Skip to content

crypto/x509: update bundled iOS roots #38843

Description

@FiloSottile

Before every release, ideally just before the freeze, we need to regenerate the iOS bundled roots.

This issue should not be closed but moved to the next milestone at each update.


The code generator currently parses an HTML table, but @sleevi pointed out the roots are published in the macOS/iOS sources, which is easier to process.

https://opensource.apple.com/source/security_certificates/security_certificates-55161.60.2/certificates/roots/

https://opensource.apple.com/tarballs/security_certificates/security_certificates-55161.60.2.tar.gz

The security_certificates version is available from the index text file, because all directory listings on opensource.apple.com are out of date. (Note how there currently is no security_certificates-55161.60.2 in https://opensource.apple.com/source/security_certificates/.)

https://opensource.apple.com/text/macos-10152.txt

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    FrozenDueToAgeNeedsFixThe path to resolution is known, but the work has not been done.okay-after-beta1Used by release team to mark a release-blocker issue as okay to resolve either before or after beta1recurringIssues that should never be closed, but moved to the next milestone once fixed in the current one.release-blocker

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions