Recommended update for openssl-certs

Announcement ID: SUSE-RU-2019:13941-1
Rating: moderate
References:
Affected Products:
  • SLES for SAP Applications 11-SP4
  • SUSE Linux Enterprise Point of Service 11 SP3
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3
  • SUSE Linux Enterprise Server 11 SP4

An update that has one fix can now be installed.

Description:

This update for openssl-certs fixes the following issues:

The package was updated to 2.30 version of the Mozilla NSS Certificate store. (bsc#1121446)

Removed Root CAs:

  • AC Raiz Certicamara S.A.
  • Certplus Root CA G1
  • Certplus Root CA G2
  • OpenTrust Root CA G1
  • OpenTrust Root CA G2
  • OpenTrust Root CA G3
  • Visa eCommerce Root

Added Root CAs:

  • Certigna Root CA (email and server auth)
  • GTS Root R1 (server auth)
  • GTS Root R2 (server auth)
  • GTS Root R3 (server auth)
  • GTS Root R4 (server auth)
  • OISTE WISeKey Global Root GC CA (email and server auth)
  • UCA Extended Validation Root (server auth)
  • UCA Global G2 Root (email and server auth)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Point of Service 11 SP3
    zypper in -t patch sleposp3-openssl-certs-13941=1
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3
    zypper in -t patch slessp3-openssl-certs-13941=1
  • SUSE Linux Enterprise Server 11 SP4
    zypper in -t patch slessp4-openssl-certs-13941=1
  • SLES for SAP Applications 11-SP4
    zypper in -t patch slessp4-openssl-certs-13941=1

Package List:

  • SUSE Linux Enterprise Point of Service 11 SP3 (noarch)
    • openssl-certs-2.30-0.7.9.1
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3 (noarch)
    • openssl-certs-2.30-0.7.9.1
  • SUSE Linux Enterprise Server 11 SP4 (noarch)
    • openssl-certs-2.30-0.7.9.1
  • SLES for SAP Applications 11-SP4 (noarch)
    • openssl-certs-2.30-0.7.9.1

References: