Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The CA certificates in the ca-certificates package were updated.. ========================================================================== Ubuntu Security Notice USN-7034-1 September 25, 2024 ca-certificates update ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: The CA certificates in the ca-certificates package were updated. Software Description: - ca-certificates: Common CA certificates Details: The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.64 version of the Mozilla certificate authority bundle. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS ca-certificates 20240203~22.04.1 Ubuntu 20.04 LTS ca-certificates 20240203~20.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7034-1 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates/20240203~20.04.1 . Urgent patch released for Ubuntu TLS certificates package crucial for safe data exchanges. Discover the specifics of the update.. Ubuntu Security, CA Certificates Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team
A certificate about to expire was removed from ca-certificates.. =========================================================================Ubuntu Security Notice USN-5089-2 September 23, 2021 ca-certificates update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: A certificate about to expire was removed from ca-certificates. Software Description: - ca-certificates: Common CA certificates Details: USN-5089-1 updated ca-certificates. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: The ca-certificates package contained a CA certificate that will expire on 2021-09-30 and will cause connectivity issues. This update removes the “DST Root CA X3” CA. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: ca-certificates 20210119~16.04.1ubuntu0.1~esm1 Ubuntu 14.04 ESM: ca-certificates 20190110~14.04.1~esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5089-2 https://ubuntu.com/security/notices/USN-5089-1 . Resolve connectivity issues linked to an expiring CA certificate in Ubuntu 14.04 and 16.04 ESM by following these essential steps for updates. ca-certificates update, connectivity issue, expiring certificate, Ubuntu security. . Severity: Critical. LinuxSecurity.com Team
This is an update to Mozilla's CA certificates list version 2.22, which has been published as part of Mozilla NSS 3.35. For additional details, please refer to the NSS 3.35 release notes: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-60613721f6 2018-02-20 16:35:51.259191 --------------------------------------------------------------------------------Name : ca-certificates Product : Fedora 26 Version : 2018.2.22 Release : 1.0.fc26 URL : https://fedoraproject.org/wiki/CA-Certificates Summary : The Mozilla CA root certificate bundle Description : This package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI. --------------------------------------------------------------------------------Update Information: This is an update to Mozilla's CA certificates list version 2.22, which has been published as part of Mozilla NSS 3.35. For additional details, please refer to the NSS 3.35 release notes: --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ca-certificates' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This is an update to the Mozilla CA certificates list version 2.10, which has been published as part of Mozilla NSS 3.27. For additional details, please refer to the NSS 3.27 release notes: As in previous versions of the ca-certificates package, the CA list has been modified to keep several. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-ae6d4b4c33 2016-10-11 15:42:43.078207 -------------------------------------------------------------------------------- Name : ca-certificates Product : Fedora 24 Version : 2016.2.10 Release : 1.0.fc24 URL : https://fedoraproject.org/wiki/CA-Certificates Summary : The Mozilla CA root certificate bundle Description : This package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI. -------------------------------------------------------------------------------- Update Information: This is an update to the Mozilla CA certificates list version 2.10, which has been published as part of Mozilla NSS 3.27. For additional details, please refer to the NSS 3.27 release notes: As in previous versions of the ca-certificates package, the CA list has been modified to keep several legacy CAs still trusted for compatibility reasons. Please refer to https://fedoraproject.org/wiki/CA-Certificates for details. If you prefer to use the unchanged list provided by Mozilla, and if you accept any compatibility issues it may cause, an administrator may configure the system by executing the "ca-legacy disable" command. Please refer to the manual page of the ca-legacy command for additional details. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1380067 - nss-3.27 is available https://bugzilla.redhat.com/show_bug.cgi?id=1380067 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yumupdate ca-certificates' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This is an update to the set of CA certificates released with NSS version 3.18.1 However, the package modifies the CA list to keep several legacy CAs still trusted for compatibility reasons. Please refer to the project URL for details. If you prefer to use the unchanged list provided by Mozilla, and if you accept any compatibility issues it may cause, an administrator may configure the system by e [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7918 2015-05-10 04:05:21 -------------------------------------------------------------------------------- Name : ca-certificates Product : Fedora 22 Version : 2015.2.4 Release : 1.0.fc22 URL : https://fedoraproject.org/wiki/CA-Certificates Summary : The Mozilla CA root certificate bundle Description : This package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI. -------------------------------------------------------------------------------- Update Information: This is an update to the set of CA certificates released with NSS version 3.18.1 However, the package modifies the CA list to keep several legacy CAs still trusted for compatibility reasons. Please refer to the project URL for details. If you prefer to use the unchanged list provided by Mozilla, and if you accept any compatibility issues it may cause, an administrator may configure the system by executing the "ca-legacy disable" command. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ca-certificates' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
This is an update to the set of CA certificates released with NSS version 3.18 However, the package modifies the CA list to keep several legacy CAs still trusted for compatibility reasons. Please refer to the project URL for details. If you prefer to use the unchanged list provided by Mozilla, and if you accept any compatibility issues it may cause, an administrator may configure the system by exe [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-4711 2015-03-26 16:50:15 -------------------------------------------------------------------------------- Name : ca-certificates Product : Fedora 21 Version : 2015.2.3 Release : 1.0.fc21 URL : https://fedoraproject.org/wiki/CA-Certificates Summary : The Mozilla CA root certificate bundle Description : This package contains the set of CA certificates chosen by the Mozilla Foundation for use with the Internet PKI. -------------------------------------------------------------------------------- Update Information: This is an update to the set of CA certificates released with NSS version 3.18 However, the package modifies the CA list to keep several legacy CAs still trusted for compatibility reasons. Please refer to the project URL for details. If you prefer to use the unchanged list provided by Mozilla, and if you accept any compatibility issues it may cause, an administrator may configure the system by executing the "ca-legacy disable" command. This update corrects the Fedora legacy classification of four root CA certificates, which had trust added or removed in the upstream 2.1 and 2.2 releases. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2015 Kai Engert - 2015.2.3-1.0 - Update to CKBI 2.3 from NSS 3.18 with legacy modifications - Fixed a mistake in the legacy handling of the upstream 2.2 release: Removed two AOL certificates from the legacy group, because upstream didn't removethem as part of phasing out 1024-bit certificates, which means it isn't necessary to keep them. - Fixed a mistake in the legacy handling of the upstream 2.1 release: Moved two NetLock certificates into the legacy group. * Tue Dec 16 2014 Kai Engert - 2014.2.2-1.0 - Update to CKBI 2.2 from NSS 3.17.3 with legacy modifications - Update project URL - Cleanup -------------------------------------------------------------------------------- References: [ 1 ] Bug #1205305 - Update to version 2.3 as released with NSS 3.18 https://bugzilla.redhat.com/show_bug.cgi?id=1205305 [ 2 ] Bug #1205302 - Fix the legacy CA inclusions of upstream 2.1 and 2.2 https://bugzilla.redhat.com/show_bug.cgi?id=1205302 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ca-certificates' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
An unauthorized SSL certificate has been found in the wild issued the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2299-1
Get the latest Linux and open source security news straight to your inbox.