From d857f7c5304d42c27b879e67659f19fcc72e17b8 Mon Sep 17 00:00:00 2001 From: DJ Lucas Date: Thu, 5 Aug 2021 00:33:04 -0500 Subject: [PATCH] make-ca: Use --filter=certificates for all stores. --- CHANGELOG | 1 + make-ca | 8 ++++---- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/CHANGELOG b/CHANGELOG index dadf4e8..89aac72 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -7,6 +7,7 @@ - Assume serverAuth for certificates added by 'trust anchors --store' and generate a trusted certificate for use in LOCALDIR - Add nss-{server,email}-distrust-after values in anchors + - Use --filter=certificates for all stores 1.7 - Revert help2man update (requires complete perl environment) 1.6 - Fix install target for make -j# - Add detailed dependency info and add note about configuration file diff --git a/make-ca b/make-ca index 04630d1..f08b66d 100644 --- a/make-ca +++ b/make-ca @@ -872,19 +872,19 @@ echo -n "Extracting OpenSSL certificates to ${DESTDIR}${CERTDIR}..." --overwrite --comment "${DESTDIR}${CERTDIR}" \ && echo "Done!" || echo "Failed!!!" echo -n "Extracting GNUTLS server auth certificates to ${DESTDIR}${CABUNDLE}..." -"${TRUST}" extract --filter=ca-anchors --format=pem-bundle \ +"${TRUST}" extract --filter=certificates --format=pem-bundle \ --purpose server-auth --overwrite --comment "${DESTDIR}${CABUNDLE}" \ && echo "Done!" || echo "Failed!!!" echo -n "Extracting GNUTLS S-Mime certificates to ${DESTDIR}${SMBUNDLE}..." -"${TRUST}" extract --filter=ca-anchors --format=pem-bundle \ +"${TRUST}" extract --filter=certificates --format=pem-bundle \ --purpose email --overwrite --comment "${DESTDIR}${SMBUNDLE}" \ && echo "Done!" || echo "Failed!!!" echo -n "Extracting GNUTLS code signing certificates to ${DESTDIR}${CSBUNDLE}..." -"${TRUST}" extract --filter=ca-anchors --format=pem-bundle \ +"${TRUST}" extract --filter=certificates --format=pem-bundle \ --purpose code-signing --overwrite --comment \ "${DESTDIR}${CSBUNDLE}" && echo "Done!" || echo "Failed!!!" echo -n "Extracting Java cacerts (JKS) to ${DESTDIR}${KEYSTORE}/cacerts..." -"${TRUST}" extract --filter=ca-anchors --format=java-cacerts \ +"${TRUST}" extract --filter=certificates --format=java-cacerts \ --purpose server-auth --overwrite \ --comment "${DESTDIR}${KEYSTORE}/cacerts" \ && echo "Done!" || echo "Failed!!!"