Skip to content

Release/2025.7.2 - #341

Merged
mitch292 merged 2 commits into
masterfrom
release/2025.7.2
Jul 9, 2025
Merged

Release/2025.7.2#341
mitch292 merged 2 commits into
masterfrom
release/2025.7.2

Conversation

@mitch292

@mitch292 mitch292 commented Jul 8, 2025

Copy link
Copy Markdown
Contributor

Output of script run

cf-repos/cfssl_trust [mitch292/sectigo-r46●] » NEW_ROOTS="./new-root.crt" NEW_INTERMEDIATES="./new-ints.crt" ./release.sh
+ CONFIG_PATH=
+ '[' -n '' ']'
+ DATABASE_PATH=./cert.db
+ '[' -n ./cert.db ']'
+ DATABASE_PATH='-d ./cert.db'
+ EXPIRATION_WINDOW=0h
+ prologue
+ check_for_tool cfssl-trust
+ command -v cfssl-trust
+ '[' 0 -ne 0 ']'
+ check_for_tool certdump
+ command -v certdump
+ '[' 0 -ne 0 ']'
+ check_for_tool mktemp
+ command -v mktemp
+ '[' 0 -ne 0 ']'
++ git rev-parse --show-toplevel
+ cd /Users/andrew/cf-repos/cfssl_trust
+ execute
++ mktemp
+ TEMPFILE=/var/folders/8p/5ldzyl2j001gxxjfbtw8d5pr0000gp/T/tmp.LX1jLoQhfc
+ release
+ tee /var/folders/8p/5ldzyl2j001gxxjfbtw8d5pr0000gp/T/tmp.LX1jLoQhfc
+++ pwd
++ basename /Users/andrew/cf-repos/cfssl_trust
+ '[' cfssl_trust '!=' cfssl_trust ']'
++ pwd
++ git rev-parse --show-toplevel
+ '[' /Users/andrew/cf-repos/cfssl_trust '!=' /Users/andrew/cf-repos/cfssl_trust ']'
++ date +%FT%T%z
+ echo 'Rolling trust store release at 2025-07-08T16:29:57-0400.'
+ echo '$ cfssl-trust -d ./cert.db  -b int release 0h'
+ cfssl-trust -d ./cert.db -b int release 0h
Rolling trust store release at 2025-07-08T16:29:57-0400.
$ cfssl-trust -d ./cert.db  -b int release 0h
1317 certificates rolled
0 certificates skipped
Successfully rolled new int release 2025.7.2
++ cfssl-trust -d ./cert.db releases
++ awk ' NR==1 { print $2 }'
+ LATEST_RELEASE=2025.7.2
+ echo '$ cfssl-trust -d ./cert.db  -b ca release 0h'
+ cfssl-trust -d ./cert.db -b ca release 0h
$ cfssl-trust -d ./cert.db  -b ca release 0h
347 certificates rolled
0 certificates skipped
Successfully rolled new ca release 2025.7.2
+ '[' -n ./new-root.crt ']'
+ echo 'Adding new roots:'
+ certdump ./new-root.crt
Adding new roots:
--./new-root.crt ---
CERTIFICATE
Subject: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-4096
	Serial number: 156256931880233212765902055439220583700
	SKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	Valid from: 2021-03-22T00:00:00+0000
	     until: 2046-03-21T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Basic constraints: valid, is a CA certificate
	SANs (0):
+ cfssl-trust -d ./cert.db -b ca -r 2025.7.2 import ./new-root.crt
selected release 2025.7.2
- importing serial 156256931880233212765902055439220583700 SKI 5673586495f9921ab0122a046279a14015882149
+ '[' -n ./new-ints.crt ']'
+ echo 'Adding new intermediates:'
+ certdump ./new-ints.crt
Adding new intermediates:
--./new-ints.crt ---
CERTIFICATE
Subject: /Entrust OV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 172838154427687735430042424616462326861
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 17:D1:AF:00:74:F9:55:FB:52:37:D8:84:76:0B:5B:12:8A:50:5A:C5
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust DV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 14403217535373145338590986297320592700
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 8D:42:49:37:40:B9:47:95:80:98:BE:A9:B9:3A:6B:F0:CD:96:A1:83
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust EV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 254151669218637103585409482530369551934
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: C1:B1:A1:FD:27:35:8E:C8:71:02:9E:7A:93:06:39:64:66:E6:6A:9D
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
+ cfssl-trust -d ./cert.db -b int -r 2025.7.2 import ./new-ints.crt
selected release 2025.7.2
- importing serial 172838154427687735430042424616462326861 SKI 17d1af0074f955fb5237d884760b5b128a505ac5
- importing serial 14403217535373145338590986297320592700 SKI 8d42493740b947958098bea9b93a6bf0cd96a183
- importing serial 254151669218637103585409482530369551934 SKI c1b1a1fd27358ec871029e7a9306396466e66a9d
+ git add cert.db
+ echo '$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b int bundle int-bundle.crt'
+ cfssl-trust -d ./cert.db -r 2025.7.2 -b int bundle int-bundle.crt
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b int bundle int-bundle.crt
selected release 2025.7.2
Selected 1317 certificates for this release.
+ echo '$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b ca bundle ca-bundle.crt'
+ cfssl-trust -d ./cert.db -r 2025.7.2 -b ca bundle ca-bundle.crt
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b ca bundle ca-bundle.crt
selected release 2025.7.2
Selected 347 certificates for this release.
./release.sh: line 147: ALLOW_SKIP_PR: unbound variable
+ grep -q No_Changes /var/folders/8p/5ldzyl2j001gxxjfbtw8d5pr0000gp/T/tmp.LX1jLoQhfc
++ cfssl-trust -d ./cert.db releases
++ awk ' NR==1 { print $2 }'
+ LATEST_RELEASE=2025.7.2
+ git checkout -b release/2025.7.2
Switched to a new branch 'release/2025.7.2'
+ git commit -F-
++ cat /var/folders/8p/5ldzyl2j001gxxjfbtw8d5pr0000gp/T/tmp.LX1jLoQhfc
+ printf 'Trust store release 2025.7.2\n\nRolling trust store release at 2025-07-08T16:29:57-0400.
$ cfssl-trust -d ./cert.db  -b int release 0h
1317 certificates rolled
0 certificates skipped
Successfully rolled new int release 2025.7.2
$ cfssl-trust -d ./cert.db  -b ca release 0h
347 certificates rolled
0 certificates skipped
Successfully rolled new ca release 2025.7.2
Adding new roots:
--./new-root.crt ---
CERTIFICATE
Subject: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-4096
	Serial number: 156256931880233212765902055439220583700
	SKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	Valid from: 2021-03-22T00:00:00+0000
	     until: 2046-03-21T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Basic constraints: valid, is a CA certificate
	SANs (0):
selected release 2025.7.2
- importing serial 156256931880233212765902055439220583700 SKI 5673586495f9921ab0122a046279a14015882149
Adding new intermediates:
--./new-ints.crt ---
CERTIFICATE
Subject: /Entrust OV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 172838154427687735430042424616462326861
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 17:D1:AF:00:74:F9:55:FB:52:37:D8:84:76:0B:5B:12:8A:50:5A:C5
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust DV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 14403217535373145338590986297320592700
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 8D:42:49:37:40:B9:47:95:80:98:BE:A9:B9:3A:6B:F0:CD:96:A1:83
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust EV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 254151669218637103585409482530369551934
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: C1:B1:A1:FD:27:35:8E:C8:71:02:9E:7A:93:06:39:64:66:E6:6A:9D
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
selected release 2025.7.2
- importing serial 172838154427687735430042424616462326861 SKI 17d1af0074f955fb5237d884760b5b128a505ac5
- importing serial 14403217535373145338590986297320592700 SKI 8d42493740b947958098bea9b93a6bf0cd96a183
- importing serial 254151669218637103585409482530369551934 SKI c1b1a1fd27358ec871029e7a9306396466e66a9d
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b int bundle int-bundle.crt
selected release 2025.7.2
Selected 1317 certificates for this release.
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b ca bundle ca-bundle.crt
selected release 2025.7.2
Selected 347 certificates for this release.'
[release/2025.7.2 183129c] Trust store release 2025.7.2
 1 file changed, 0 insertions(+), 0 deletions(-)
+ rm /var/folders/8p/5ldzyl2j001gxxjfbtw8d5pr0000gp/T/tmp.LX1jLoQhfc
+ git tag trust-store-2025.7.2
+ '[' -n '' ']'
+ git push --set-upstream origin release/2025.7.2
Enumerating objects: 5, done.
Counting objects: 100% (5/5), done.
Delta compression using up to 10 threads
Compressing objects: 100% (3/3), done.
Writing objects: 100% (3/3), 257.99 KiB | 587.00 KiB/s, done.
Total 3 (delta 2), reused 0 (delta 0), pack-reused 0
remote: Resolving deltas: 100% (2/2), completed with 2 local objects.
remote:
remote: Create a pull request for 'release/2025.7.2' on GitHub by visiting:
remote:      https://github.com/cloudflare/cfssl_trust/pull/new/release/2025.7.2
remote:
remote: GitHub found 2 vulnerabilities on cloudflare/cfssl_trust's default branch (2 moderate). To find out more, visit:
remote:      https://github.com/cloudflare/cfssl_trust/security/dependabot
remote:
To github.com:cloudflare/cfssl_trust.git
 * [new branch]      release/2025.7.2 -> release/2025.7.2
branch 'release/2025.7.2' set up to track 'origin/release/2025.7.2'.
+ git push origin trust-store-2025.7.2
Total 0 (delta 0), reused 0 (delta 0), pack-reused 0
To github.com:cloudflare/cfssl_trust.git
 * [new tag]         trust-store-2025.7.2 -> trust-store-2025.7.2

