author: kx <kx@radix.pro> 2023-04-09 23:18:24 +0300
committer: kx <kx@radix.pro> 2023-04-09 23:18:24 +0300
commit: 8b7e76c7ad2445c0920e9d056728f7b6baaa0c43
parent: 3dd1914515dc5c714451bc4148f0abb51672ed06
Commit Summary:
Diffstat:
5 files changed, 109 insertions, 0 deletions
diff --git a/packages/n/ca-certificates/cacert.org/Makefile b/packages/n/ca-certificates/cacert.org/Makefile
new file mode 100644
index 0000000..b3a5f1d
--- /dev/null
+++ b/packages/n/ca-certificates/cacert.org/Makefile
@@ -0,0 +1,46 @@
+
+cacert_home = http://www.cacert.org/index.php?id=3
+cacert_url = http://www.cacert.org/certs
+cacert_files = root class3
+cacert_suffixes = crt der txt
+cacert_asc = cacert.asc
+
+ID = 65D0FD58
+signatures = sign/cacert-fingerprint.txt sign/cacert-gpg-fingerprint.txt
+
+tarball = cacert.tar.xz
+suffix = $(shell echo $(tarball) | cut -f 2,3 -d '.')
+sha1s = $(addsuffix .sha1sum, $(tarball))
+
+files = $(foreach sfx, $(cacert_suffixes), $(addsuffix .$(sfx),$(cacert_files)))
+files += $(cacert_asc)
+
+all: $(tarball) $(sha1s)
+
+.PHONY: verify downloads_clean
+
+
+$(files):
+ @echo -e "\n======= Downloading cacert.org certificates =======\n"
+ @for file in $(files) ; do \
+ wget -N $(cacert_url)/$$file ; \
+ done
+
+$(tarball): $(files)
+ @( directory=`echo $(tarball) | cut -f 1 -d '.'` ; \
+ mkdir -p $$directory ; \
+ cp -a sign $$directory ; \
+ cp -a README *.crt *.der *.txt *.asc $$directory ; \
+ tar cJvf $(tarball) $$directory ; \
+ rm -rf $$directory ; \
+ rm -f *.crt *.der *.txt *.asc ; \
+ )
+
+$(sha1s): %.$(suffix).sha1sum : %.$(suffix)
+ @for tarball in $< ; do \
+ echo -e "\n======= Calculation the '$$tarball' sha1sum =======\n" ; \
+ sha1sum --binary $$tarball > $$tarball.sha1sum ; \
+ done
+
+downloads_clean:
+ @rm -f $(tarball) $(sha1s) *.crt *.der *.txt *.asc *.gpg
diff --git a/packages/n/ca-certificates/cacert.org/README b/packages/n/ca-certificates/cacert.org/README
new file mode 100644
index 0000000..196fc7e
--- /dev/null
+++ b/packages/n/ca-certificates/cacert.org/README
@@ -0,0 +1,31 @@
+
+Confirmed the certificate fingerprint:
+=====================================
+
+$ openssl x509 -in root.crt -fingerprint -noout -sha1
+SHA1 Fingerprint=13:5C:EC:36:F4:9C:B8:E9:3B:1A:B2:70:CD:80:88:46:76:CE:8F:33
+
+$ openssl x509 -in root.crt -fingerprint -noout -md5
+MD5 Fingerprint=A6:1B:37:5E:39:0D:9C:36:54:EE:BD:20:31:46:1F:6B
+
+
+$ openssl x509 -in class3.crt -fingerprint -noout -sha1
+SHA1 Fingerprint=AD:7C:3F:64:FC:44:39:FE:F4:E9:0B:E8:F4:7C:6C:FA:8A:AD:FD:CE
+
+$ openssl x509 -in class3.crt -fingerprint -noout -md5
+MD5 Fingerprint=F7:25:12:82:4E:67:B5:D0:8D:92:B7:7C:0B:86:7A:42
+
+
+$ LANG=C gpg --verify sign/cacert-fingerprint.txt
+gpg: Signature made Thu Sep 4 00:57:45 2003 CDT using DSA key ID 65D0FD58
+gpg: Good signature from "CA Cert Signing Authority (Root CA) <gpg@cacert.org>"
+gpg: WARNING: This key is not certified with a trusted signature!
+gpg: There is no indication that the signature belongs to the owner.
+Primary key fingerprint: A31D 4F81 EF4E BD07 B456 FA04 D2BB 0D01 65D0 FD58
+
+$ LANG=C gpg --verify sign/cacert-gpg-fingerprint.txt
+gpg: Signature made Sun Feb 13 23:10:37 2005 CST using DSA key ID 65D0FD58
+gpg: Good signature from "CA Cert Signing Authority (Root CA) <gpg@cacert.org>"
+gpg: WARNING: This key is not certified with a trusted signature!
