1:c0:
+         ea:cf:0d:84:e4:17:b7:a2:7c:a5:de:55:25:06:ee:cc:c0:87:
+         5c:40:da:cc:95:3f:55:e0:35:c7:b8:84:be:b4:5d:cd:7a:83:
+         01:72:ee:87:e6:5f:1d:ae:b5:85:c6:26:df:e6:c1:9a:e9:1e:
+         02:47:9f:2a:a8:6d:a9:5b:cf:ec:45:77:7f:98:27:9a:32:5d:
+         2a:e3:84:ee:c5:98:66:2f:96:20:1d:dd:d8:c3:27:d7:b0:f9:
+         fe:d9:7d:cd:d0:9f:8f:0b:14:58:51:9f:2f:8b:c3:38:2d:de:
+         e8:8f:d6:8d:87:a4:f5:56:43:16:99:2c:f4:a4:56:b4:34:b8:
+         61:37:c9:c2:58:80:1b:a0:97:a1:fc:59:8d:e9:11:f6:d1:0f:
+         4b:55:34:46:2a:8b:86:3b
+SHA1 Fingerprint=93:05:7A:88:15:C6:4F:CE:88:2F:FA:91:16:52:28:78:BC:53:64:17
+-----BEGIN CERTIFICATE-----
+MIIH0zCCBbugAwIBAgIIXsO3pkN/pOAwDQYJKoZIhvcNAQEFBQAwQjESMBAGA1UE
+AwwJQUNDVlJBSVoxMRAwDgYDVQQLDAdQS0lBQ0NWMQ0wCwYDVQQKDARBQ0NWMQsw
+CQYDVQQGEwJFUzAeFw0xMTA1MDUwOTM3MzdaFw0zMDEyMzEwOTM3MzdaMEIxEjAQ
+BgNVBAMMCUFDQ1ZSQUlaMTEQMA4GA1UECwwHUEtJQUNDVjENMAsGA1UECgwEQUND
+VjELMAkGA1UEBhMCRVMwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCb
+qau/YUqXry+XZpp0X9DZlv3P4uRm7x8fRzPCRKPfmt4ftVTdFXxpNRFvu8gMjmoY
+HtiP2Ra8EEg2XPBjs5BaXCQ316PWywlxufEBcoSwfdtNgM3802/J+Nq2DoLSRYWo
+G2ioPej0RGy9ocLLA76MPhMAhN9KSMDjIgro6TenGEyxCQ0jVn8ETdkXhBilyNpA
+lHPrzg5XPAOBOp0KoVdDaaxXbXmQeOW1tDvYvEyNKKGno6e6Ak4l0Squ7a4DIrhr
+IA8wKFSVf+DuzgpmndFALW4ir50awQUZ0m/A8p/4e7MCQvtQqR0tkw8jq8bBD5L/
+0KIV9VMJcRz/RROE5iZe+OCIHAr8Fraocwa48GOEAqDGWuzndN9wrqODJerWx5eH
+k6fGioozl2A3ED6XPm4pFdahD9GILBKfb6qkxkLrQaLjlUPTAYVtjrs78yM2x/47
+4KElB0iryYl0/wiPgL/AlmXz7uxLaL2diMMxs0Dx6M/2OLuc5NF/1OVYm3z61PMO
+m3WR5LpSLhl+0fXNWhn8ugb2+1KoS5kE3fj5tItQo05iifCHJPqDQsGH+tUtKSpa
+cXpkatcnYGMN285J9Y0fkIkyF/hzQ7jSWpOGYdbhdQrqeWZ2iE9x6wQl1gpaepPl
+uUsXQA+xtrn13k/c4LOsOxFwYIRKQ26ZIMApcQrAZQIDAQABo4ICyzCCAscwfQYI
+KwYBBQUHAQEEcTBvMEwGCCsGAQUFBzAChkBodHRwOi8vd3d3LmFjY3YuZXMvZmls
+ZWFkbWluL0FyY2hpdm9zL2NlcnRpZmljYWRvcy9yYWl6YWNjdjEuY3J0MB8GCCsG
+AQUFBzABhhNodHRwOi8vb2NzcC5hY2N2LmVzMB0GA1UdDgQWBBTSh7Tj3zcnk1X2
+VuqB5TbMjB4/vTAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFNKHtOPfNyeT
+VfZW6oHlNsyMHj+9MIIBcwYDVR0gBIIBajCCAWYwggFiBgRVHSAAMIIBWDCCASIG
+CCsGAQUFBwICMIIBFB6CARAAQQB1AHQAbwByAGkAZABhAGQAIABkAGUAIABDAGUA
+cgB0AGkAZgBpAGMAYQBjAGkA8wBuACAAUgBhAO0AegAgAGQAZQAgAGwAYQAgAEEA
+QwBDAFYAIAAoAEEAZwBlAG4AYwBpAGEAIABkAGUAIABUAGUAYwBuAG8AbABvAGcA
+7QBhACAAeQAgAEMAZQByAHQAaQBmAGkAYwBhAGMAaQDzAG4AIABFAGwAZQBjAHQA
+cgDzAG4AaQBjAGEALAAgAEMASQBGACAAUQA0ADYAMAAxADEANQA2AEUAKQAuACAA
+QwBQAFMAIABlAG4AIABoAHQAdABwADoALwAvAHcAdwB3AC4AYQBjAGMAdgAuAGUA
+czAwBggrBgEFBQcCARYkaHR0cDovL3d3dy5hY2N2LmVzL2xlZ2lzbGFjaW9uX2Mu
+aHRtMFUGA1UdHwROMEwwSqBIoEaGRGh0dHA6Ly93d3cuYWNjdi5lcy9maWxlYWRt
+aW4vQXJjaGl2b3MvY2VydGlmaWNhZG9zL3JhaXphY2N2MV9kZXIuY3JsMA4GA1Ud
+DwEB/wQEAwIBBjAXBgNVHREEEDAOgQxhY2N2QGFjY3YuZXMwDQYJKoZIhvcNAQEF
+BQADggIBAJcxAp/n/UNnSEQU5CmH7UwoZtCPNdpNYbdKl02125DgBS4OxnnQ8pdp
+D70ER9m+27Up2pvZrqmZ1dM8MJP1jaGo/AaNRPTKFpV8M9xii6g3+CfYCS0b78gU
+JyCpZET/LtZ1qmxNYEAZSUNUY9rizLpm5U9EelvZaoErQNV/+QEnWCzI7UiRfD+m
+AM/EKXMRNt6GGT6d7hmKG9Ww7Y49nCrADdg9ZuM8Db3VlFzi4qc1GwQA9j9ajepD
+vV+JHanBsMyZ4k0ACtrJJ1vnE5Bc5PUzolVt3OAJTS+xJlsndQAJxGJ3KQhfnlms
+tn6tn1QwIgPBHnFk/vk4CpYY3QIUrCPLBhwepH2NDd4nQeit2hW3sCPdK6jT2iWH
+7ehVRE2I9DZ+hJp4rPcOVkkO1jMl1oRQQmwgEh0q1b688nCBpHBgvgW1m54ERL5h
+I6zppSSMEYCUWqKiuUnSwdzRp+0xESyeGabu4VXhwOrPDYTkF7eifKXeVSUG7szA
+h1xA2syVP1XgNce4hL60Xc16gwFy7ofmXx2utYXGJt/mwZrpHgJHnyqobalbz+xF
+d3+YJ5oyXSrjhO7FmGYvliAd3djDJ9ew+f7Zfc3Qn48LFFhRny+Lwzgt3uiP1o2H
+pPVWQxaZLPSkVrQ0uGE3ycJYgBugl6H8WY3pEfbRD0tVNEYqi4Y7
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem (from r353095, head/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AC_RAIZ_FNMT-RCM.pem)
@@ -0,0 +1,137 @@
+##
+##  AC RAIZ FNMT-RCM
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            5d:93:8d:30:67:36:c8:06:1d:1a:c7:54:84:69:07
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = ES, O = FNMT-RCM, OU = AC RAIZ FNMT-RCM
+        Validity
+            Not Before: Oct 29 15:59:56 2008 GMT
+            Not After : Jan  1 00:00:00 2030 GMT
+        Subject: C = ES, O = FNMT-RCM, OU = AC RAIZ FNMT-RCM
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:ba:71:80:7a:4c:86:6e:7f:c8:13:6d:c0:c6:7d:
+                    1c:00:97:8f:2c:0c:23:bb:10:9a:40:a9:1a:b7:87:
+                    88:f8:9b:56:6a:fb:e6:7b:8e:8b:92:8e:a7:25:5d:
+                    59:11:db:36:2e:b7:51:17:1f:a9:08:1f:04:17:24:
+                    58:aa:37:4a:18:df:e5:39:d4:57:fd:d7:c1:2c:91:
+                    01:91:e2:22:d4:03:c0:58:fc:77:47:ec:8f:3e:74:
+                    43:ba:ac:34:8d:4d:38:76:67:8e:b0:c8:6f:30:33:
+                    58:71:5c:b4:f5:6b:6e:d4:01:50:b8:13:7e:6c:4a:
+                    a3:49:d1:20:19:ee:bc:c0:29:18:65:a7:de:fe:ef:
+                    dd:0a:90:21:e7:1a:67:92:42:10:98:5f:4f:30:bc:
+                    3e:1c:45:b4:10:d7:68:40:14:c0:40:fa:e7:77:17:
+                    7a:e6:0b:8f:65:5b:3c:d9:9a:52:db:b5:bd:9e:46:
+                    cf:3d:eb:91:05:02:c0:96:b2:76:4c:4d:10:96:3b:
+                    92:fa:9c:7f:0f:99:df:be:23:35:45:1e:02:5c:fe:
+                    b5:a8:9b:99:25:da:5e:f3:22:c3:39:f5:e4:2a:2e:
+                    d3:c6:1f:c4:6c:aa:c5:1c:6a:01:05:4a:2f:d2:c5:
+                    c1:a8:34:26:5d:66:a5:d2:02:21:f9:18:b7:06:f5:
+                    4e:99:6f:a8:ab:4c:51:e8:cf:50:18:c5:77:c8:39:
+                    09:2c:49:92:32:99:a8:bb:17:17:79:b0:5a:c5:e6:
+                    a3:c4:59:65:47:35:83:5e:a9:e8:35:0b:99:bb:e4:
+                    cd:20:c6:9b:4a:06:39:b5:68:fc:22:ba:ee:55:8c:
+                    2b:4e:ea:f3:b1:e3:fc:b6:99:9a:d5:42:fa:71:4d:
+                    08:cf:87:1e:6a:71:7d:f9:d3:b4:e9:a5:71:81:7b:
+                    c2:4e:47:96:a5:f6:76:85:a3:28:8f:e9:80:6e:81:
+                    53:a5:6d:5f:b8:48:f9:c2:f9:36:a6:2e:49:ff:b8:
+                    96:c2:8c:07:b3:9b:88:58:fc:eb:1b:1c:de:2d:70:
+                    e2:97:92:30:a1:89:e3:bc:55:a8:27:d6:4b:ed:90:
+                    ad:8b:fa:63:25:59:2d:a8:35:dd:ca:97:33:bc:e5:
+                    cd:c7:9d:d1:ec:ef:5e:0e:4a:90:06:26:63:ad:b9:
+                    d9:35:2d:07:ba:76:65:2c:ac:57:8f:7d:f4:07:94:
+                    d7:81:02:96:5d:a3:07:49:d5:7a:d0:57:f9:1b:e7:
+                    53:46:75:aa:b0:79:42:cb:68:71:08:e9:60:bd:39:
+                    69:ce:f4:af:c3:56:40:c7:ad:52:a2:09:e4:6f:86:
+                    47:8a:1f:eb:28:27:5d:83:20:af:04:c9:6c:56:9a:
+                    8b:46:f5
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Subject Key Identifier: 
+                F7:7D:C5:FD:C4:E8:9A:1B:77:64:A7:F5:1D:A0:CC:BF:87:60:9A:6D
+            X509v3 Certificate Policies: 
+                Policy: X509v3 Any Policy
+                  CPS: http://www.cert.fnmt.es/dpcs/
+
+    Signature Algorithm: sha256WithRSAEncryption
+         07:90:4a:df:f3:23:4e:f0:c3:9c:51:65:9b:9c:22:a2:8a:0c:
+         85:f3:73:29:6b:4d:fe:01:e2:a9:0c:63:01:bf:04:67:a5:9d:
+         98:5f:fd:01:13:fa:ec:9a:62:e9:86:fe:b6:62:d2:6e:4c:94:
+         fb:c0:75:45:7c:65:0c:f8:b2:37:cf:ac:0f:cf:8d:6f:f9:19:
+         f7:8f:ec:1e:f2:70:9e:f0:ca:b8:ef:b7:ff:76:37:76:5b:f6:
+         6e:88:f3:af:62:32:22:93:0d:3a:6a:8e:14:66:0c:2d:53:74:
+         57:65:1e:d5:b2:dd:23:81:3b:a5:66:23:27:67:09:8f:e1:77:
+         aa:43:cd:65:51:08:ed:51:58:fe:e6:39:f9:cb:47:84:a4:15:
+         f1:76:bb:a4:ee:a4:3b:c4:5f:ef:b2:33:96:11:18:b7:c9:65:
+         be:18:e1:a3:a4:dc:fa:18:f9:d3:bc:13:9b:39:7a:34:ba:d3:
+         41:fb:fa:32:8a:2a:b7:2b:86:0b:69:83:38:be:cd:8a:2e:0b:
+         70:ad:8d:26:92:ee:1e:f5:01:2b:0a:d9:d6:97:9b:6e:e0:a8:
+         19:1c:3a:21:8b:0c:1e:40:ad:03:e7:dd:66:7e:f5:b9:20:0d:
+         03:e8:96:f9:82:45:d4:39:e0:a0:00:5d:d7:98:e6:7d:9e:67:
+         73:c3:9a:2a:f7:ab:8b:a1:3a:14:ef:34:bc:52:0e:89:98:9a:
+         04:40:84:1d:7e:45:69:93:57:ce:eb:ce:f8:50:7c:4f:1c:6e:
+         04:43:9b:f9:d6:3b:23:18:e9:ea:8e:d1:4d:46:8d:f1:3b:e4:
+         6a:ca:ba:fb:23:b7:9b:fa:99:01:29:5a:58:5a:2d:e3:f9:d4:
+         6d:0e:26:ad:c1:6e:34:bc:32:f8:0c:05:fa:65:a3:db:3b:37:
+         83:22:e9:d6:dc:72:33:fd:5d:f2:20:bd:76:3c:23:da:28:f7:
+         f9:1b:eb:59:64:d5:dc:5f:72:7e:20:fc:cd:89:b5:90:67:4d:
+         62:7a:3f:4e:ad:1d:c3:39:fe:7a:f4:28:16:df:41:f6:48:80:
+         05:d7:0f:51:79:ac:10:ab:d4:ec:03:66:e6:6a:b0:ba:31:92:
+         42:40:6a:be:3a:d3:72:e1:6a:37:55:bc:ac:1d:95:b7:69:61:
+         f2:43:91:74:e6:a0:d3:0a:24:46:a1:08:af:d6:da:45:19:96:
+         d4:53:1d:5b:84:79:f0:c0:f7:47:ef:8b:8f:c5:06:ae:9d:4c:
+         62:9d:ff:46:04:f8:d3:c9:b6:10:25:40:75:fe:16:aa:c9:4a:
+         60:86:2f:ba:ef:30:77:e4:54:e2:b8:84:99:58:80:aa:13:8b:
+         51:3a:4f:48:f6:8b:b6:b3
+SHA1 Fingerprint=EC:50:35:07:B2:15:C4:95:62:19:E2:A8:9A:5B:42:99:2C:4C:2C:20
+-----BEGIN CERTIFICATE-----
+MIIFgzCCA2ugAwIBAgIPXZONMGc2yAYdGsdUhGkHMA0GCSqGSIb3DQEBCwUAMDsx
+CzAJBgNVBAYTAkVTMREwDwYDVQQKDAhGTk1ULVJDTTEZMBcGA1UECwwQQUMgUkFJ
+WiBGTk1ULVJDTTAeFw0wODEwMjkxNTU5NTZaFw0zMDAxMDEwMDAwMDBaMDsxCzAJ
+BgNVBAYTAkVTMREwDwYDVQQKDAhGTk1ULVJDTTEZMBcGA1UECwwQQUMgUkFJWiBG
+Tk1ULVJDTTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBALpxgHpMhm5/
+yBNtwMZ9HACXjywMI7sQmkCpGreHiPibVmr75nuOi5KOpyVdWRHbNi63URcfqQgf
+BBckWKo3Shjf5TnUV/3XwSyRAZHiItQDwFj8d0fsjz50Q7qsNI1NOHZnjrDIbzAz
+WHFctPVrbtQBULgTfmxKo0nRIBnuvMApGGWn3v7v3QqQIecaZ5JCEJhfTzC8PhxF
+tBDXaEAUwED653cXeuYLj2VbPNmaUtu1vZ5Gzz3rkQUCwJaydkxNEJY7kvqcfw+Z
+374jNUUeAlz+taibmSXaXvMiwzn15Cou08YfxGyqxRxqAQVKL9LFwag0Jl1mpdIC
+IfkYtwb1TplvqKtMUejPUBjFd8g5CSxJkjKZqLsXF3mwWsXmo8RZZUc1g16p6DUL
+mbvkzSDGm0oGObVo/CK67lWMK07q87Hj/LaZmtVC+nFNCM+HHmpxffnTtOmlcYF7
+wk5HlqX2doWjKI/pgG6BU6VtX7hI+cL5NqYuSf+4lsKMB7ObiFj86xsc3i1w4peS
+MKGJ47xVqCfWS+2QrYv6YyVZLag13cqXM7zlzced0ezvXg5KkAYmY6252TUtB7p2
+ZSysV4999AeU14ECll2jB0nVetBX+RvnU0Z1qrB5QstocQjpYL05ac70r8NWQMet
+UqIJ5G+GR4of6ygnXYMgrwTJbFaai0b1AgMBAAGjgYMwgYAwDwYDVR0TAQH/BAUw
+AwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFPd9xf3E6Jobd2Sn9R2gzL+H
+YJptMD4GA1UdIAQ3MDUwMwYEVR0gADArMCkGCCsGAQUFBwIBFh1odHRwOi8vd3d3
+LmNlcnQuZm5tdC5lcy9kcGNzLzANBgkqhkiG9w0BAQsFAAOCAgEAB5BK3/MjTvDD
+nFFlm5wioooMhfNzKWtN/gHiqQxjAb8EZ6WdmF/9ARP67Jpi6Yb+tmLSbkyU+8B1
+RXxlDPiyN8+sD8+Nb/kZ94/sHvJwnvDKuO+3/3Y3dlv2bojzr2IyIpMNOmqOFGYM
+LVN0V2Ue1bLdI4E7pWYjJ2cJj+F3qkPNZVEI7VFY/uY5+ctHhKQV8Xa7pO6kO8Rf
+77IzlhEYt8llvhjho6Tc+hj507wTmzl6NLrTQfv6MooqtyuGC2mDOL7Nii4LcK2N
+JpLuHvUBKwrZ1pebbuCoGRw6IYsMHkCtA+fdZn71uSANA+iW+YJF1DngoABd15jm
+fZ5nc8OaKveri6E6FO80vFIOiZiaBECEHX5FaZNXzuvO+FB8TxxuBEOb+dY7Ixjp
+6o7RTUaN8Tvkasq6+yO3m/qZASlaWFot4/nUbQ4mrcFuNLwy+AwF+mWj2zs3gyLp
+1txyM/1d8iC9djwj2ij3+RvrWWTV3F9yfiD8zYm1kGdNYno/Tq0dwzn+evQoFt9B
+9kiABdcPUXmsEKvU7ANm5mqwujGSQkBqvjrTcuFqN1W8rB2Vt2lh8kORdOag0wok
+RqEIr9baRRmW1FMdW4R58MD3R++Lj8UGrp1MYp3/RgT408m2ECVAdf4WqslKYIYv
+uu8wd+RU4riEmViAqhOLUTpPSPaLtrM=
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem (from r353095, head/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/Actalis_Authentication_Root_CA.pem)
@@ -0,0 +1,136 @@
+##
+##  Actalis Authentication Root CA
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 6271844772424770508 (0x570a119742c4e3cc)
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = IT, L = Milan, O = Actalis S.p.A./03358520967, CN = Actalis Authentication Root CA
+        Validity
+            Not Before: Sep 22 11:22:02 2011 GMT
+            Not After : Sep 22 11:22:02 2030 GMT
+        Subject: C = IT, L = Milan, O = Actalis S.p.A./03358520967, CN = Actalis Authentication Root CA
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:a7:c6:c4:a5:29:a4:2c:ef:e5:18:c5:b0:50:a3:
+                    6f:51:3b:9f:0a:5a:c9:c2:48:38:0a:c2:1c:a0:18:
+                    7f:91:b5:87:b9:40:3f:dd:1d:68:1f:08:83:d5:2d:
+                    1e:88:a0:f8:8f:56:8f:6d:99:02:92:90:16:d5:5f:
+                    08:6c:89:d7:e1:ac:bc:20:c2:b1:e0:83:51:8a:69:
+                    4d:00:96:5a:6f:2f:c0:44:7e:a3:0e:e4:91:cd:58:
+                    ee:dc:fb:c7:1e:45:47:dd:27:b9:08:01:9f:a6:21:
+                    1d:f5:41:2d:2f:4c:fd:28:ad:e0:8a:ad:22:b4:56:
+                    65:8e:86:54:8f:93:43:29:de:39:46:78:a3:30:23:
+                    ba:cd:f0:7d:13:57:c0:5d:d2:83:6b:48:4c:c4:ab:
+                    9f:80:5a:5b:3a:bd:c9:a7:22:3f:80:27:33:5b:0e:
+                    b7:8a:0c:5d:07:37:08:cb:6c:d2:7a:47:22:44:35:
+                    c5:cc:cc:2e:8e:dd:2a:ed:b7:7d:66:0d:5f:61:51:
+                    22:55:1b:e3:46:e3:e3:3d:d0:35:62:9a:db:af:14:
+                    c8:5b:a1:cc:89:1b:e1:30:26:fc:a0:9b:1f:81:a7:
+                    47:1f:04:eb:a3:39:92:06:9f:99:d3:bf:d3:ea:4f:
+                    50:9c:19:fe:96:87:1e:3c:65:f6:a3:18:24:83:86:
+                    10:e7:54:3e:a8:3a:76:24:4f:81:21:c5:e3:0f:02:
+                    f8:93:94:47:20:bb:fe:d4:0e:d3:68:b9:dd:c4:7a:
+                    84:82:e3:53:54:79:dd:db:9c:d2:f2:07:9b:2e:b6:
+                    bc:3e:ed:85:6d:ef:25:11:f2:97:1a:42:61:f7:4a:
+                    97:e8:8b:b1:10:07:fa:65:81:b2:a2:39:cf:f7:3c:
+                    ff:18:fb:c6:f1:5a:8b:59:e2:02:ac:7b:92:d0:4e:
+                    14:4f:59:45:f6:0c:5e:28:5f:b0:e8:3f:45:cf:cf:
+                    af:9b:6f:fb:84:d3:77:5a:95:6f:ac:94:84:9e:ee:
+                    bc:c0:4a:8f:4a:93:f8:44:21:e2:31:45:61:50:4e:
+                    10:d8:e3:35:7c:4c:19:b4:de:05:bf:a3:06:9f:c8:
+                    b5:cd:e4:1f:d7:17:06:0d:7a:95:74:55:0d:68:1a:
+                    fc:10:1b:62:64:9d:6d:e0:95:a0:c3:94:07:57:0d:
+                    14:e6:bd:05:fb:b8:9f:e6:df:8b:e2:c6:e7:7e:96:
+                    f6:53:c5:80:34:50:28:58:f0:12:50:71:17:30:ba:
+                    e6:78:63:bc:f4:b2:ad:9b:2b:b2:fe:e1:39:8c:5e:
+                    ba:0b:20:94:de:7b:83:b8:ff:e3:56:8d:b7:11:e9:
+                    3b:8c:f2:b1:c1:5d:9d:a4:0b:4c:2b:d9:b2:18:f5:
+                    b5:9f:4b
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Authority Key Identifier: 
+                keyid:52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
+
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: sha256WithRSAEncryption
+         0b:7b:72:87:c0:60:a6:49:4c:88:58:e6:1d:88:f7:14:64:48:
+         a6:d8:58:0a:0e:4f:13:35:df:35:1d:d4:ed:06:31:c8:81:3e:
+         6a:d5:dd:3b:1a:32:ee:90:3d:11:d2:2e:f4:8e:c3:63:2e:23:
+         66:b0:67:be:6f:b6:c0:13:39:60:aa:a2:34:25:93:75:52:de:
+         a7:9d:ad:0e:87:89:52:71:6a:16:3c:19:1d:83:f8:9a:29:65:
+         be:f4:3f:9a:d9:f0:f3:5a:87:21:71:80:4d:cb:e0:38:9b:3f:
+         bb:fa:e0:30:4d:cf:86:d3:65:10:19:18:d1:97:02:b1:2b:72:
+         42:68:ac:a0:bd:4e:5a:da:18:bf:6b:98:81:d0:fd:9a:be:5e:
+         15:48:cd:11:15:b9:c0:29:5c:b4:e8:88:f7:3e:36:ae:b7:62:
+         fd:1e:62:de:70:78:10:1c:48:5b:da:bc:a4:38:ba:67:ed:55:
+         3e:5e:57:df:d4:03:40:4c:81:a4:d2:4f:63:a7:09:42:09:14:
+         fc:00:a9:c2:80:73:4f:2e:c0:40:d9:11:7b:48:ea:7a:02:c0:
+         d3:eb:28:01:26:58:74:c1:c0:73:22:6d:93:95:fd:39:7d:bb:
+         2a:e3:f6:82:e3:2c:97:5f:4e:1f:91:94:fa:fe:2c:a3:d8:76:
+         1a:b8:4d:b2:38:4f:9b:fa:1d:48:60:79:26:e2:f3:fd:a9:d0:
+         9a:e8:70:8f:49:7a:d6:e5:bd:0a:0e:db:2d:f3:8d:bf:eb:e3:
+         a4:7d:cb:c7:95:71:e8:da:a3:7c:c5:c2:f8:74:92:04:1b:86:
+         ac:a4:22:53:40:b6:ac:fe:4c:76:cf:fb:94:32:c0:35:9f:76:
+         3f:6e:e5:90:6e:a0:a6:26:a2:b8:2c:be:d1:2b:85:fd:a7:68:
+         c8:ba:01:2b:b1:6c:74:1d:b8:73:95:e7:ee:b7:c7:25:f0:00:
+         4c:00:b2:7e:b6:0b:8b:1c:f3:c0:50:9e:25:b9:e0:08:de:36:
+         66:ff:37:a5:d1:bb:54:64:2c:c9:27:b5:4b:92:7e:65:ff:d3:
+         2d:e1:b9:4e:bc:7f:a4:41:21:90:41:77:a6:39:1f:ea:9e:e3:
+         9f:d0:66:6f:05:ec:aa:76:7e:bf:6b:16:a0:eb:b5:c7:fc:92:
+         54:2f:2b:11:27:25:37:78:4c:51:6a:b0:f3:cc:58:5d:14:f1:
+         6a:48:15:ff:c2:07:b6:b1:8d:0f:8e:5c:50:46:b3:3d:bf:01:
+         98:4f:b2:59:54:47:3e:34:7b:78:6d:56:93:2e:73:ea:66:28:
+         78:cd:1d:14:bf:a0:8f:2f:2e:b8:2e:8e:f2:14:8a:cc:e9:b5:
+         7c:fb:6c:9d:0c:a5:e1:96
+SHA1 Fingerprint=F3:73:B3:87:06:5A:28:84:8A:F2:F3:4A:CE:19:2B:DD:C7:8E:9C:AC
+-----BEGIN CERTIFICATE-----
+MIIFuzCCA6OgAwIBAgIIVwoRl0LE48wwDQYJKoZIhvcNAQELBQAwazELMAkGA1UE
+BhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8w
+MzM1ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290
+IENBMB4XDTExMDkyMjExMjIwMloXDTMwMDkyMjExMjIwMlowazELMAkGA1UEBhMC
+SVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1
+ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290IENB
+MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAp8bEpSmkLO/lGMWwUKNv
+UTufClrJwkg4CsIcoBh/kbWHuUA/3R1oHwiD1S0eiKD4j1aPbZkCkpAW1V8IbInX
+4ay8IMKx4INRimlNAJZaby/ARH6jDuSRzVju3PvHHkVH3Se5CAGfpiEd9UEtL0z9
+KK3giq0itFZljoZUj5NDKd45RnijMCO6zfB9E1fAXdKDa0hMxKufgFpbOr3JpyI/
+gCczWw63igxdBzcIy2zSekciRDXFzMwujt0q7bd9Zg1fYVEiVRvjRuPjPdA1Yprb
+rxTIW6HMiRvhMCb8oJsfgadHHwTrozmSBp+Z07/T6k9QnBn+locePGX2oxgkg4YQ
+51Q+qDp2JE+BIcXjDwL4k5RHILv+1A7TaLndxHqEguNTVHnd25zS8gebLra8Pu2F
+be8lEfKXGkJh90qX6IuxEAf6ZYGyojnP9zz/GPvG8VqLWeICrHuS0E4UT1lF9gxe
+KF+w6D9Fz8+vm2/7hNN3WpVvrJSEnu68wEqPSpP4RCHiMUVhUE4Q2OM1fEwZtN4F
+v6MGn8i1zeQf1xcGDXqVdFUNaBr8EBtiZJ1t4JWgw5QHVw0U5r0F+7if5t+L4sbn
+fpb2U8WANFAoWPASUHEXMLrmeGO89LKtmyuy/uE5jF66CyCU3nuDuP/jVo23Eek7
+jPKxwV2dpAtMK9myGPW1n0sCAwEAAaNjMGEwHQYDVR0OBBYEFFLYiDrIn3hm7Ynz
+ezhwlMkCAjbQMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUUtiIOsifeGbt
+ifN7OHCUyQICNtAwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4ICAQAL
+e3KHwGCmSUyIWOYdiPcUZEim2FgKDk8TNd81HdTtBjHIgT5q1d07GjLukD0R0i70
+jsNjLiNmsGe+b7bAEzlgqqI0JZN1Ut6nna0Oh4lScWoWPBkdg/iaKWW+9D+a2fDz
+WochcYBNy+A4mz+7+uAwTc+G02UQGRjRlwKxK3JCaKygvU5a2hi/a5iB0P2avl4V
+SM0RFbnAKVy06Ij3Pjaut2L9HmLecHgQHEhb2rykOLpn7VU+Xlff1ANATIGk0k9j
+pwlCCRT8AKnCgHNPLsBA2RF7SOp6AsDT6ygBJlh0wcBzIm2Tlf05fbsq4/aC4yyX
+X04fkZT6/iyj2HYauE2yOE+b+h1IYHkm4vP9qdCa6HCPSXrW5b0KDtst842/6+Ok
+fcvHlXHo2qN8xcL4dJIEG4aspCJTQLas/kx2z/uUMsA1n3Y/buWQbqCmJqK4LL7R
+K4X9p2jIugErsWx0Hbhzlefut8cl8ABMALJ+tguLHPPAUJ4lueAI3jZm/zel0btU
+ZCzJJ7VLkn5l/9Mt4blOvH+kQSGQQXemOR/qnuOf0GZvBeyqdn6/axag67XH/JJU
+LysRJyU3eExRarDzzFhdFPFqSBX/wge2sY0PjlxQRrM9vwGYT7JZVEc+NHt4bVaT
+LnPqZih4zR0Uv6CPLy64Lo7yFIrM6bV8+2ydDKXhlg==
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AddTrust_External_Root.pem (from r353095, head/secure/caroot/trusted/AddTrust_External_Root.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AddTrust_External_Root.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AddTrust_External_Root.pem)
@@ -0,0 +1,99 @@
+##
+##  AddTrust External Root
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 1 (0x1)
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C = SE, O = AddTrust AB, OU = AddTrust External TTP Network, CN = AddTrust External CA Root
+        Validity
+            Not Before: May 30 10:48:38 2000 GMT
+            Not After : May 30 10:48:38 2020 GMT
+        Subject: C = SE, O = AddTrust AB, OU = AddTrust External TTP Network, CN = AddTrust External CA Root
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (2048 bit)
+                Modulus:
+                    00:b7:f7:1a:33:e6:f2:00:04:2d:39:e0:4e:5b:ed:
+                    1f:bc:6c:0f:cd:b5:fa:23:b6:ce:de:9b:11:33:97:
+                    a4:29:4c:7d:93:9f:bd:4a:bc:93:ed:03:1a:e3:8f:
+                    cf:e5:6d:50:5a:d6:97:29:94:5a:80:b0:49:7a:db:
+                    2e:95:fd:b8:ca:bf:37:38:2d:1e:3e:91:41:ad:70:
+                    56:c7:f0:4f:3f:e8:32:9e:74:ca:c8:90:54:e9:c6:
+                    5f:0f:78:9d:9a:40:3c:0e:ac:61:aa:5e:14:8f:9e:
+                    87:a1:6a:50:dc:d7:9a:4e:af:05:b3:a6:71:94:9c:
+                    71:b3:50:60:0a:c7:13:9d:38:07:86:02:a8:e9:a8:
+                    69:26:18:90:ab:4c:b0:4f:23:ab:3a:4f:84:d8:df:
+                    ce:9f:e1:69:6f:bb:d7:42:d7:6b:44:e4:c7:ad:ee:
+                    6d:41:5f:72:5a:71:08:37:b3:79:65:a4:59:a0:94:
+                    37:f7:00:2f:0d:c2:92:72:da:d0:38:72:db:14:a8:
+                    45:c4:5d:2a:7d:b7:b4:d6:c4:ee:ac:cd:13:44:b7:
+                    c9:2b:dd:43:00:25:fa:61:b9:69:6a:58:23:11:b7:
+                    a7:33:8f:56:75:59:f5:cd:29:d7:46:b7:0a:2b:65:
+                    b6:d3:42:6f:15:b2:b8:7b:fb:ef:e9:5d:53:d5:34:
+                    5a:27
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A
+            X509v3 Key Usage: 
+                Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Authority Key Identifier: 
+                keyid:AD:BD:98:7A:34:B4:26:F7:FA:C4:26:54:EF:03:BD:E0:24:CB:54:1A
+                DirName:/C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
+                serial:01
+
+    Signature Algorithm: sha1WithRSAEncryption
+         b0:9b:e0:85:25:c2:d6:23:e2:0f:96:06:92:9d:41:98:9c:d9:
+         84:79:81:d9:1e:5b:14:07:23:36:65:8f:b0:d8:77:bb:ac:41:
+         6c:47:60:83:51:b0:f9:32:3d:e7:fc:f6:26:13:c7:80:16:a5:
+         bf:5a:fc:87:cf:78:79:89:21:9a:e2:4c:07:0a:86:35:bc:f2:
+         de:51:c4:d2:96:b7:dc:7e:4e:ee:70:fd:1c:39:eb:0c:02:51:
+         14:2d:8e:bd:16:e0:c1:df:46:75:e7:24:ad:ec:f4:42:b4:85:
+         93:70:10:67:ba:9d:06:35:4a:18:d3:2b:7a:cc:51:42:a1:7a:
+         63:d1:e6:bb:a1:c5:2b:c2:36:be:13:0d:e6:bd:63:7e:79:7b:
+         a7:09:0d:40:ab:6a:dd:8f:8a:c3:f6:f6:8c:1a:42:05:51:d4:
+         45:f5:9f:a7:62:21:68:15:20:43:3c:99:e7:7c:bd:24:d8:a9:
+         91:17:73:88:3f:56:1b:31:38:18:b4:71:0f:9a:cd:c8:0e:9e:
+         8e:2e:1b:e1:8c:98:83:cb:1f:31:f1:44:4c:c6:04:73:49:76:
+         60:0f:c7:f8:bd:17:80:6b:2e:e9:cc:4c:0e:5a:9a:79:0f:20:
+         0a:2e:d5:9e:63:26:1e:55:92:94:d8:82:17:5a:7b:d0:bc:c7:
+         8f:4e:86:04
+SHA1 Fingerprint=02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68
+-----BEGIN CERTIFICATE-----
+MIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
+MBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFkZFRydXN0IEV4dGVybmFs
+IFRUUCBOZXR3b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBFeHRlcm5hbCBDQSBSb290
+MB4XDTAwMDUzMDEwNDgzOFoXDTIwMDUzMDEwNDgzOFowbzELMAkGA1UEBhMCU0Ux
+FDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
+bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9v
+dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALf3GjPm8gAELTngTlvt
+H7xsD821+iO2zt6bETOXpClMfZOfvUq8k+0DGuOPz+VtUFrWlymUWoCwSXrbLpX9
+uMq/NzgtHj6RQa1wVsfwTz/oMp50ysiQVOnGXw94nZpAPA6sYapeFI+eh6FqUNzX
+mk6vBbOmcZSccbNQYArHE504B4YCqOmoaSYYkKtMsE8jqzpPhNjfzp/haW+710LX
+a0Tkx63ubUFfclpxCDezeWWkWaCUN/cALw3CknLa0Dhy2xSoRcRdKn23tNbE7qzN
+E0S3ySvdQwAl+mG5aWpYIxG3pzOPVnVZ9c0p10a3CitlttNCbxWyuHv77+ldU9U0
+WicCAwEAAaOB3DCB2TAdBgNVHQ4EFgQUrb2YejS0Jvf6xCZU7wO94CTLVBowCwYD
+VR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wgZkGA1UdIwSBkTCBjoAUrb2YejS0
+Jvf6xCZU7wO94CTLVBqhc6RxMG8xCzAJBgNVBAYTAlNFMRQwEgYDVQQKEwtBZGRU
+cnVzdCBBQjEmMCQGA1UECxMdQWRkVHJ1c3QgRXh0ZXJuYWwgVFRQIE5ldHdvcmsx
+IjAgBgNVBAMTGUFkZFRydXN0IEV4dGVybmFsIENBIFJvb3SCAQEwDQYJKoZIhvcN
+AQEFBQADggEBALCb4IUlwtYj4g+WBpKdQZic2YR5gdkeWxQHIzZlj7DYd7usQWxH
+YINRsPkyPef89iYTx4AWpb9a/IfPeHmJIZriTAcKhjW88t5RxNKWt9x+Tu5w/Rw5
+6wwCURQtjr0W4MHfRnXnJK3s9EK0hZNwEGe6nQY1ShjTK3rMUUKhemPR5ruhxSvC
+Nr4TDea9Y355e6cJDUCrat2PisP29owaQgVR1EX1n6diIWgVIEM8med8vSTYqZEX
+c4g/VhsxOBi0cQ+azcgOno4uG+GMmIPLHzHxREzGBHNJdmAPx/i9F4BrLunMTA5a
+mnkPIAou1Z5jJh5VkpTYghdae9C8x49OhgQ=
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem (from r353095, head/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AddTrust_Low-Value_Services_Root.pem)
@@ -0,0 +1,98 @@
+##
+##  AddTrust Low-Value Services Root
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 1 (0x1)
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C = SE, O = AddTrust AB, OU = AddTrust TTP Network, CN = AddTrust Class 1 CA Root
+        Validity
+            Not Before: May 30 10:38:31 2000 GMT
+            Not After : May 30 10:38:31 2020 GMT
+        Subject: C = SE, O = AddTrust AB, OU = AddTrust TTP Network, CN = AddTrust Class 1 CA Root
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (2048 bit)
+                Modulus:
+                    00:96:96:d4:21:49:60:e2:6b:e8:41:07:0c:de:c4:
+                    e0:dc:13:23:cd:c1:35:c7:fb:d6:4e:11:0a:67:5e:
+                    f5:06:5b:6b:a5:08:3b:5b:29:16:3a:e7:87:b2:34:
+                    06:c5:bc:05:a5:03:7c:82:cb:29:10:ae:e1:88:81:
+                    bd:d6:9e:d3:fe:2d:56:c1:15:ce:e3:26:9d:15:2e:
+                    10:fb:06:8f:30:04:de:a7:b4:63:b4:ff:b1:9c:ae:
+                    3c:af:77:b6:56:c5:b5:ab:a2:e9:69:3a:3d:0e:33:
+                    79:32:3f:70:82:92:99:61:6d:8d:30:08:8f:71:3f:
+                    a6:48:57:19:f8:25:dc:4b:66:5c:a5:74:8f:98:ae:
+                    c8:f9:c0:06:22:e7:ac:73:df:a5:2e:fb:52:dc:b1:
+                    15:65:20:fa:35:66:69:de:df:2c:f1:6e:bc:30:db:
+                    2c:24:12:db:eb:35:35:68:90:cb:00:b0:97:21:3d:
+                    74:21:23:65:34:2b:bb:78:59:a3:d6:e1:76:39:9a:
+                    a4:49:8e:8c:74:af:6e:a4:9a:a3:d9:9b:d2:38:5c:
+                    9b:a2:18:cc:75:23:84:be:eb:e2:4d:33:71:8e:1a:
+                    f0:c2:f8:c7:1d:a2:ad:03:97:2c:f8:cf:25:c6:f6:
+                    b8:24:31:b1:63:5d:92:7f:63:f0:25:c9:53:2e:1f:
+                    bf:4d
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                95:B1:B4:F0:94:B6:BD:C7:DA:D1:11:09:21:BE:C1:AF:49:FD:10:7B
+            X509v3 Key Usage: 
+                Certificate Sign, CRL Sign
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Authority Key Identifier: 
+                keyid:95:B1:B4:F0:94:B6:BD:C7:DA:D1:11:09:21:BE:C1:AF:49:FD:10:7B
+                DirName:/C=SE/O=AddTrust AB/OU=AddTrust TTP Network/CN=AddTrust Class 1 CA Root
+                serial:01
+
+    Signature Algorithm: sha1WithRSAEncryption
+         2c:6d:64:1b:1f:cd:0d:dd:b9:01:fa:96:63:34:32:48:47:99:
+         ae:97:ed:fd:72:16:a6:73:47:5a:f4:eb:dd:e9:f5:d6:fb:45:
+         cc:29:89:44:5d:bf:46:39:3d:e8:ee:bc:4d:54:86:1e:1d:6c:
+         e3:17:27:43:e1:89:56:2b:a9:6f:72:4e:49:33:e3:72:7c:2a:
+         23:9a:bc:3e:ff:28:2a:ed:a3:ff:1c:23:ba:43:57:09:67:4d:
+         4b:62:06:2d:f8:ff:6c:9d:60:1e:d8:1c:4b:7d:b5:31:2f:d9:
+         d0:7c:5d:f8:de:6b:83:18:78:37:57:2f:e8:33:07:67:df:1e:
+         c7:6b:2a:95:76:ae:8f:57:a3:f0:f4:52:b4:a9:53:08:cf:e0:
+         4f:d3:7a:53:8b:fd:bb:1c:56:36:f2:fe:b2:b6:e5:76:bb:d5:
+         22:65:a7:3f:fe:d1:66:ad:0b:bc:6b:99:86:ef:3f:7d:f3:18:
+         32:ca:7b:c6:e3:ab:64:46:95:f8:26:69:d9:55:83:7b:2c:96:
+         07:ff:59:2c:44:a3:c6:e5:e9:a9:dc:a1:63:80:5a:21:5e:21:
+         cf:53:54:f0:ba:6f:89:db:a8:aa:95:cf:8b:e3:71:cc:1e:1b:
+         20:44:08:c0:7a:b6:40:fd:c4:e4:35:e1:1d:16:1c:d0:bc:2b:
+         8e:d6:71:d9
+SHA1 Fingerprint=CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D
+-----BEGIN CERTIFICATE-----
+MIIEGDCCAwCgAwIBAgIBATANBgkqhkiG9w0BAQUFADBlMQswCQYDVQQGEwJTRTEU
+MBIGA1UEChMLQWRkVHJ1c3QgQUIxHTAbBgNVBAsTFEFkZFRydXN0IFRUUCBOZXR3
+b3JrMSEwHwYDVQQDExhBZGRUcnVzdCBDbGFzcyAxIENBIFJvb3QwHhcNMDAwNTMw
+MTAzODMxWhcNMjAwNTMwMTAzODMxWjBlMQswCQYDVQQGEwJTRTEUMBIGA1UEChML
+QWRkVHJ1c3QgQUIxHTAbBgNVBAsTFEFkZFRydXN0IFRUUCBOZXR3b3JrMSEwHwYD
+VQQDExhBZGRUcnVzdCBDbGFzcyAxIENBIFJvb3QwggEiMA0GCSqGSIb3DQEBAQUA
+A4IBDwAwggEKAoIBAQCWltQhSWDia+hBBwzexODcEyPNwTXH+9ZOEQpnXvUGW2ul
+CDtbKRY654eyNAbFvAWlA3yCyykQruGIgb3WntP+LVbBFc7jJp0VLhD7Bo8wBN6n
+tGO0/7Gcrjyvd7ZWxbWroulpOj0OM3kyP3CCkplhbY0wCI9xP6ZIVxn4JdxLZlyl
+dI+Yrsj5wAYi56xz36Uu+1LcsRVlIPo1Zmne3yzxbrww2ywkEtvrNTVokMsAsJch
+PXQhI2U0K7t4WaPW4XY5mqRJjox0r26kmqPZm9I4XJuiGMx1I4S+6+JNM3GOGvDC
++Mcdoq0Dlyz4zyXG9rgkMbFjXZJ/Y/AlyVMuH79NAgMBAAGjgdIwgc8wHQYDVR0O
+BBYEFJWxtPCUtr3H2tERCSG+wa9J/RB7MAsGA1UdDwQEAwIBBjAPBgNVHRMBAf8E
+BTADAQH/MIGPBgNVHSMEgYcwgYSAFJWxtPCUtr3H2tERCSG+wa9J/RB7oWmkZzBl
+MQswCQYDVQQGEwJTRTEUMBIGA1UEChMLQWRkVHJ1c3QgQUIxHTAbBgNVBAsTFEFk
+ZFRydXN0IFRUUCBOZXR3b3JrMSEwHwYDVQQDExhBZGRUcnVzdCBDbGFzcyAxIENB
+IFJvb3SCAQEwDQYJKoZIhvcNAQEFBQADggEBACxtZBsfzQ3duQH6lmM0MkhHma6X
+7f1yFqZzR1r0693p9db7RcwpiURdv0Y5PejuvE1Uhh4dbOMXJ0PhiVYrqW9yTkkz
+43J8KiOavD7/KCrto/8cI7pDVwlnTUtiBi34/2ydYB7YHEt9tTEv2dB8Xfjea4MY
+eDdXL+gzB2ffHsdrKpV2ro9Xo/D0UrSpUwjP4E/TelOL/bscVjby/rK25Xa71SJl
+pz/+0WatC7xrmYbvP33zGDLKe8bjq2RGlfgmadlVg3sslgf/WSxEo8bl6ancoWOA
+WiFeIc9TVPC6b4nbqKqVz4vjccweGyBECMB6tkD9xOQ14R0WHNC8K47Wcdk=
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AffirmTrust_Commercial.pem (from r353095, head/secure/caroot/trusted/AffirmTrust_Commercial.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AffirmTrust_Commercial.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AffirmTrust_Commercial.pem)
@@ -0,0 +1,89 @@
+##
+##  AffirmTrust Commercial
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 8608355977964138876 (0x7777062726a9b17c)
+        Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C = US, O = AffirmTrust, CN = AffirmTrust Commercial
+        Validity
+            Not Before: Jan 29 14:06:06 2010 GMT
+            Not After : Dec 31 14:06:06 2030 GMT
+        Subject: C = US, O = AffirmTrust, CN = AffirmTrust Commercial
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (2048 bit)
+                Modulus:
+                    00:f6:1b:4f:67:07:2b:a1:15:f5:06:22:cb:1f:01:
+                    b2:e3:73:45:06:44:49:2c:bb:49:25:14:d6:ce:c3:
+                    b7:ab:2c:4f:c6:41:32:94:57:fa:12:a7:5b:0e:e2:
+                    8f:1f:1e:86:19:a7:aa:b5:2d:b9:5f:0d:8a:c2:af:
+                    85:35:79:32:2d:bb:1c:62:37:f2:b1:5b:4a:3d:ca:
+                    cd:71:5f:e9:42:be:94:e8:c8:de:f9:22:48:64:c6:
+                    e5:ab:c6:2b:6d:ad:05:f0:fa:d5:0b:cf:9a:e5:f0:
+                    50:a4:8b:3b:47:a5:23:5b:7a:7a:f8:33:3f:b8:ef:
+                    99:97:e3:20:c1:d6:28:89:cf:94:fb:b9:45:ed:e3:
+                    40:17:11:d4:74:f0:0b:31:e2:2b:26:6a:9b:4c:57:
+                    ae:ac:20:3e:ba:45:7a:05:f3:bd:9b:69:15:ae:7d:
+                    4e:20:63:c4:35:76:3a:07:02:c9:37:fd:c7:47:ee:
+                    e8:f1:76:1d:73:15:f2:97:a4:b5:c8:7a:79:d9:42:
+                    aa:2b:7f:5c:fe:ce:26:4f:a3:66:81:35:af:44:ba:
+                    54:1e:1c:30:32:65:9d:e6:3c:93:5e:50:4e:7a:e3:
+                    3a:d4:6e:cc:1a:fb:f9:d2:37:ae:24:2a:ab:57:03:
+                    22:28:0d:49:75:7f:b7:28:da:75:bf:8e:e3:dc:0e:
+                    79:31
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                9D:93:C6:53:8B:5E:CA:AF:3F:9F:1E:0F:E5:99:95:BC:24:F6:94:8F
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: sha256WithRSAEncryption
+         58:ac:f4:04:0e:cd:c0:0d:ff:0a:fd:d4:ba:16:5f:29:bd:7b:
+         68:99:58:49:d2:b4:1d:37:4d:7f:27:7d:46:06:5d:43:c6:86:
+         2e:3e:73:b2:26:7d:4f:93:a9:b6:c4:2a:9a:ab:21:97:14:b1:
+         de:8c:d3:ab:89:15:d8:6b:24:d4:f1:16:ae:d8:a4:5c:d4:7f:
+         51:8e:ed:18:01:b1:93:63:bd:bc:f8:61:80:9a:9e:b1:ce:42:
+         70:e2:a9:7d:06:25:7d:27:a1:fe:6f:ec:b3:1e:24:da:e3:4b:
+         55:1a:00:3b:35:b4:3b:d9:d7:5d:30:fd:81:13:89:f2:c2:06:
+         2b:ed:67:c4:8e:c9:43:b2:5c:6b:15:89:02:bc:62:fc:4e:f2:
+         b5:33:aa:b2:6f:d3:0a:a2:50:e3:f6:3b:e8:2e:44:c2:db:66:
+         38:a9:33:56:48:f1:6d:1b:33:8d:0d:8c:3f:60:37:9d:d3:ca:
+         6d:7e:34:7e:0d:9f:72:76:8b:1b:9f:72:fd:52:35:41:45:02:
+         96:2f:1c:b2:9a:73:49:21:b1:49:47:45:47:b4:ef:6a:34:11:
+         c9:4d:9a:cc:59:b7:d6:02:9e:5a:4e:65:b5:94:ae:1b:df:29:
+         b0:16:f1:bf:00:9e:07:3a:17:64:b5:04:b5:23:21:99:0a:95:
+         3b:97:7c:ef
+SHA1 Fingerprint=F9:B5:B6:32:45:5F:9C:BE:EC:57:5F:80:DC:E9:6E:2C:C7:B2:78:B7
+-----BEGIN CERTIFICATE-----
+MIIDTDCCAjSgAwIBAgIId3cGJyapsXwwDQYJKoZIhvcNAQELBQAwRDELMAkGA1UE
+BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZpcm1UcnVz
+dCBDb21tZXJjaWFsMB4XDTEwMDEyOTE0MDYwNloXDTMwMTIzMTE0MDYwNlowRDEL
+MAkGA1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZp
+cm1UcnVzdCBDb21tZXJjaWFsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
+AQEA9htPZwcroRX1BiLLHwGy43NFBkRJLLtJJRTWzsO3qyxPxkEylFf6EqdbDuKP
+Hx6GGaeqtS25Xw2Kwq+FNXkyLbscYjfysVtKPcrNcV/pQr6U6Mje+SJIZMblq8Yr
+ba0F8PrVC8+a5fBQpIs7R6UjW3p6+DM/uO+Zl+MgwdYoic+U+7lF7eNAFxHUdPAL
+MeIrJmqbTFeurCA+ukV6BfO9m2kVrn1OIGPENXY6BwLJN/3HR+7o8XYdcxXyl6S1
+yHp52UKqK39c/s4mT6NmgTWvRLpUHhwwMmWd5jyTXlBOeuM61G7MGvv50jeuJCqr
+VwMiKA1JdX+3KNp1v47j3A55MQIDAQABo0IwQDAdBgNVHQ4EFgQUnZPGU4teyq8/
+nx4P5ZmVvCT2lI8wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwDQYJ
+KoZIhvcNAQELBQADggEBAFis9AQOzcAN/wr91LoWXym9e2iZWEnStB03TX8nfUYG
+XUPGhi4+c7ImfU+TqbbEKpqrIZcUsd6M06uJFdhrJNTxFq7YpFzUf1GO7RgBsZNj
+vbz4YYCanrHOQnDiqX0GJX0nof5v7LMeJNrjS1UaADs1tDvZ110w/YETifLCBivt
+Z8SOyUOyXGsViQK8YvxO8rUzqrJv0wqiUOP2O+guRMLbZjipM1ZI8W0bM40NjD9g
+N53Tym1+NH4Nn3J2ixufcv1SNUFFApYvHLKac0khsUlHRUe072o0EclNmsxZt9YC
+nlpOZbWUrhvfKbAW8b8Angc6F2S1BLUjIZkKlTuXfO8=
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AffirmTrust_Networking.pem (from r353095, head/secure/caroot/trusted/AffirmTrust_Networking.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AffirmTrust_Networking.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AffirmTrust_Networking.pem)
@@ -0,0 +1,89 @@
+##
+##  AffirmTrust Networking
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 8957382827206547757 (0x7c4f04391cd4992d)
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C = US, O = AffirmTrust, CN = AffirmTrust Networking
+        Validity
+            Not Before: Jan 29 14:08:24 2010 GMT
+            Not After : Dec 31 14:08:24 2030 GMT
+        Subject: C = US, O = AffirmTrust, CN = AffirmTrust Networking
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (2048 bit)
+                Modulus:
+                    00:b4:84:cc:33:17:2e:6b:94:6c:6b:61:52:a0:eb:
+                    a3:cf:79:94:4c:e5:94:80:99:cb:55:64:44:65:8f:
+                    67:64:e2:06:e3:5c:37:49:f6:2f:9b:84:84:1e:2d:
+                    f2:60:9d:30:4e:cc:84:85:e2:2c:cf:1e:9e:fe:36:
+                    ab:33:77:35:44:d8:35:96:1a:3d:36:e8:7a:0e:d8:
+                    d5:47:a1:6a:69:8b:d9:fc:bb:3a:ae:79:5a:d5:f4:
+                    d6:71:bb:9a:90:23:6b:9a:b7:88:74:87:0c:1e:5f:
+                    b9:9e:2d:fa:ab:53:2b:dc:bb:76:3e:93:4c:08:08:
+                    8c:1e:a2:23:1c:d4:6a:ad:22:ba:99:01:2e:6d:65:
+                    cb:be:24:66:55:24:4b:40:44:b1:1b:d7:e1:c2:85:
+                    c0:de:10:3f:3d:ed:b8:fc:f1:f1:23:53:dc:bf:65:
+                    97:6f:d9:f9:40:71:8d:7d:bd:95:d4:ce:be:a0:5e:
+                    27:23:de:fd:a6:d0:26:0e:00:29:eb:3c:46:f0:3d:
+                    60:bf:3f:50:d2:dc:26:41:51:9e:14:37:42:04:a3:
+                    70:57:a8:1b:87:ed:2d:fa:7b:ee:8c:0a:e3:a9:66:
+                    89:19:cb:41:f9:dd:44:36:61:cf:e2:77:46:c8:7d:
+                    f6:f4:92:81:36:fd:db:34:f1:72:7e:f3:0c:16:bd:
+                    b4:15
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                07:1F:D2:E7:9C:DA:C2:6E:A2:40:B4:B0:7A:50:10:50:74:C4:C8:BD
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: sha1WithRSAEncryption
+         89:57:b2:16:7a:a8:c2:fd:d6:d9:9b:9b:34:c2:9c:b4:32:14:
+         4d:a7:a4:df:ec:be:a7:be:f8:43:db:91:37:ce:b4:32:2e:50:
+         55:1a:35:4e:76:43:71:20:ef:93:77:4e:15:70:2e:87:c3:c1:
+         1d:6d:dc:cb:b5:27:d4:2c:56:d1:52:53:3a:44:d2:73:c8:c4:
+         1b:05:65:5a:62:92:9c:ee:41:8d:31:db:e7:34:ea:59:21:d5:
+         01:7a:d7:64:b8:64:39:cd:c9:ed:af:ed:4b:03:48:a7:a0:99:
+         01:80:dc:65:a3:36:ae:65:59:48:4f:82:4b:c8:65:f1:57:1d:
+         e5:59:2e:0a:3f:6c:d8:d1:f5:e5:09:b4:6c:54:00:0a:e0:15:
+         4d:87:75:6d:b7:58:96:5a:dd:6d:d2:00:a0:f4:9b:48:be:c3:
+         37:a4:ba:36:e0:7c:87:85:97:1a:15:a2:de:2e:a2:5b:bd:af:
+         18:f9:90:50:cd:70:59:f8:27:67:47:cb:c7:a0:07:3a:7d:d1:
+         2c:5d:6c:19:3a:66:b5:7d:fd:91:6f:82:b1:be:08:93:db:14:
+         47:f1:a2:37:c7:45:9e:3c:c7:77:af:64:a8:93:df:f6:69:83:
+         82:60:f2:49:42:34:ed:5a:00:54:85:1c:16:36:92:0c:5c:fa:
+         a6:ad:bf:db
+SHA1 Fingerprint=29:36:21:02:8B:20:ED:02:F5:66:C5:32:D1:D6:ED:90:9F:45:00:2F
+-----BEGIN CERTIFICATE-----
+MIIDTDCCAjSgAwIBAgIIfE8EORzUmS0wDQYJKoZIhvcNAQEFBQAwRDELMAkGA1UE
+BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZpcm1UcnVz
+dCBOZXR3b3JraW5nMB4XDTEwMDEyOTE0MDgyNFoXDTMwMTIzMTE0MDgyNFowRDEL
+MAkGA1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MR8wHQYDVQQDDBZBZmZp
+cm1UcnVzdCBOZXR3b3JraW5nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
+AQEAtITMMxcua5Rsa2FSoOujz3mUTOWUgJnLVWREZY9nZOIG41w3SfYvm4SEHi3y
+YJ0wTsyEheIszx6e/jarM3c1RNg1lho9Nuh6DtjVR6FqaYvZ/Ls6rnla1fTWcbua
+kCNrmreIdIcMHl+5ni36q1Mr3Lt2PpNMCAiMHqIjHNRqrSK6mQEubWXLviRmVSRL
+QESxG9fhwoXA3hA/Pe24/PHxI1Pcv2WXb9n5QHGNfb2V1M6+oF4nI979ptAmDgAp
+6zxG8D1gvz9Q0twmQVGeFDdCBKNwV6gbh+0t+nvujArjqWaJGctB+d1ENmHP4ndG
+yH329JKBNv3bNPFyfvMMFr20FQIDAQABo0IwQDAdBgNVHQ4EFgQUBx/S55zawm6i
+QLSwelAQUHTEyL0wDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwDQYJ
+KoZIhvcNAQEFBQADggEBAIlXshZ6qML91tmbmzTCnLQyFE2npN/svqe++EPbkTfO
+tDIuUFUaNU52Q3Eg75N3ThVwLofDwR1t3Mu1J9QsVtFSUzpE0nPIxBsFZVpikpzu
+QY0x2+c06lkh1QF612S4ZDnNye2v7UsDSKegmQGA3GWjNq5lWUhPgkvIZfFXHeVZ
+Lgo/bNjR9eUJtGxUAArgFU2HdW23WJZa3W3SAKD0m0i+wzekujbgfIeFlxoVot4u
+olu9rxj5kFDNcFn4J2dHy8egBzp90SxdbBk6ZrV9/ZFvgrG+CJPbFEfxojfHRZ48
+x3evZKiT3/Zpg4Jg8klCNO1aAFSFHBY2kgxc+qatv9s=
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AffirmTrust_Premium.pem (from r353095, head/secure/caroot/trusted/AffirmTrust_Premium.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AffirmTrust_Premium.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AffirmTrust_Premium.pem)
@@ -0,0 +1,131 @@
+##
+##  AffirmTrust Premium
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 7893706540734352110 (0x6d8c1446b1a60aee)
+        Signature Algorithm: sha384WithRSAEncryption
+        Issuer: C = US, O = AffirmTrust, CN = AffirmTrust Premium
+        Validity
+            Not Before: Jan 29 14:10:36 2010 GMT
+            Not After : Dec 31 14:10:36 2040 GMT
+        Subject: C = US, O = AffirmTrust, CN = AffirmTrust Premium
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:c4:12:df:a9:5f:fe:41:dd:dd:f5:9f:8a:e3:f6:
+                    ac:e1:3c:78:9a:bc:d8:f0:7f:7a:a0:33:2a:dc:8d:
+                    20:5b:ae:2d:6f:e7:93:d9:36:70:6a:68:cf:8e:51:
+                    a3:85:5b:67:04:a0:10:24:6f:5d:28:82:c1:97:57:
+                    d8:48:29:13:b6:e1:be:91:4d:df:85:0c:53:18:9a:
+                    1e:24:a2:4f:8f:f0:a2:85:0b:cb:f4:29:7f:d2:a4:
+                    58:ee:26:4d:c9:aa:a8:7b:9a:d9:fa:38:de:44:57:
+                    15:e5:f8:8c:c8:d9:48:e2:0d:16:27:1d:1e:c8:83:
+                    85:25:b7:ba:aa:55:41:cc:03:22:4b:2d:91:8d:8b:
+                    e6:89:af:66:c7:e9:ff:2b:e9:3c:ac:da:d2:b3:c3:
+                    e1:68:9c:89:f8:7a:00:56:de:f4:55:95:6c:fb:ba:
+                    64:dd:62:8b:df:0b:77:32:eb:62:cc:26:9a:9b:bb:
+                    aa:62:83:4c:b4:06:7a:30:c8:29:bf:ed:06:4d:97:
+                    b9:1c:c4:31:2b:d5:5f:bc:53:12:17:9c:99:57:29:
+                    66:77:61:21:31:07:2e:25:49:9d:18:f2:ee:f3:2b:
+                    71:8c:b5:ba:39:07:49:77:fc:ef:2e:92:90:05:8d:
+                    2d:2f:77:7b:ef:43:bf:35:bb:9a:d8:f9:73:a7:2c:
+                    f2:d0:57:ee:28:4e:26:5f:8f:90:68:09:2f:b8:f8:
+                    dc:06:e9:2e:9a:3e:51:a7:d1:22:c4:0a:a7:38:48:
+                    6c:b3:f9:ff:7d:ab:86:57:e3:ba:d6:85:78:77:ba:
+                    43:ea:48:7f:f6:d8:be:23:6d:1e:bf:d1:36:6c:58:
+                    5c:f1:ee:a4:19:54:1a:f5:03:d2:76:e6:e1:8c:bd:
+                    3c:b3:d3:48:4b:e2:c8:f8:7f:92:a8:76:46:9c:42:
+                    65:3e:a4:1e:c1:07:03:5a:46:2d:b8:97:f3:b7:d5:
+                    b2:55:21:ef:ba:dc:4c:00:97:fb:14:95:27:33:bf:
+                    e8:43:47:46:d2:08:99:16:60:3b:9a:7e:d2:e6:ed:
+                    38:ea:ec:01:1e:3c:48:56:49:09:c7:4c:37:00:9e:
+                    88:0e:c0:73:e1:6f:66:e9:72:47:30:3e:10:e5:0b:
+                    03:c9:9a:42:00:6c:c5:94:7e:61:c4:8a:df:7f:82:
+                    1a:0b:59:c4:59:32:77:b3:bc:60:69:56:39:fd:b4:
+                    06:7b:2c:d6:64:36:d9:bd:48:ed:84:1f:7e:a5:22:
+                    8f:2a:b8:42:f4:82:b7:d4:53:90:78:4e:2d:1a:fd:
+                    81:6f:44:d7:3b:01:74:96:42:e0:00:e2:2e:6b:ea:
+                    c5:ee:72:ac:bb:bf:fe:ea:aa:a8:f8:dc:f6:b2:79:
+                    8a:b6:67
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Subject Key Identifier: 
+                9D:C0:67:A6:0C:22:D9:26:F5:45:AB:A6:65:52:11:27:D8:45:AC:63
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+    Signature Algorithm: sha384WithRSAEncryption
+         b3:57:4d:10:62:4e:3a:e4:ac:ea:b8:1c:af:32:23:c8:b3:49:
+         5a:51:9c:76:28:8d:79:aa:57:46:17:d5:f5:52:f6:b7:44:e8:
+         08:44:bf:18:84:d2:0b:80:cd:c5:12:fd:00:55:05:61:87:41:
+         dc:b5:24:9e:3c:c4:d8:c8:fb:70:9e:2f:78:96:83:20:36:de:
+         7c:0f:69:13:88:a5:75:36:98:08:a6:c6:df:ac:ce:e3:58:d6:
+         b7:3e:de:ba:f3:eb:34:40:d8:a2:81:f5:78:3f:2f:d5:a5:fc:
+         d9:a2:d4:5e:04:0e:17:ad:fe:41:f0:e5:b2:72:fa:44:82:33:
+         42:e8:2d:58:f7:56:8c:62:3f:ba:42:b0:9c:0c:5c:7e:2e:65:
+         26:5c:53:4f:00:b2:78:7e:a1:0d:99:2d:8d:b8:1d:8e:a2:c4:
+         b0:fd:60:d0:30:a4:8e:c8:04:62:a9:c4:ed:35:de:7a:97:ed:
+         0e:38:5e:92:2f:93:70:a5:a9:9c:6f:a7:7d:13:1d:7e:c6:08:
+         48:b1:5e:67:eb:51:08:25:e9:e6:25:6b:52:29:91:9c:d2:39:
+         73:08:57:de:99:06:b4:5b:9d:10:06:e1:c2:00:a8:b8:1c:4a:
+         02:0a:14:d0:c1:41:ca:fb:8c:35:21:7d:82:38:f2:a9:54:91:
+         19:35:93:94:6d:6a:3a:c5:b2:d0:bb:89:86:93:e8:9b:c9:0f:
+         3a:a7:7a:b8:a1:f0:78:46:fa:fc:37:2f:e5:8a:84:f3:df:fe:
+         04:d9:a1:68:a0:2f:24:e2:09:95:06:d5:95:ca:e1:24:96:eb:
+         7c:f6:93:05:bb:ed:73:e9:2d:d1:75:39:d7:e7:24:db:d8:4e:
+         5f:43:8f:9e:d0:14:39:bf:55:70:48:99:57:31:b4:9c:ee:4a:
+         98:03:96:30:1f:60:06:ee:1b:23:fe:81:60:23:1a:47:62:85:
+         a5:cc:19:34:80:6f:b3:ac:1a:e3:9f:f0:7b:48:ad:d5:01:d9:
+         67:b6:a9:72:93:ea:2d:66:b5:b2:b8:e4:3d:3c:b2:ef:4c:8c:
+         ea:eb:07:bf:ab:35:9a:55:86:bc:18:a6:b5:a8:5e:b4:83:6c:
+         6b:69:40:d3:9f:dc:f1:c3:69:6b:b9:e1:6d:09:f4:f1:aa:50:
+         76:0a:7a:7d:7a:17:a1:55:96:42:99:31:09:dd:60:11:8d:05:
+         30:7e:e6:8e:46:d1:9d:14:da:c7:17:e4:05:96:8c:c4:24:b5:
+         1b:cf:14:07:b2:40:f8:a3:9e:41:86:bc:04:d0:6b:96:c8:2a:
+         80:34:fd:bf:ef:06:a3:dd:58:c5:85:3d:3e:8f:fe:9e:29:e0:
+         b6:b8:09:68:19:1c:18:43
+SHA1 Fingerprint=D8:A6:33:2C:E0:03:6F:B1:85:F6:63:4F:7D:6A:06:65:26:32:28:27
+-----BEGIN CERTIFICATE-----
+MIIFRjCCAy6gAwIBAgIIbYwURrGmCu4wDQYJKoZIhvcNAQEMBQAwQTELMAkGA1UE
+BhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MRwwGgYDVQQDDBNBZmZpcm1UcnVz
+dCBQcmVtaXVtMB4XDTEwMDEyOTE0MTAzNloXDTQwMTIzMTE0MTAzNlowQTELMAkG
+A1UEBhMCVVMxFDASBgNVBAoMC0FmZmlybVRydXN0MRwwGgYDVQQDDBNBZmZpcm1U
+cnVzdCBQcmVtaXVtMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxBLf
+qV/+Qd3d9Z+K4/as4Tx4mrzY8H96oDMq3I0gW64tb+eT2TZwamjPjlGjhVtnBKAQ
+JG9dKILBl1fYSCkTtuG+kU3fhQxTGJoeJKJPj/CihQvL9Cl/0qRY7iZNyaqoe5rZ
++jjeRFcV5fiMyNlI4g0WJx0eyIOFJbe6qlVBzAMiSy2RjYvmia9mx+n/K+k8rNrS
+s8PhaJyJ+HoAVt70VZVs+7pk3WKL3wt3MutizCaam7uqYoNMtAZ6MMgpv+0GTZe5
+HMQxK9VfvFMSF5yZVylmd2EhMQcuJUmdGPLu8ytxjLW6OQdJd/zvLpKQBY0tL3d7
+70O/Nbua2Plzpyzy0FfuKE4mX4+QaAkvuPjcBukumj5Rp9EixAqnOEhss/n/fauG
+V+O61oV4d7pD6kh/9ti+I20ev9E2bFhc8e6kGVQa9QPSdubhjL08s9NIS+LI+H+S
+qHZGnEJlPqQewQcDWkYtuJfzt9WyVSHvutxMAJf7FJUnM7/oQ0dG0giZFmA7mn7S
+5u046uwBHjxIVkkJx0w3AJ6IDsBz4W9m6XJHMD4Q5QsDyZpCAGzFlH5hxIrff4Ia
+C1nEWTJ3s7xgaVY5/bQGeyzWZDbZvUjthB9+pSKPKrhC9IK31FOQeE4tGv2Bb0TX
+OwF0lkLgAOIua+rF7nKsu7/+6qqo+Nz2snmKtmcCAwEAAaNCMEAwHQYDVR0OBBYE
+FJ3AZ6YMItkm9UWrpmVSESfYRaxjMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/
+BAQDAgEGMA0GCSqGSIb3DQEBDAUAA4ICAQCzV00QYk465KzquByvMiPIs0laUZx2
+KI15qldGF9X1Uva3ROgIRL8YhNILgM3FEv0AVQVhh0HctSSePMTYyPtwni94loMg
+Nt58D2kTiKV1NpgIpsbfrM7jWNa3Pt668+s0QNiigfV4Py/VpfzZotReBA4Xrf5B
+8OWycvpEgjNC6C1Y91aMYj+6QrCcDFx+LmUmXFNPALJ4fqENmS2NuB2OosSw/WDQ
+MKSOyARiqcTtNd56l+0OOF6SL5Nwpamcb6d9Ex1+xghIsV5n61EIJenmJWtSKZGc
+0jlzCFfemQa0W50QBuHCAKi4HEoCChTQwUHK+4w1IX2COPKpVJEZNZOUbWo6xbLQ
+u4mGk+ibyQ86p3q4ofB4Rvr8Ny/lioTz3/4E2aFooC8k4gmVBtWVyuEklut89pMF
+u+1z6S3RdTnX5yTb2E5fQ4+e0BQ5v1VwSJlXMbSc7kqYA5YwH2AG7hsj/oFgIxpH
+YoWlzBk0gG+zrBrjn/B7SK3VAdlntqlyk+otZrWyuOQ9PLLvTIzq6we/qzWaVYa8
+GKa1qF60g2xraUDTn9zxw2lrueFtCfTxqlB2Cnp9ehehVZZCmTEJ3WARjQUwfuaO
+RtGdFNrHF+QFlozEJLUbzxQHskD4o55BhrwE0GuWyCqANP2/7waj3VjFhT0+j/6e
+KeC2uAloGRwYQw==
+-----END CERTIFICATE-----

Copied: stable/11/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem (from r353095, head/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem)
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ stable/11/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem	Mon Apr 27 21:41:00 2020	(r360395, copy of r353095, head/secure/caroot/trusted/AffirmTrust_Premium_ECC.pem)
@@ -0,0 +1,63 @@
+##
+##  AffirmTrust Premium ECC
+##
+##  This is a single X.509 certificate for a public Certificate
+##  Authority (CA). It was automatically extracted from Mozilla's
+##  root CA list (the file `certdata.txt' in security/nss).
+##
+##  Extracted from nss
+##  with $FreeBSD: head/secure/caroot/MAca-bundle.pl 352951 2019-10-02 01:27:50Z kevans $
+##
+##  @generated
+##
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 8401224907861490260 (0x7497258ac73f7a54)
+        Signature Algorithm: ecdsa-with-SHA384
+        Issuer: C = US, O = AffirmTrust, CN = AffirmTrust Premium ECC
+        Validity
+            Not Before: Jan 29 14:20:24 2010 GMT
+            Not After : Dec 31 14:20:24 2040 GMT
+        Subject: C = US, O = AffirmTrust, CN = AffirmTrust Premium ECC
+        Subject Public Key Info:
+            Public Key Algorithm: id-ecPublicKey
+                Public-Key: (384 bit)
+                pub:
+                    04:0d:30:5e:1b:15:9d:03:d0:a1:79:35:b7:3a:3c:
+                    92:7a:ca:15:1c:cd:62:f3:9c:26:5c:07:3d:e5:54:
+                    fa:a3:d6:cc:12:ea:f4:14:5f:e8:8e:19:ab:2f:2e:
+                    48:e6:ac:18:43:78:ac:d0:37:c3:bd:b2:cd:2c:e6:

*** DIFF OUTPUT TRUNCATED AT 1000 LINES ***


More information about the svn-src-all mailing list