Before every release, ideally just before the freeze, we need to regenerate the iOS bundled roots.
This issue should not be closed but moved to the next milestone at each update.
The code generator currently parses an HTML table, but @sleevi pointed out the roots are published in the macOS/iOS sources, which is easier to process.
https://opensource.apple.com/source/security_certificates/security_certificates-55161.60.2/certificates/roots/
https://opensource.apple.com/tarballs/security_certificates/security_certificates-55161.60.2.tar.gz
The security_certificates version is available from the index text file, because all directory listings on opensource.apple.com are out of date. (Note how there currently is no security_certificates-55161.60.2 in https://opensource.apple.com/source/security_certificates/.)
https://opensource.apple.com/text/macos-10152.txt
Before every release, ideally just before the freeze, we need to regenerate the iOS bundled roots.
This issue should not be closed but moved to the next milestone at each update.
The code generator currently parses an HTML table, but @sleevi pointed out the roots are published in the macOS/iOS sources, which is easier to process.
https://opensource.apple.com/source/security_certificates/security_certificates-55161.60.2/certificates/roots/
https://opensource.apple.com/tarballs/security_certificates/security_certificates-55161.60.2.tar.gz
The security_certificates version is available from the index text file, because all directory listings on opensource.apple.com are out of date. (Note how there currently is no
security_certificates-55161.60.2in https://opensource.apple.com/source/security_certificates/.)https://opensource.apple.com/text/macos-10152.txt