mitch292 added 2 commits July 8, 2025 16:17
Rolling trust store release at 2025-07-08T16:29:57-0400.
$ cfssl-trust -d ./cert.db  -b int release 0h
1317 certificates rolled
0 certificates skipped
Successfully rolled new int release 2025.7.2
$ cfssl-trust -d ./cert.db  -b ca release 0h
347 certificates rolled
0 certificates skipped
Successfully rolled new ca release 2025.7.2
Adding new roots:
--./new-root.crt ---
CERTIFICATE
Subject: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-4096
	Serial number: 156256931880233212765902055439220583700
	SKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	Valid from: 2021-03-22T00:00:00+0000
	     until: 2046-03-21T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Basic constraints: valid, is a CA certificate
	SANs (0):
selected release 2025.7.2
- importing serial 156256931880233212765902055439220583700 SKI 5673586495f9921ab0122a046279a14015882149
Adding new intermediates:
--./new-ints.crt ---
CERTIFICATE
Subject: /Entrust OV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 172838154427687735430042424616462326861
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 17:D1:AF:00:74:F9:55:FB:52:37:D8:84:76:0B:5B:12:8A:50:5A:C5
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust DV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 14403217535373145338590986297320592700
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: 8D:42:49:37:40:B9:47:95:80:98:BE:A9:B9:3A:6B:F0:CD:96:A1:83
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
CERTIFICATE
Subject: /Entrust EV TLS Issuing RSA CA 2/C=CA/O=Entrust Limited
Issuer: /Sectigo Public Server Authentication Root R46/C=GB/O=Sectigo Limited
	Signature algorithm: RSA / SHA384
Details:
	Public key: RSA-3072
	Serial number: 254151669218637103585409482530369551934
	AKI: 56:73:58:64:95:F9:92:1A:B0:12:2A:04:62:79:A1:40:15:88:21:49
	SKI: C1:B1:A1:FD:27:35:8E:C8:71:02:9E:7A:93:06:39:64:66:E6:6A:9D
	Valid from: 2024-12-11T00:00:00+0000
	     until: 2027-12-10T23:59:59+0000
	Key usages: cert sign, crl sign, digital signature
	Extended usages: client auth, server auth
	Basic constraints: valid, is a CA certificate, max path length 0
	SANs (0):
	1 AIA:
		http://crt.sectigo.com/SectigoPublicServerAuthenticationRootR46.p7c
	OCSP server:
		- http://ocsp.sectigo.com
selected release 2025.7.2
- importing serial 172838154427687735430042424616462326861 SKI 17d1af0074f955fb5237d884760b5b128a505ac5
- importing serial 14403217535373145338590986297320592700 SKI 8d42493740b947958098bea9b93a6bf0cd96a183
- importing serial 254151669218637103585409482530369551934 SKI c1b1a1fd27358ec871029e7a9306396466e66a9d
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b int bundle int-bundle.crt
selected release 2025.7.2
Selected 1317 certificates for this release.
$ cfssl-trust -d ./cert.db  -r 2025.7.2 -b ca bundle ca-bundle.crt
selected release 2025.7.2
Selected 347 certificates for this release.
@mitch292
mitch292 requested review from dt-dtran and lgarofalo July 8, 2025 20:33
@mitch292 mitch292 self-assigned this Jul 8, 2025
@mitch292
mitch292 merged commit b3f09cd into master Jul 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants