ืงืจื™ืกื•ืช ื‘-OpenBSD, DragonFly BSD ื•-Electron ืขืงื‘ ืคืงื™ืขืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ IdenTrust

ื”ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืฉืœ ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ IdenTrust (DST Root CA X3), ื”ืžืฉืžืฉ ืœื—ืชื™ืžื” ืฆื•ืœื‘ืช ืฉืœ ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ Let's Encrypt CA, ื’ืจื ืœื‘ืขื™ื•ืช ืขื ืื™ืžื•ืช ืื™ืฉื•ืจ Let's Encrypt ื‘ืคืจื•ื™ืงื˜ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ OpenSSL ื•-GnuTLS. ื‘ืขื™ื•ืช ื”ืฉืคื™ืขื• ื’ื ืขืœ ืกืคืจื™ื™ืช LibreSSL, ืฉื”ืžืคืชื—ื™ื ืฉืœื” ืœื ืœืงื—ื• ื‘ื—ืฉื‘ื•ืŸ ื ื™ืกื™ื•ืŸ ื”ืขื‘ืจ ื”ืงืฉื•ืจ ืœื›ืฉืœื™ื ืฉื”ืชืขื•ืจืจื• ืœืื—ืจ ืฉืื™ืฉื•ืจ ื”ืฉื•ืจืฉ AddTrust ืฉืœ Sectigo (Comodo) CA ื”ืชื™ื™ืฉืŸ.

ื ื–ื›ื™ืจ ื›ื™ ื‘ืžื”ื“ื•ืจื•ืช OpenSSL ืขื“ ืขื ืฃ 1.0.2 ื›ื•ืœืœ ื•ื‘-GnuTLS ืœืคื ื™ ื’ืจืกื” 3.6.14, ื”ื™ื” ื‘ืื’ ืฉืœื ืืคืฉืจ ืœืขื‘ื“ ืชืขื•ื“ื•ืช ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช ื‘ืฆื•ืจื” ื ื›ื•ื ื” ืื ืื—ื“ ืžืชืขื•ื“ื•ืช ื”ื‘ืกื™ืก ืฉืฉื™ืžืฉื• ืœื—ืชื™ืžื” ืžื™ื•ืฉืŸ , ื’ื ืื ืชืงืคื™ื ืื—ืจื™ื ื”ื™ื• ืฉืจืฉืจืื•ืช ืืžื•ืŸ ืฉื ืฉืžืจื• (ื‘ืžืงืจื” ืฉืœ Let's Encrypt, ื”ืชื™ื™ืฉื ื•ืช ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœ IdenTrust ืžื•ื ืขืช ืื™ืžื•ืช, ื’ื ืื ืœืžืขืจื›ืช ื™ืฉ ืชืžื™ื›ื” ื‘ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœ Let's Encrypt ืขืฆืžื•, ื‘ืชื•ืงืฃ ืขื“ 2030). ืชืžืฆื™ืช ื”ื‘ืื’ ื”ื™ื ืฉื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ OpenSSL ื•-GnuTLS ื ื™ืชื—ื• ืืช ื”ืชืขื•ื“ื” ื›ืฉืจืฉืจืช ืœื™ื ื™ืืจื™ืช, ื‘ืขื•ื“ ืฉืœืคื™ RFC 4158, ืชืขื•ื“ื” ื™ื›ื•ืœื” ืœื™ื™ืฆื’ ื’ืจืฃ ืžืขื’ืœื™ ืžื‘ื•ื–ืจ ืžื›ื•ื•ืŸ ืขื ืขื•ื’ื ื™ ืืžื•ืŸ ืžืจื•ื‘ื™ื ืฉื™ืฉ ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ.

ื›ื“ืจืš ืขื•ืงืคืช ืœืคืชืจื•ืŸ ื”ื›ืฉืœ, ืžื•ืฆืข ืœืžื—ื•ืง ืืช ืื™ืฉื•ืจ "DST Root CA X3" ืžืื—ืกื•ืŸ ื”ืžืขืจื›ืช (/etc/ca-certificates.conf ื•-/etc/ssl/certs), ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” "update" -ca-certificates -f -v" "). ื‘-CentOS ื•-RHEL, ืืชื” ื™ื›ื•ืœ ืœื”ื•ืกื™ืฃ ืืช ื”ืื™ืฉื•ืจ "DST Root CA X3" ืœืจืฉื™ืžื” ื”ืฉื—ื•ืจื”: trust dump โ€”filter "pkcs11:id=%c4%a7%b1%a4%7b%2c%71%fa%db%e1% 4b%90 %75%ff%c4%15%60%85%89%10" | openssl x509 | sudo tee /etc/pki/ca-trust/source/blacklist/DST-Root-CA-X3.pem sudo update-ca-trust extract

ื›ืžื” ืžื”ืงืจื™ืกื•ืช ืฉืจืื™ื ื• ืฉื”ืชืจื—ืฉื• ืœืื—ืจ ืฉืคื’ ืชื•ืงืคื• ืฉืœ ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ IdenTrust:

  • ื‘-OpenBSD, ื›ืœื™ ื”ืฉื™ืจื•ืช syspatch, ื”ืžืฉืžืฉ ืœื”ืชืงื ืช ืขื“ื›ื•ื ื™ ืžืขืจื›ืช ื‘ื™ื ืืจื™ื, ื”ืคืกื™ืง ืœืขื‘ื•ื“. ืคืจื•ื™ืงื˜ OpenBSD ืฉื—ืจืจ ื”ื™ื•ื ื‘ื“ื—ื™ืคื•ืช ืชื™ืงื•ื ื™ื ืœืกื ื™ืคื™ื 6.8 ื•-6.9 ืฉืžืชืงื ื™ื ื‘ืขื™ื•ืช ื‘-LibreSSL ื‘ื‘ื“ื™ืงืช ืื™ืฉื•ืจื™ื ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช, ืฉืื—ื“ ืžืชืขื•ื“ื•ืช ื”ืฉื•ืจืฉ ื‘ืฉืจืฉืจืช ื”ืืžื•ืŸ ืฉืœื” ืคื’. ื›ืคืชืจื•ืŸ ืœื‘ืขื™ื”, ืžื•ืžืœืฅ ืœืขื‘ื•ืจ ืž-HTTPS ืœ-HTTP ื‘-/etc/installurl (ื–ื” ืœื ืžืื™ื™ื ืขืœ ื”ืื‘ื˜ื—ื”, ืžื›ื™ื•ื•ืŸ ืฉื”ืขื“ื›ื•ื ื™ื ืžืื•ืžืชื™ื ื‘ื ื•ืกืฃ ืขืœ ื™ื“ื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช) ืื• ืœื‘ื—ื•ืจ ืžืจืื” ื—ืœื•ืคื™ (ftp.usa.openbsd. org, ftp.hostserver.de, cdn.openbsd.org). ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ืกื™ืจ ืืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ DST Root CA X3 ืฉืคื’ ืชื•ืงืคื• ืžื”ืงื•ื‘ืฅ /etc/ssl/cert.pem.
  • ื‘-DragonFly BSD, ื‘ืขื™ื•ืช ื“ื•ืžื•ืช ื ืฆืคื•ืช ื‘ืขื‘ื•ื“ื” ืขื DPorts. ื‘ืขืช ื”ืคืขืœืช ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ pkg, ืžื•ืคื™ืขื” ืฉื’ื™ืืช ืื™ืžื•ืช ืื™ืฉื•ืจ. ื”ืชื™ืงื•ืŸ ื ื•ืกืฃ ื”ื™ื•ื ืœืกื ื™ืคื™ ื”ืžืืกื˜ืจ, DragonFly_RELEASE_6_0 ื•-DragonFly_RELEASE_5_8. ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ืชื•ื›ืœ ืœื”ืกื™ืจ ืืช ืื™ืฉื•ืจ DST Root CA X3.
  • ืชื”ืœื™ืš ื”ืื™ืžื•ืช ืฉืœ ืชืขื•ื“ื•ืช Let's Encrypt ื‘ืืคืœื™ืงืฆื™ื•ืช ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืคืœื˜ืคื•ืจืžืช Electron ืฉื‘ื•ืจ. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืขื“ื›ื•ื ื™ื 12.2.1, 13.5.1, 14.1.0, 15.1.0.
  • ืœื”ืคืฆื•ืช ืžืกื•ื™ืžื•ืช ื™ืฉ ื‘ืขื™ื•ืช ื‘ื’ื™ืฉื” ืœืžืื’ืจื™ ื”ื—ื‘ื™ืœื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช APT ื”ืžืฉื•ื™ืš ืœื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ ืกืคืจื™ื™ืช GnuTLS. ื“ื‘ื™ืืŸ 9 ื”ื•ืฉืคืขื” ืžื”ื‘ืขื™ื”, ืฉื”ืฉืชืžืฉื” ื‘ื—ื‘ื™ืœืช GnuTLS ืœื ืžืชื•ืงื ืช, ืžื” ืฉื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ื‘ื’ื™ืฉื” ืœ-deb.debian.org ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืฉืœื ื”ืชืงื™ื ื• ืืช ื”ืขื“ื›ื•ืŸ ื‘ื–ืžืŸ (ื”ืชื™ืงื•ืŸ gnutls28-3.5.8-5+deb9u6 ื”ื•ืฆืข ื‘-17 ื‘ืกืคื˜ืžื‘ืจ). ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ืžื•ืžืœืฅ ืœื”ืกื™ืจ ืืช DST_Root_CA_X3.crt ืžื”ืงื•ื‘ืฅ /etc/ca-certificates.conf.
  • ืคืขื•ืœืช acme-client ื‘ืขืจื›ืช ื”ื”ืคืฆื” ืœื™ืฆื™ืจืช ื—ื•ืžื•ืช ืืฉ OPNsense ื”ื•ืคืจืขื”, ื”ื‘ืขื™ื” ื“ื•ื•ื—ื” ืžืจืืฉ, ืืš ื”ืžืคืชื—ื™ื ืœื ื”ืฆืœื™ื—ื• ืœืฉื—ืจืจ ืชื™ืงื•ืŸ ื‘ื–ืžืŸ.
  • ื”ื‘ืขื™ื” ื”ืฉืคื™ืขื” ืขืœ ื—ื‘ื™ืœืช OpenSSL 1.0.2k ื‘-RHEL/CentOS 7, ืืš ืœืคื ื™ ืฉื‘ื•ืข ื ื•ืฆืจ ืขื“ื›ื•ืŸ ืœื—ื‘ื™ืœืช ca-certificates-7-7.el2021.2.50_72.noarch ืขื‘ื•ืจ RHEL 7 ื•-CentOS 9, ืฉืžืžื ื• IdenTrust ืื™ืฉื•ืจ ื”ื•ืกืจ, ื›ืœื•ืžืจ. ื‘ื™ื˜ื•ื™ ื”ื‘ืขื™ื” ื ื—ืกื ืžืจืืฉ. ืขื“ื›ื•ืŸ ื“ื•ืžื” ืคื•ืจืกื ืœืคื ื™ ืฉื‘ื•ืข ืขื‘ื•ืจ ืื•ื‘ื•ื ื˜ื• 16.04, ืื•ื‘ื•ื ื˜ื• 14.04, ืื•ื‘ื•ื ื˜ื• 21.04, ืื•ื‘ื•ื ื˜ื• 20.04 ื•ืื•ื‘ื•ื ื˜ื• 18.04. ืžื›ื™ื•ื•ืŸ ืฉื”ืขื“ื›ื•ื ื™ื ืฉื•ื—ืจืจื• ืžืจืืฉ, ื”ื‘ืขื™ื” ื‘ื‘ื“ื™ืงืช ืื™ืฉื•ืจื™ Let's Encrypt ืคื’ืขื” ืจืง ื‘ืžืฉืชืžืฉื™ื ืฉืœ ืกื ื™ืคื™ื ื™ืฉื ื™ื ื™ื•ืชืจ ืฉืœ RHEL/CentOS ื•ืื•ื‘ื•ื ื˜ื• ืฉืื™ื ื ืžืชืงื™ื ื™ื ืขื“ื›ื•ื ื™ื ื‘ืื•ืคืŸ ืงื‘ื•ืข.
  • ืชื”ืœื™ืš ืื™ืžื•ืช ื”ืื™ืฉื•ืจ ื‘-grpc ืฉื‘ื•ืจ.
  • ื‘ื ื™ื™ืช ืคืœื˜ืคื•ืจืžืช Cloudflare Pages ื ื›ืฉืœื”.
  • ื‘ืขื™ื•ืช ื‘ืฉื™ืจื•ืชื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ืืžื–ื•ืŸ (AWS).
  • ืœืžืฉืชืžืฉื™ DigitalOcean ื™ืฉ ื‘ืขื™ื•ืช ื‘ื—ื™ื‘ื•ืจ ืœืžืกื“ ื”ื ืชื•ื ื™ื.
  • ืคืœื˜ืคื•ืจืžืช ื”ืขื ืŸ ืฉืœ Netlify ืงืจืกื”.
  • ื‘ืขื™ื•ืช ื‘ื’ื™ืฉื” ืœืฉื™ืจื•ืชื™ Xero.
  • ื ื™ืกื™ื•ืŸ ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ TLS ืœ-Web API ืฉืœ ืฉื™ืจื•ืช MailGun ื ื›ืฉืœ.
  • ืงืจื™ืกื•ืช ื‘ื’ืจืกืื•ืช macOS ื•-iOS (11, 13, 14), ืืฉืจ ื‘ืื•ืคืŸ ืชื™ืื•ืจื˜ื™ ืœื ื”ื™ื• ืืžื•ืจื•ืช ืœื”ื™ื•ืช ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื”.
  • ืฉื™ืจื•ืชื™ ืชืคื™ืกื” ื ื›ืฉืœื•.
  • ืฉื’ื™ืื” ื‘ืื™ืžื•ืช ืื™ืฉื•ืจื™ื ื‘ืขืช ื’ื™ืฉื” ืœ-PostMan API.
  • ื—ื•ืžืช ื”ืืฉ ืฉืœ Guardian ืงืจืกื”.
  • ื“ืฃ ื”ืชืžื™ื›ื” ืฉืœ monday.com ืฉื‘ื•ืจ.
  • ืคืœื˜ืคื•ืจืžืช Cerb ืงืจืกื”.
  • ื‘ื“ื™ืงืช ื–ืžืŸ ื”ืคืขื•ืœื” ื ื›ืฉืœื” ื‘-Google Cloud Monitoring.
  • ื‘ืขื™ื” ื‘ืื™ืžื•ืช ืื™ืฉื•ืจ ื‘-Cisco Umbrella Secure Web Gateway.
  • ื‘ืขื™ื•ืช ื‘ื—ื™ื‘ื•ืจ ืœืฉืœื™ื—ื™ Bluecoat ื•-Palo Alto.
  • OVHcloud ื ืชืงืœ ื‘ื‘ืขื™ื•ืช ื‘ื—ื™ื‘ื•ืจ ืœ- OpenStack API.
  • ื‘ืขื™ื•ืช ื‘ื™ืฆื™ืจืช ื“ื•ื—ื•ืช ื‘-Shopify.
  • ื™ืฉ ื‘ืขื™ื•ืช ื‘ื’ื™ืฉื” ืœ-Heroku API.
  • Ledger Live Manager ืงื•ืจืก.
  • ืฉื’ื™ืืช ืื™ืžื•ืช ืื™ืฉื•ืจ ื‘ื›ืœื™ื ืœืžืคืชื—ื™ ืืคืœื™ืงืฆื™ื•ืช ืฉืœ ืคื™ื™ืกื‘ื•ืง.
  • ื‘ืขื™ื•ืช ื‘-Sophos SG UTM.
  • ื‘ืขื™ื•ืช ืขื ืื™ืžื•ืช ืชืขื•ื“ื” ื‘-cPanel.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”