[oi-dev] update of ca-certificates ?

stes@PANDORA.BE stes at telenet.be
Thu Oct 14 17:25:54 UTC 2021


Hi,

In the current OpenIndiana ca-certificates:

$ pkg contents ca-certificates | grep DST_Root_CA        
etc/certs/CA/DST_Root_CA_X3.pem

However see the following note on expiration on Sep 30 2021 :

http://lists.squeakfoundation.org/pipermail/squeak-dev/2021-October/216603.html

I am experiencing in "Squeak for OpenIndiana" a (new) certificate error.

(Squeak is a Smalltalk-80 implementation by Dan Ingalls/Alan Kay etc.)

New in the sense that it only started to happen the last weeks - after Sep 30.

This Squeak application level error is going away after

# cd /etc/certs/CA
# rm DST_Root_CA_X3.pem
# svcadm restart ca-certificates

at the OS level - without changing anything in Squeak.

Possibly only Squeak is affected as the repository of Squeak uses perhaps this certificate,
but the note at openssl.com seems to imply that all systems must be patched/fixed ?

So should there be an update of the ca-certificates package in OpenIndiana ?

Thanks,
David Stes



More information about the oi-dev mailing list