Skip to content

Conversation

@lgarofalo
Copy link
Contributor

Rolling trust store release at 2025-12-15T17:13:12-0800. $ cfssl-trust -d ./cert.db -b int release 744h
skipping expired certificate (SKI=f4f93d5e53117b9c6965283e8c6f2f00787ee573, serial=1735334444758909597309683440489490, subject='/TC TrustCenter Class 1 L1 CA VII/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 1 L1 CA') skipping expired certificate (SKI=5857e2fc9a3b14f8b0efa622949ede5da4b287a4, serial=3216980311938159973284287268626246, subject='/TC TrustCenter Class 3 L1 CA VII/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 3 L1 CA') skipping expired certificate (SKI=0876cdcb07ff24f6c5cdedbb90bce284374675f7, serial=47728425367563953368335862826026879003, subject='/Certum Trusted Network CA/C=PL/O=Unizeto Technologies S.A./OU=Certum Certification Authority') skipping expired certificate (SKI=b051f97d55e4b8729fd13a680ad085dada850f90, serial=13538439173959050390055592225638891297, subject='/Allina Health Connect HIE Intermediate CA/C=US/O=Allina Health System/OU=Information Services') skipping expired certificate (SKI=0d177f4a586eb40f15d1aaf3d1e486786c67e236, serial=11425711187779396239744497887850152405, subject='/CompuGroup Medical Certificate Authority/C=US/O=Compugroup Medical, Inc/OU=IT') skipping expired certificate (SKI=54dc90bb9d471951c379682c84ed2edf5f46bac7, serial=128168660809396254797307279296874507737, subject='/nazwaSSL/C=PL/O=nazwa.pl sp. z o.o./OU=http://nazwa.pl') skipping expired certificate (SKI=c339fc6768aeb311d6198076b3d5ba085e19c5d4, serial=86493547276155173388489777046356462199, subject='/Certigna Identity CA/C=FR/O=DHIMYOTIS/OU=0002 48146308100036') skipping expired certificate (SKI=7190c599ca0812c940f398d3a6b30fc9fdaac7d6, serial=156762549197834556994352785380332204247, subject='/Certigna Entity Code Signing CA/C=FR/O=DHIMYOTIS/OU=0002 48146308100036') 1272 certificates rolled
8 certificates skipped
Successfully rolled new int release 2025.12.0
$ cfssl-trust -d ./cert.db -b ca release 744h
skipping expired certificate (SKI=e3ab544c80a1db5643b7914acbf3827a135c08ab, serial=941389028203453866782103406992443, subject='/TC TrustCenter Class 2 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 2 CA') skipping expired certificate (SKI=d4a2fc9fb3c3d803d3575c07a4d024a7c0f200d4, serial=1506523511417715638772220530020799, subject='/TC TrustCenter Class 3 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 3 CA') skipping expired certificate (SKI=92a4752ca49ebe8144eb79fc8ac595a5eb107573, serial=601024842042189035295619584734726, subject='/TC TrustCenter Universal CA I/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Universal CA') skipping expired certificate (SKI=1feabb3e251b06bda5dd62057ec64c5abfe80f43, serial=116623856429964560337522234651920, subject='/TC TrustCenter Class 4 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 4 CA') 342 certificates rolled
4 certificates skipped
Successfully rolled new ca release 2025.12.0
$ cfssl-trust -d ./cert.db -r 2025.12.0 -b int bundle int-bundle.crt selected release 2025.12.0
Selected 1272 certificates for this release.
$ cfssl-trust -d ./cert.db -r 2025.12.0 -b ca bundle ca-bundle.crt selected release 2025.12.0
Selected 342 certificates for this release.
$ certdump ca-bundle.crt > certdata/ca-bundle.txt $ certdump int-bundle.crt > certdata/int-bundle.txt $ git status --porcelain -uno
M ca-bundle.crt
M cert.db
M certdata/ca-bundle.txt
M certdata/int-bundle.txt
M int-bundle.crt

