NetBSD-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

SSL root certificates in base system?



Hi,

Is there a better way to install and update trusted root certificates in NetBSD? The recommendation of using security/mozilla-rootcerts from pkgsrc isn't a good one; first, it assumes that a system has NO other certificates (/etc/openssl/certs/ must be empty), and second, it leaves a mess in /etc/openssl/certs/, then creates /etc/ssl/certs/ca-certificates.crt, which programs don't use by default.

Should people and programs be using /etc/ssl/certs/, or /etc/openssl/certs/? Why would mozilla-rootcerts use both? This doesn't seem to make sense.

John


Home | Main Index | Thread Index | Old Index