+gpg: There is no indication that the signature belongs to the owner.
+Primary key fingerprint: A31D 4F81 EF4E BD07 B456 FA04 D2BB 0D01 65D0 FD58
diff --git a/packages/n/ca-certificates/cacert.org/sign/README b/packages/n/ca-certificates/cacert.org/sign/README
new file mode 100644
index 0000000..cb4529f
--- /dev/null
+++ b/packages/n/ca-certificates/cacert.org/sign/README
@@ -0,0 +1,40 @@
+
+Signatures 'cacert-fingerprint.asc' and 'cacert-gpg-fingerprint.asc'
+are taken from http://www.cacert.org/index.php?id=3 WEB page:
+============================================================
+
+GPG Key ID: 0x65D0FD58
+Fingerprint: A31D 4F81 EF4E BD07 B456 FA04 D2BB 0D01 65D0 FD58
+
+PKI fingerprint signed by the CAcert GPG Key
+
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+For most software, the fingerprint is reported as:
+A6:1B:37:5E:39:0D:9C:36:54:EE:BD:20:31:46:1F:6B
+
+Under MSIE the thumbprint is reported as:
+135C EC36 F49C B8E9 3B1A B270 CD80 8846 76CE 8F33
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.2.2 (GNU/Linux)
+
+iD8DBQE/VtRZ0rsNAWXQ/VgRAphfAJ9jh6TKBDexG0NTTUHvdNuf6O9RuQCdE5kD
+Mch2LMZhK4h/SBIft5ROzVU=
+=R/pJ
+-----END PGP SIGNATURE-----
+
+
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+pub 1024D/65D0FD58 2003-07-11 CA Cert Signing Authority (Root CA)
+ Key fingerprint = A31D 4F81 EF4E BD07 B456 FA04 D2BB 0D01 65D0 FD58
+sub 2048g/113ED0F2 2003-07-11 [expires: 2033-07-03]
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.2.5 (GNU/Linux)
+
+iD8DBQFCEDLN0rsNAWXQ/VgRArhhAJ9EY1TJOzsVVuy2lL98CoKL0vnJjQCfbdBk
+TG1yj+lkktROGGyn0hJ5SbM=
+=tXoj
+-----END PGP SIGNATURE-----
diff --git a/packages/n/ca-certificates/cacert.org/sign/cacert-fingerprint.txt b/packages/n/ca-certificates/cacert.org/sign/cacert-fingerprint.txt
new file mode 100644
index 0000000..5b0a358
--- /dev/null
+++ b/packages/n/ca-certificates/cacert.org/sign/cacert-fingerprint.txt
@@ -0,0 +1,15 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+For most software, the fingerprint is reported as:
+A6:1B:37:5E:39:0D:9C:36:54:EE:BD:20:31:46:1F:6B
+
+Under MSIE the thumbprint is reported as:
+135C EC36 F49C B8E9 3B1A B270 CD80 8846 76CE 8F33
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.2.2 (GNU/Linux)
+
+iD8DBQE/VtRZ0rsNAWXQ/VgRAphfAJ9jh6TKBDexG0NTTUHvdNuf6O9RuQCdE5kD
+Mch2LMZhK4h/SBIft5ROzVU=
+=R/pJ
+-----END PGP SIGNATURE-----
diff --git a/packages/n/ca-certificates/cacert.org/sign/cacert-gpg-fingerprint.txt b/packages/n/ca-certificates/cacert.org/sign/cacert-gpg-fingerprint.txt
new file mode 100644
index 0000000..33d2868
--- /dev/null
+++ b/packages/n/ca-certificates/cacert.org/sign/cacert-gpg-fingerprint.txt
@@ -0,0 +1,13 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+pub 1024D/65D0FD58 2003-07-11 CA Cert Signing Authority (Root CA)
+ Key fingerprint = A31D 4F81 EF4E BD07 B456 FA04 D2BB 0D01 65D0 FD58
+sub 2048g/113ED0F2 2003-07-11 [expires: 2033-07-03]
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.2.5 (GNU/Linux)
+
+iD8DBQFCEDLN0rsNAWXQ/VgRArhhAJ9EY1TJOzsVVuy2lL98CoKL0vnJjQCfbdBk
+TG1yj+lkktROGGyn0hJ5SbM=
+=tXoj
+-----END PGP SIGNATURE-----