Testing against a new build for jessie, it looks as if the ca-certificates-java hook does nothing with new CA certificate additions, either? None of the newly added CAs appear to have made it to the keystore upon package upgrade, but were added in --fresh. It appears the hook is not doing the right thing in either add/remove case.
Just wanted to let you know I've taken a quick look, but I'm not sure what the real issue is, at this moment. (test stdout attached) -- Kind regards, Michael
mshuler@hana:~$ sudo apt-get install ca-certificates=20141019+deb8u4 Reading package lists... Done Building dependency tree Reading state information... Done The following packages will be upgraded: ca-certificates 1 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. Need to get 196 kB of archives. After this operation, 70.7 kB of additional disk space will be used. WARNING: The following packages cannot be authenticated! ca-certificates Install these packages without verification? [y/N] y Get:1 http://www.pbandjelly.org/debian/ ./ ca-certificates 20141019+deb8u4 [196 kB] Fetched 196 kB in 0s (1,513 kB/s) Reading changelogs... Done Preconfiguring packages ... (Reading database ... 278491 files and directories currently installed.) Preparing to unpack .../ca-certificates_20141019+deb8u4_all.deb ... Unpacking ca-certificates (20141019+deb8u4) over (20141019+deb8u3) ... Processing triggers for man-db (2.7.0.2-5) ... Setting up ca-certificates (20141019+deb8u4) ... Updating certificates in /etc/ssl/certs... 12 added, 24 removed; done. Processing triggers for ca-certificates (20141019+deb8u4) ... Updating certificates in /etc/ssl/certs... 0 added, 0 removed; done. Running hooks in /etc/ca-certificates/update.d.... done. done. mshuler@hana:~$ mshuler@hana:~$ mshuler@hana:~$ sudo update-ca-certificates --fresh --verbose Clearing symlinks in /etc/ssl/certs...done. Updating certificates in /etc/ssl/certs... Doing . SwissSign_Silver_CA_-_G2.pem => 57bcb2da.0 SwissSign_Silver_CA_-_G2.pem => 5046c355.0 Entrust_Root_Certification_Authority.pem => 6b99d060.0 Entrust_Root_Certification_Authority.pem => bf64f35b.0 AC_RAIZ_FNMT-RCM.pem => cd8c0d63.0 AC_RAIZ_FNMT-RCM.pem => b936d1c6.0 Entrust_Root_Certification_Authority_-_G2.pem => 02265526.0 Entrust_Root_Certification_Authority_-_G2.pem => 455f1b52.0 T-TeleSec_GlobalRoot_Class_2.pem => 1e09d511.0 T-TeleSec_GlobalRoot_Class_2.pem => d06393bb.0 SZAFIR_ROOT_CA2.pem => fe8a2cd8.0 SZAFIR_ROOT_CA2.pem => a81e292b.0 Trustis_FPS_Root_CA.pem => d853d49e.0 Trustis_FPS_Root_CA.pem => c51c224c.0 DigiCert_Trusted_Root_G4.pem => 75d1b2ed.0 DigiCert_Trusted_Root_G4.pem => a2c66da8.0 IdenTrust_Commercial_Root_CA_1.pem => ef954a4e.0 IdenTrust_Commercial_Root_CA_1.pem => d18e9066.0 ssl-cert-snakeoil.pem => 2781bb9b.0 ssl-cert-snakeoil.pem => 548bcbf5.0 TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem => ff34af3f.0 TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem => 31188b5e.0 SwissSign_Gold_CA_-_G2.pem => 4f316efb.0 SwissSign_Gold_CA_-_G2.pem => 3c860d51.0 DigiCert_Global_Root_G2.pem => 607986c7.0 DigiCert_Global_Root_G2.pem => c90bc37d.0 CFCA_EV_ROOT.pem => 0b1b94ef.0 CFCA_EV_ROOT.pem => 9282e51c.0 Global_Chambersign_Root_-_2008.pem => 0c4c9b6c.0 Global_Chambersign_Root_-_2008.pem => 9f533518.0 Network_Solutions_Certificate_Authority.pem => 4304c5e5.0 Network_Solutions_Certificate_Authority.pem => 2fa87019.0 Swisscom_Root_CA_1.pem => 667c66d4.0 Swisscom_Root_CA_1.pem => e60bf0c0.0 GlobalSign_Root_CA.pem => 5ad8a5d6.0 GlobalSign_Root_CA.pem => b0f3e76e.0 AddTrust_Qualified_Certificates_Root.pem => e536d871.0 AddTrust_Qualified_Certificates_Root.pem => 052e396b.0 GlobalSign_ECC_Root_CA_-_R5.pem => 1d3472b9.0 GlobalSign_ECC_Root_CA_-_R5.pem => 2add47b6.0 GeoTrust_Primary_Certification_Authority_-_G3.pem => e2799e36.0 GeoTrust_Primary_Certification_Authority_-_G3.pem => c7e2a638.0 DigiCert_Global_Root_G3.pem => dd8e9d41.0 DigiCert_Global_Root_G3.pem => ed39abd0.0 Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem => 1320b215.0 Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem => 0708417d.0 Entrust_Root_Certification_Authority_-_EC1.pem => 106f3e4d.0 Entrust_Root_Certification_Authority_-_EC1.pem => b3fb433b.0 AffirmTrust_Premium.pem => b727005e.0 AffirmTrust_Premium.pem => dbc54cab.0 Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem => 26312675.0 Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem => b6782d18.0 QuoVadis_Root_CA_1_G3.pem => 749e9e03.0 QuoVadis_Root_CA_1_G3.pem => 52b525c7.0 S-TRUST_Universal_Root_CA.pem => 19c1fa33.0 S-TRUST_Universal_Root_CA.pem => 631c779f.0 GeoTrust_Primary_Certification_Authority_-_G2.pem => 116bf586.0 GeoTrust_Primary_Certification_Authority_-_G2.pem => 27af790d.0 TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem => 65b876bd.0 TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem => 418595b9.0 SecureSign_RootCA11.pem => 18856ac4.0 SecureSign_RootCA11.pem => ab5346f4.0 Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem => 4d4ba017.0 Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem => 8951b75e.0 Certum_Trusted_Network_CA.pem => 48bec511.0 Certum_Trusted_Network_CA.pem => 95aff9e3.0 Amazon_Root_CA_3.pem => 8cb5ee0f.0 Amazon_Root_CA_3.pem => 7a7c655d.0 DigiCert_Assured_ID_Root_CA.pem => b1159c4c.0 DigiCert_Assured_ID_Root_CA.pem => 69105f4f.0 Staat_der_Nederlanden_EV_Root_CA.pem => 03179a64.0 Staat_der_Nederlanden_EV_Root_CA.pem => 3c6676aa.0 Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem => 1636090b.0 Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem => 40dc992e.0 GlobalSign_Root_CA_-_R3.pem => 062cdee6.0 GlobalSign_Root_CA_-_R3.pem => 1e8e7201.0 Certigna.pem => e113c810.0 Certigna.pem => fde84897.0 QuoVadis_Root_CA.pem => 080911ac.0 QuoVadis_Root_CA.pem => 5cf9d536.0 AddTrust_Low-Value_Services_Root.pem => 861a399d.0 AddTrust_Low-Value_Services_Root.pem => e268a4c5.0 Actalis_Authentication_Root_CA.pem => 930ac5d2.0 Actalis_Authentication_Root_CA.pem => 5f47b495.0 ISRG_Root_X1.pem => 4042bcee.0 ISRG_Root_X1.pem => 6187b673.0 AddTrust_Public_Services_Root.pem => 8b59b1ad.0 AddTrust_Public_Services_Root.pem => a2df7ad7.0 D-TRUST_Root_CA_3_2013.pem => 0b7c536a.0 D-TRUST_Root_CA_3_2013.pem => c6127c60.0 DigiCert_Assured_ID_Root_G2.pem => 9d04f354.0 DigiCert_Assured_ID_Root_G2.pem => 8d6437c3.0 Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem => c0ff1f52.0 Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem => 7d453d8f.0 Baltimore_CyberTrust_Root.pem => 653b494a.0 Baltimore_CyberTrust_Root.pem => 3ad48a91.0 USERTrust_RSA_Certification_Authority.pem => fc5a8f99.0 USERTrust_RSA_Certification_Authority.pem => 35105088.0 AffirmTrust_Commercial.pem => 2b349938.0 AffirmTrust_Commercial.pem => e48193cf.0 CNNIC_ROOT.pem => bd1910d4.0 CNNIC_ROOT.pem => 895cad1a.0 Certplus_Root_CA_G1.pem => 9168f543.0 Certplus_Root_CA_G1.pem => 02756ea4.0 Buypass_Class_2_Root_CA.pem => 54657681.0 Buypass_Class_2_Root_CA.pem => 82223c44.0 China_Internet_Network_Information_Center_EV_Certificates_Root.pem => 1874d4aa.0 China_Internet_Network_Information_Center_EV_Certificates_Root.pem => 1676090a.0 OISTE_WISeKey_Global_Root_GA_CA.pem => b1b8a7f3.0 OISTE_WISeKey_Global_Root_GA_CA.pem => 3a3b02ce.0 TURKTRUST_Certificate_Services_Provider_Root_2007.pem => 592c0a9a.0 TURKTRUST_Certificate_Services_Provider_Root_2007.pem => d66b55d9.0 DigiCert_Assured_ID_Root_G3.pem => 7f3d5d1d.0 DigiCert_Assured_ID_Root_G3.pem => c491639e.0 E-Tugra_Certification_Authority.pem => 5273a94c.0 E-Tugra_Certification_Authority.pem => cb156124.0 Amazon_Root_CA_4.pem => de6d66f3.0 Amazon_Root_CA_4.pem => d41b5e2a.0 Microsec_e-Szigno_Root_CA_2009.pem => 8160b96c.0 Microsec_e-Szigno_Root_CA_2009.pem => e8651083.0 AC_Raíz_Certicámara_S.A..pem => 6f2c1157.0 AC_Raíz_Certicámara_S.A..pem => c8763593.0 AffirmTrust_Premium_ECC.pem => 9c8dfbd4.0 AffirmTrust_Premium_ECC.pem => ccc52f49.0 TWCA_Root_Certification_Authority.pem => b7a5b843.0 TWCA_Root_Certification_Authority.pem => b7db1890.0 TWCA_Global_Root_CA.pem => 5f15c80c.0 TWCA_Global_Root_CA.pem => b0ed035a.0 USERTrust_ECC_Certification_Authority.pem => f30dd6ad.0 USERTrust_ECC_Certification_Authority.pem => 04f60c28.0 thawte_Primary_Root_CA.pem => 2e4eed3c.0 thawte_Primary_Root_CA.pem => 00673b5b.0 GeoTrust_Primary_Certification_Authority.pem => 480720ec.0 GeoTrust_Primary_Certification_Authority.pem => 9772ca32.0 SwissSign_Platinum_CA_-_G2.pem => a8dee976.0 SwissSign_Platinum_CA_-_G2.pem => 46b2fd3b.0 Hongkong_Post_Root_CA_1.pem => 3e45d192.0 Hongkong_Post_Root_CA_1.pem => 9685a493.0 AffirmTrust_Networking.pem => 93bc0acc.0 AffirmTrust_Networking.pem => 86212b19.0 Comodo_Secure_Services_root.pem => c9f83a1c.0 Comodo_Secure_Services_root.pem => 02b73561.0 NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem => 988a38cb.0 NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem => 60afe812.0 Staat_der_Nederlanden_Root_CA_-_G2.pem => 5c44d531.0 Staat_der_Nederlanden_Root_CA_-_G2.pem => 3d441de8.0 COMODO_ECC_Certification_Authority.pem => eed8c118.0 COMODO_ECC_Certification_Authority.pem => 89c02a45.0 QuoVadis_Root_CA_3_G3.pem => e18bfb83.0 QuoVadis_Root_CA_3_G3.pem => e442e424.0 Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem => 62744ee1.0 Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem => 43eb08c7.0 Visa_eCommerce_Root.pem => a760e1bd.0 Visa_eCommerce_Root.pem => 6fcc125d.0 LuxTrust_Global_Root_2.pem => def36a68.0 LuxTrust_Global_Root_2.pem => c907e29b.0 Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem => 3bde41ac.0 Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem => d16a5865.0 GlobalSign_ECC_Root_CA_-_R4.pem => b0e59380.0 GlobalSign_ECC_Root_CA_-_R4.pem => 0d69c7e1.0 Certum_Root_CA.pem => 442adcac.0 Certum_Root_CA.pem => 6e8bf996.0 Camerfirma_Chambers_of_Commerce_Root.pem => f90208f7.0 Camerfirma_Chambers_of_Commerce_Root.pem => ee7cd6fb.0 VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem => b204d74a.0 VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem => facacbc6.0 OpenTrust_Root_CA_G1.pem => 87229d21.0 OpenTrust_Root_CA_G1.pem => 9c3323d4.0 GeoTrust_Global_CA_2.pem => cbeee9e2.0 GeoTrust_Global_CA_2.pem => 57692373.0 Deutsche_Telekom_Root_CA_2.pem => 812e17de.0 Deutsche_Telekom_Root_CA_2.pem => 4e18c148.0 Buypass_Class_3_Root_CA.pem => e8de2f56.0 Buypass_Class_3_Root_CA.pem => 2d9dafe4.0 Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem => 32888f65.0 Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem => dc99f41e.0 DST_ACES_CA_X6.pem => 790a7190.0 DST_ACES_CA_X6.pem => 1dac3003.0 thawte_Primary_Root_CA_-_G3.pem => ba89ed3b.0 thawte_Primary_Root_CA_-_G3.pem => 67495436.0 DST_Root_CA_X3.pem => 2e5ac55d.0 DST_Root_CA_X3.pem => 12d55845.0 Entrust.net_Premium_2048_Secure_Server_CA.pem => aee5f10d.0 Entrust.net_Premium_2048_Secure_Server_CA.pem => 3e7271e8.0 VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem => 7d0b38bd.0 VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem => 5e4e69e7.0 AddTrust_External_Root.pem => 157753a5.0 AddTrust_External_Root.pem => 3c58f906.0 Go_Daddy_Root_Certificate_Authority_-_G2.pem => cbf06781.0 Go_Daddy_Root_Certificate_Authority_-_G2.pem => bc3f2570.0 D-TRUST_Root_Class_3_CA_2_EV_2009.pem => d4dae3dd.0 D-TRUST_Root_Class_3_CA_2_EV_2009.pem => d7746a63.0 Security_Communication_EV_RootCA1.pem => 9d520b32.0 Security_Communication_EV_RootCA1.pem => 9dbefe7b.0 COMODO_RSA_Certification_Authority.pem => d6325660.0 COMODO_RSA_Certification_Authority.pem => d4c339cb.0 Starfield_Class_2_CA.pem => f387163d.0 Starfield_Class_2_CA.pem => 23f4c490.0 Comodo_Trusted_Services_root.pem => 56657bde.0 Comodo_Trusted_Services_root.pem => 124bbd54.0 TC_TrustCenter_Class_3_CA_II.pem => 5620c4aa.0 TC_TrustCenter_Class_3_CA_II.pem => 7a481e66.0 EC-ACC.pem => 349f2832.0 EC-ACC.pem => aeb67534.0 Taiwan_GRCA.pem => 6410666e.0 Taiwan_GRCA.pem => 1dcd6f4c.0 Amazon_Root_CA_1.pem => ce5e74ef.0 Amazon_Root_CA_1.pem => fd08c599.0 Chambers_of_Commerce_Root_-_2008.pem => c47d9980.0 Chambers_of_Commerce_Root_-_2008.pem => 1eb37bdf.0 UTN_USERFirst_Hardware_Root_CA.pem => b13cc6df.0 UTN_USERFirst_Hardware_Root_CA.pem => ff783690.0 Certinomis_-_Autorité_Racine.pem => d957f522.0 Certinomis_-_Autorité_Racine.pem => 7672ac4b.0 EE_Certification_Centre_Root_CA.pem => 128805a3.0 EE_Certification_Centre_Root_CA.pem => 91739615.0 OpenTrust_Root_CA_G2.pem => 608a55ad.0 OpenTrust_Root_CA_G2.pem => 3929ec9f.0 Cybertrust_Global_Root.pem => 76cb8f92.0 Cybertrust_Global_Root.pem => 343eb6cb.0 Izenpe.com.pem => cc450945.0 Izenpe.com.pem => 48a195d8.0 Go_Daddy_Class_2_CA.pem => f081611a.0 Go_Daddy_Class_2_CA.pem => 219d9499.0 DigiCert_High_Assurance_EV_Root_CA.pem => 244b5494.0 DigiCert_High_Assurance_EV_Root_CA.pem => 81b9768f.0 certSIGN_ROOT_CA.pem => 8d86cdd1.0 certSIGN_ROOT_CA.pem => 882de061.0 COMODO_Certification_Authority.pem => 40547a79.0 COMODO_Certification_Authority.pem => 5a3f0ff8.0 Sonera_Class_2_Root_CA.pem => 9c2e7d30.0 Sonera_Class_2_Root_CA.pem => a7605362.0 PSCProcert.pem => c5d3212a.0 PSCProcert.pem => 8c24b137.0 ACCVRAIZ1.pem => a94d09e5.0 ACCVRAIZ1.pem => 3c9a4d3b.0 GeoTrust_Universal_CA_2.pem => 8867006a.0 GeoTrust_Universal_CA_2.pem => 87753b0d.0 QuoVadis_Root_CA_3.pem => 76faf6c0.0 QuoVadis_Root_CA_3.pem => 9339512a.0 Comodo_AAA_Services_root.pem => ee64a828.0 Comodo_AAA_Services_root.pem => 75680d2e.0 Swisscom_Root_EV_CA_2.pem => 034868d6.0 Swisscom_Root_EV_CA_2.pem => 9ab62355.0 ComSign_CA.pem => bb2d49a0.0 ComSign_CA.pem => ff588423.0 TeliaSonera_Root_CA_v1.pem => 5cd81ad7.0 TeliaSonera_Root_CA_v1.pem => 63a2c897.0 Certinomis_-_Root_CA.pem => 9f0f5fd6.0 Certinomis_-_Root_CA.pem => d6e6eab9.0 UTN_USERFirst_Email_Root_CA.pem => c5e082db.0 UTN_USERFirst_Email_Root_CA.pem => 9ec3a561.0 GlobalSign_Root_CA_-_R2.pem => 4a6481c9.0 GlobalSign_Root_CA_-_R2.pem => 111e6273.0 Amazon_Root_CA_2.pem => 6d41d539.0 Amazon_Root_CA_2.pem => fb5fa911.0 CA_Disig_Root_R1.pem => 9007ae68.0 CA_Disig_Root_R1.pem => 21855f49.0 Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem => 7719f463.0 Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem => 9479c8c3.0 SecureTrust_CA.pem => f39fc864.0 SecureTrust_CA.pem => cf701eeb.0 GeoTrust_Global_CA.pem => 2c543cd1.0 GeoTrust_Global_CA.pem => 7999be0d.0 Swisscom_Root_CA_2.pem => 3efd4dc0.0 Swisscom_Root_CA_2.pem => 450c6e38.0 OpenTrust_Root_CA_G3.pem => 2c11d503.0 OpenTrust_Root_CA_G3.pem => 559f7c71.0 Security_Communication_Root_CA.pem => f3377b1b.0 Security_Communication_Root_CA.pem => a3896b44.0 Certplus_Root_CA_G2.pem => 451b5485.0 Certplus_Root_CA_G2.pem => d8317ada.0 QuoVadis_Root_CA_2.pem => d7e8dc79.0 QuoVadis_Root_CA_2.pem => 7a819ef2.0 VeriSign_Universal_Root_Certification_Authority.pem => c01cdfa2.0 VeriSign_Universal_Root_Certification_Authority.pem => 524d9b43.0 Starfield_Root_Certificate_Authority_-_G2.pem => 4bfab552.0 Starfield_Root_Certificate_Authority_-_G2.pem => 85cde254.0 Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem => ee1365c0.0 Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem => 11f154d6.0 CA_Disig_Root_R2.pem => 2ae6433e.0 CA_Disig_Root_R2.pem => 9576d26b.0 T-TeleSec_GlobalRoot_Class_3.pem => 5443e9e3.0 T-TeleSec_GlobalRoot_Class_3.pem => 1e1eab7c.0 TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem => 7992b8bb.0 TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem => 0d5a4e1c.0 Certplus_Class_2_Primary_CA.pem => f060240e.0 Certplus_Class_2_Primary_CA.pem => 17b51fe6.0 Certum_Trusted_Network_CA_2.pem => 40193066.0 Certum_Trusted_Network_CA_2.pem => cb1c3204.0 Starfield_Services_Root_Certificate_Authority_-_G2.pem => 09789157.0 Starfield_Services_Root_Certificate_Authority_-_G2.pem => 10531352.0 Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem => dc45b0bd.0 Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem => d78a75c7.0 spi-cacert-2008.pem => ec87c655.0 spi-cacert-2008.pem => 56e29e75.0 DigiCert_Global_Root_CA.pem => 3513523f.0 DigiCert_Global_Root_CA.pem => 399e7759.0 XRamp_Global_CA_Root.pem => 706f604c.0 XRamp_Global_CA_Root.pem => 76579174.0 thawte_Primary_Root_CA_-_G2.pem => c089bbbd.0 thawte_Primary_Root_CA_-_G2.pem => a7d2cf64.0 GeoTrust_Universal_CA.pem => ad088e1d.0 GeoTrust_Universal_CA.pem => e775ed2d.0 Camerfirma_Global_Chambersign_Root.pem => cb59f961.0 Camerfirma_Global_Chambersign_Root.pem => a0bc6fbb.0 IdenTrust_Public_Sector_Root_CA_1.pem => 1e08bfd1.0 IdenTrust_Public_Sector_Root_CA_1.pem => 4be590e0.0 Staat_der_Nederlanden_Root_CA_-_G3.pem => 5a4d6896.0 Staat_der_Nederlanden_Root_CA_-_G3.pem => 5a250ea7.0 Atos_TrustedRoot_2011.pem => e36a6752.0 Atos_TrustedRoot_2011.pem => b872f2b4.0 D-TRUST_Root_Class_3_CA_2_2009.pem => c28a8a30.0 D-TRUST_Root_Class_3_CA_2_2009.pem => 1df5a75f.0 ACEDICOM_Root.pem => 381ce4dd.0 ACEDICOM_Root.pem => ea169617.0 QuoVadis_Root_CA_2_G3.pem => 064e0aa9.0 QuoVadis_Root_CA_2_G3.pem => 1f58a078.0 ePKI_Root_Certification_Authority.pem => ca6e4ad9.0 ePKI_Root_Certification_Authority.pem => 9d6523ce.0 Secure_Global_CA.pem => b66938e9.0 Secure_Global_CA.pem => bdacca6f.0 OISTE_WISeKey_Global_Root_GB_CA.pem => e73d606e.0 OISTE_WISeKey_Global_Root_GB_CA.pem => dfc0fe80.0 Security_Communication_RootCA2.pem => cd58d51e.0 Security_Communication_RootCA2.pem => d59297b8.0 162 added, 0 removed; done. Running hooks in /etc/ca-certificates/update.d.... Replacing debian:ACCVRAIZ1.pem Replacing debian:ACEDICOM_Root.pem Replacing debian:AC_Raíz_Certicámara_S.A..pem Replacing debian:Actalis_Authentication_Root_CA.pem Replacing debian:AddTrust_External_Root.pem Replacing debian:AddTrust_Low-Value_Services_Root.pem Replacing debian:AddTrust_Public_Services_Root.pem Replacing debian:AddTrust_Qualified_Certificates_Root.pem Replacing debian:AffirmTrust_Commercial.pem Replacing debian:AffirmTrust_Networking.pem Replacing debian:AffirmTrust_Premium.pem Replacing debian:AffirmTrust_Premium_ECC.pem Replacing debian:Atos_TrustedRoot_2011.pem Replacing debian:Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem Replacing debian:Baltimore_CyberTrust_Root.pem Replacing debian:Buypass_Class_2_Root_CA.pem Replacing debian:Buypass_Class_3_Root_CA.pem Replacing debian:CA_Disig_Root_R1.pem Replacing debian:CA_Disig_Root_R2.pem Replacing debian:Camerfirma_Chambers_of_Commerce_Root.pem Replacing debian:Camerfirma_Global_Chambersign_Root.pem Replacing debian:Certigna.pem Replacing debian:Certinomis_-_Autorité_Racine.pem Replacing debian:Certinomis_-_Root_CA.pem Replacing debian:Certplus_Class_2_Primary_CA.pem Replacing debian:certSIGN_ROOT_CA.pem Replacing debian:Certum_Root_CA.pem Replacing debian:Certum_Trusted_Network_CA.pem Replacing debian:CFCA_EV_ROOT.pem Replacing debian:Chambers_of_Commerce_Root_-_2008.pem Replacing debian:China_Internet_Network_Information_Center_EV_Certificates_Root.pem Replacing debian:CNNIC_ROOT.pem Replacing debian:Comodo_AAA_Services_root.pem Replacing debian:COMODO_Certification_Authority.pem Replacing debian:COMODO_ECC_Certification_Authority.pem Replacing debian:COMODO_RSA_Certification_Authority.pem Replacing debian:Comodo_Secure_Services_root.pem Replacing debian:Comodo_Trusted_Services_root.pem Replacing debian:ComSign_CA.pem Replacing debian:Cybertrust_Global_Root.pem Replacing debian:Deutsche_Telekom_Root_CA_2.pem Replacing debian:DigiCert_Assured_ID_Root_CA.pem Replacing debian:DigiCert_Assured_ID_Root_G2.pem Replacing debian:DigiCert_Assured_ID_Root_G3.pem Replacing debian:DigiCert_Global_Root_CA.pem Replacing debian:DigiCert_Global_Root_G2.pem Replacing debian:DigiCert_Global_Root_G3.pem Replacing debian:DigiCert_High_Assurance_EV_Root_CA.pem Replacing debian:DigiCert_Trusted_Root_G4.pem Replacing debian:DST_ACES_CA_X6.pem Replacing debian:DST_Root_CA_X3.pem Replacing debian:D-TRUST_Root_Class_3_CA_2_2009.pem Replacing debian:D-TRUST_Root_Class_3_CA_2_EV_2009.pem Replacing debian:EC-ACC.pem Replacing debian:EE_Certification_Centre_Root_CA.pem Replacing debian:Entrust.net_Premium_2048_Secure_Server_CA.pem Replacing debian:Entrust_Root_Certification_Authority.pem Replacing debian:Entrust_Root_Certification_Authority_-_EC1.pem Replacing debian:Entrust_Root_Certification_Authority_-_G2.pem Replacing debian:ePKI_Root_Certification_Authority.pem Replacing debian:E-Tugra_Certification_Authority.pem Replacing debian:GeoTrust_Global_CA_2.pem Replacing debian:GeoTrust_Global_CA.pem Replacing debian:GeoTrust_Primary_Certification_Authority.pem Replacing debian:GeoTrust_Primary_Certification_Authority_-_G2.pem Replacing debian:GeoTrust_Primary_Certification_Authority_-_G3.pem Replacing debian:GeoTrust_Universal_CA_2.pem Replacing debian:GeoTrust_Universal_CA.pem Replacing debian:Global_Chambersign_Root_-_2008.pem Replacing debian:GlobalSign_ECC_Root_CA_-_R4.pem Replacing debian:GlobalSign_ECC_Root_CA_-_R5.pem Replacing debian:GlobalSign_Root_CA.pem Replacing debian:GlobalSign_Root_CA_-_R2.pem Replacing debian:GlobalSign_Root_CA_-_R3.pem Replacing debian:Go_Daddy_Class_2_CA.pem Replacing debian:Go_Daddy_Root_Certificate_Authority_-_G2.pem Replacing debian:Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem Replacing debian:Hongkong_Post_Root_CA_1.pem Replacing debian:IdenTrust_Commercial_Root_CA_1.pem Replacing debian:IdenTrust_Public_Sector_Root_CA_1.pem Replacing debian:Izenpe.com.pem Replacing debian:Microsec_e-Szigno_Root_CA_2009.pem Replacing debian:NetLock_Arany_=Class_Gold=_Főtanúsítvány.pem Replacing debian:Network_Solutions_Certificate_Authority.pem Replacing debian:OISTE_WISeKey_Global_Root_GA_CA.pem Replacing debian:OISTE_WISeKey_Global_Root_GB_CA.pem Replacing debian:PSCProcert.pem Replacing debian:QuoVadis_Root_CA_1_G3.pem Replacing debian:QuoVadis_Root_CA_2.pem Replacing debian:QuoVadis_Root_CA_2_G3.pem Replacing debian:QuoVadis_Root_CA_3.pem Replacing debian:QuoVadis_Root_CA_3_G3.pem Replacing debian:QuoVadis_Root_CA.pem Replacing debian:Secure_Global_CA.pem Replacing debian:SecureSign_RootCA11.pem Replacing debian:SecureTrust_CA.pem Replacing debian:Security_Communication_EV_RootCA1.pem Replacing debian:Security_Communication_RootCA2.pem Replacing debian:Security_Communication_Root_CA.pem Replacing debian:Sonera_Class_2_Root_CA.pem Replacing debian:Staat_der_Nederlanden_EV_Root_CA.pem Replacing debian:Staat_der_Nederlanden_Root_CA_-_G2.pem Replacing debian:Staat_der_Nederlanden_Root_CA_-_G3.pem Replacing debian:Starfield_Class_2_CA.pem Replacing debian:Starfield_Root_Certificate_Authority_-_G2.pem Replacing debian:Starfield_Services_Root_Certificate_Authority_-_G2.pem Replacing debian:S-TRUST_Universal_Root_CA.pem Replacing debian:Swisscom_Root_CA_1.pem Replacing debian:Swisscom_Root_CA_2.pem Replacing debian:Swisscom_Root_EV_CA_2.pem Replacing debian:SwissSign_Gold_CA_-_G2.pem Replacing debian:SwissSign_Platinum_CA_-_G2.pem Replacing debian:SwissSign_Silver_CA_-_G2.pem Replacing debian:Taiwan_GRCA.pem Replacing debian:TC_TrustCenter_Class_3_CA_II.pem Replacing debian:TeliaSonera_Root_CA_v1.pem Replacing debian:thawte_Primary_Root_CA.pem Replacing debian:thawte_Primary_Root_CA_-_G2.pem Replacing debian:thawte_Primary_Root_CA_-_G3.pem Replacing debian:Trustis_FPS_Root_CA.pem Replacing debian:T-TeleSec_GlobalRoot_Class_2.pem Replacing debian:T-TeleSec_GlobalRoot_Class_3.pem Replacing debian:TÜBİTAK_UEKAE_Kök_Sertifika_Hizmet_Sağlayıcısı_-_Sürüm_3.pem Replacing debian:TURKTRUST_Certificate_Services_Provider_Root_2007.pem Replacing debian:TÜRKTRUST_Elektronik_Sertifika_Hizmet_Sağlayıcısı_H5.pem Replacing debian:TWCA_Global_Root_CA.pem Replacing debian:TWCA_Root_Certification_Authority.pem Replacing debian:USERTrust_ECC_Certification_Authority.pem Replacing debian:USERTrust_RSA_Certification_Authority.pem Replacing debian:UTN_USERFirst_Email_Root_CA.pem Replacing debian:UTN_USERFirst_Hardware_Root_CA.pem Replacing debian:Verisign_Class_1_Public_Primary_Certification_Authority_-_G3.pem Replacing debian:Verisign_Class_2_Public_Primary_Certification_Authority_-_G3.pem Replacing debian:Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.pem Replacing debian:VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.pem Replacing debian:VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.pem Replacing debian:VeriSign_Universal_Root_Certification_Authority.pem Replacing debian:Visa_eCommerce_Root.pem Replacing debian:XRamp_Global_CA_Root.pem Replacing debian:spi-cacert-2008.pem Replacing debian:Certplus_Root_CA_G1.pem Replacing debian:Certplus_Root_CA_G2.pem Replacing debian:Certum_Trusted_Network_CA_2.pem Replacing debian:Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem Replacing debian:Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem Replacing debian:ISRG_Root_X1.pem Replacing debian:OpenTrust_Root_CA_G1.pem Replacing debian:OpenTrust_Root_CA_G2.pem Replacing debian:OpenTrust_Root_CA_G3.pem Replacing debian:SZAFIR_ROOT_CA2.pem Adding debian:AC_RAIZ_FNMT-RCM.pem Adding debian:Amazon_Root_CA_1.pem Adding debian:Amazon_Root_CA_2.pem Adding debian:Amazon_Root_CA_3.pem Adding debian:Amazon_Root_CA_4.pem Adding debian:D-TRUST_Root_CA_3_2013.pem Adding debian:LuxTrust_Global_Root_2.pem Adding debian:Symantec_Class_1_Public_Primary_Certification_Authority_-_G4.pem Adding debian:Symantec_Class_1_Public_Primary_Certification_Authority_-_G6.pem Adding debian:Symantec_Class_2_Public_Primary_Certification_Authority_-_G4.pem Adding debian:Symantec_Class_2_Public_Primary_Certification_Authority_-_G6.pem Adding debian:TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem done. done. mshuler@hana:~$ mshuler@hana:~$ mshuler@hana:~$ keytool -list -v -keystore /etc/ssl/certs/java/cacerts | egrep 'ApplicationCA|StartCom|Microsec' Enter keystore password: changeit Owner: OU=ApplicationCA, O=Japanese Government, C=JP Issuer: OU=ApplicationCA, O=Japanese Government, C=JP Owner: CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL Issuer: CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL Owner: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL Issuer: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL 0000: 16 29 53 74 61 72 74 43 6F 6D 20 46 72 65 65 20 .)StartCom Free Owner: EMAILADDRESS=i...@e-szigno.hu, CN=Microsec e-Szigno Root CA 2009, O=Microsec Ltd., L=Budapest, C=HU Issuer: EMAILADDRESS=i...@e-szigno.hu, CN=Microsec e-Szigno Root CA 2009, O=Microsec Ltd., L=Budapest, C=HU Owner: CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU Issuer: CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU [CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU] [URIName: http://www.e-szigno.hu/RootCA.crl, URIName: ldap://ldap.e-szigno.hu/CN=Microsec%20e-Szigno%20Root%20CA,OU=e-Szigno%20CA,O=Microsec%20Ltd.,L=Budapest,C=HU?certificateRevocationList;binary] C=HU, L=Budapest, O=Microsec Kft., OU=e-Szignó HSZ, CN=Microsec e-Szignó Root CA Owner: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL Issuer: CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL 0000: 16 29 53 74 61 72 74 43 6F 6D 20 46 72 65 65 20 .)StartCom Free mshuler@hana:~$