Rolling trust store release at 2025-12-15T17:13:12-0800.
$ cfssl-trust -d ./cert.db  -b int release 744h
skipping expired certificate (SKI=f4f93d5e53117b9c6965283e8c6f2f00787ee573, serial=1735334444758909597309683440489490, subject='/TC TrustCenter Class 1 L1 CA VII/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 1 L1 CA')
skipping expired certificate (SKI=5857e2fc9a3b14f8b0efa622949ede5da4b287a4, serial=3216980311938159973284287268626246, subject='/TC TrustCenter Class 3 L1 CA VII/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 3 L1 CA')
skipping expired certificate (SKI=0876cdcb07ff24f6c5cdedbb90bce284374675f7, serial=47728425367563953368335862826026879003, subject='/Certum Trusted Network CA/C=PL/O=Unizeto Technologies S.A./OU=Certum Certification Authority')
skipping expired certificate (SKI=b051f97d55e4b8729fd13a680ad085dada850f90, serial=13538439173959050390055592225638891297, subject='/Allina Health Connect HIE Intermediate CA/C=US/O=Allina Health System/OU=Information Services')
skipping expired certificate (SKI=0d177f4a586eb40f15d1aaf3d1e486786c67e236, serial=11425711187779396239744497887850152405, subject='/CompuGroup Medical Certificate Authority/C=US/O=Compugroup Medical, Inc/OU=IT')
skipping expired certificate (SKI=54dc90bb9d471951c379682c84ed2edf5f46bac7, serial=128168660809396254797307279296874507737, subject='/nazwaSSL/C=PL/O=nazwa.pl sp. z o.o./OU=http://nazwa.pl')
skipping expired certificate (SKI=c339fc6768aeb311d6198076b3d5ba085e19c5d4, serial=86493547276155173388489777046356462199, subject='/Certigna Identity CA/C=FR/O=DHIMYOTIS/OU=0002 48146308100036')
skipping expired certificate (SKI=7190c599ca0812c940f398d3a6b30fc9fdaac7d6, serial=156762549197834556994352785380332204247, subject='/Certigna Entity Code Signing CA/C=FR/O=DHIMYOTIS/OU=0002 48146308100036')
1272 certificates rolled
8 certificates skipped
Successfully rolled new int release 2025.12.0
$ cfssl-trust -d ./cert.db  -b ca release 744h
skipping expired certificate (SKI=e3ab544c80a1db5643b7914acbf3827a135c08ab, serial=941389028203453866782103406992443, subject='/TC TrustCenter Class 2 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 2 CA')
skipping expired certificate (SKI=d4a2fc9fb3c3d803d3575c07a4d024a7c0f200d4, serial=1506523511417715638772220530020799, subject='/TC TrustCenter Class 3 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 3 CA')
skipping expired certificate (SKI=92a4752ca49ebe8144eb79fc8ac595a5eb107573, serial=601024842042189035295619584734726, subject='/TC TrustCenter Universal CA I/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Universal CA')
skipping expired certificate (SKI=1feabb3e251b06bda5dd62057ec64c5abfe80f43, serial=116623856429964560337522234651920, subject='/TC TrustCenter Class 4 CA II/C=DE/O=TC TrustCenter GmbH/OU=TC TrustCenter Class 4 CA')
342 certificates rolled
4 certificates skipped
Successfully rolled new ca release 2025.12.0
$ cfssl-trust -d ./cert.db  -r 2025.12.0 -b int bundle int-bundle.crt
selected release 2025.12.0
Selected 1272 certificates for this release.
$ cfssl-trust -d ./cert.db  -r 2025.12.0 -b ca bundle ca-bundle.crt
selected release 2025.12.0
Selected 342 certificates for this release.
$ certdump ca-bundle.crt  > certdata/ca-bundle.txt
$ certdump int-bundle.crt > certdata/int-bundle.txt
$ git status --porcelain -uno
M  ca-bundle.crt
M  cert.db
M  certdata/ca-bundle.txt
M  certdata/int-bundle.txt
M  int-bundle.crt
@lgarofalo lgarofalo merged commit a3b9e2d into master Dec 16, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant