Recommended update for openssl-certs

SUSE Recommended Update: Recommended update for openssl-certs
Announcement ID: SUSE-RU-2018:2625-1
Rating: moderate
References: #1100415 #1104780
Affected Products:
  • SUSE Linux Enterprise Server 11-SP4
  • SUSE Linux Enterprise Server 11-SP3-LTSS
  • SUSE Linux Enterprise Point of Sale 11-SP3

An update that has two recommended fixes can now be installed.

Description:


This update for openssl-certs fixes the following issues:
Updated to 2.26 state of the Mozilla NSS Certificate store. (bsc#1104780)

  • Removed server auth rights from:

- Certplus Root CA G1 - Certplus Root CA G2 - OpenTrust Root CA G1 - OpenTrust Root CA G2 - OpenTrust Root CA G3
  • removed CA

- ComSign CA
  • Added new CA

- GlobalSign
Updated to 2.24 state of the Mozilla NSS Certificate store. (bsc#1100415)
Removed CAs:
- S-TRUST_Universal_Root_CA:2.16.96.86.197.75.35.64.91.100.212.237.37.218.217 .214.30.30.crt - TC_TrustCenter_Class_3_CA_II:2.14.74.71.0.1.0.2.229.160.93.214.63.0.81.191. crt - TUeRKTRUST_Elektronik_Sertifika_Hizmet_Saglayicisi_H5:2.7.0.142.23.254.36.3 2.129.crt

Patch Instructions:

To install this SUSE Recommended Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server 11-SP4:
    zypper in -t patch slessp4-openssl-certs-13768=1
  • SUSE Linux Enterprise Server 11-SP3-LTSS:
    zypper in -t patch slessp3-openssl-certs-13768=1
  • SUSE Linux Enterprise Point of Sale 11-SP3:
    zypper in -t patch sleposp3-openssl-certs-13768=1

Package List:

  • SUSE Linux Enterprise Server 11-SP4 (noarch):
    • openssl-certs-2.26-0.7.6.1
  • SUSE Linux Enterprise Server 11-SP3-LTSS (noarch):
    • openssl-certs-2.26-0.7.6.1
  • SUSE Linux Enterprise Point of Sale 11-SP3 (noarch):
    • openssl-certs-2.26-0.7.6.1

References: