Package: ca-certificates Version: 20090814+nmu1 Severity: serious Justification: does not honor decision of admin
Calling dpkg-reconfigure ca-certificates behaves a bit erratically at best: Calling dpkg-reconfigure ca-certificates behaves a bit erratically at best: - When disabling *all* certificates I get: Updating certificates in /etc/ssl/certs... unable to load certificate 22866:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long:asn1_lib.c:150: WARNING: ca-certificates.crt does not contain a certificate or CRL: skipping 0 added, 141 removed; done. Running hooks in /etc/ca-certificates/update.d.... updating keystore /etc/ssl/certs/java/cacerts... does not exist: /etc/ssl/certs/brasil.gov.br.pem does not exist: /etc/ssl/certs/cacert.org.pem .... does not exist: /etc/ssl/certs/WellsSecure_Public_Root_Certificate_Authority.pem done. done. - When enabling only *one* certificate (debconf.org) I get: Updating certificates in /etc/ssl/certs... WARNING: Skipping duplicate certificate ca-certificates.crt 141 added, 0 removed; done. Running hooks in /etc/ca-certificates/update.d.... updating keystore /etc/ssl/certs/java/cacerts... added: /etc/ssl/certs/ca.pem added: /etc/ssl/certs/brasil.gov.br.pem ... added: /etc/ssl/certs/deutsche-telekom-root-ca-2.pem done. done. and /etc/ssl/certs/ca-certificates.crt ends up with *ALL* of them??? So what the hell is going on here??? That is a serious breakage of what *I* told it to do. -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.35+ (SMP w/2 CPU cores; PREEMPT) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages ca-certificates depends on: ii debconf [debconf-2.0] 1.5.33 Debian configuration management sy ii openssl 0.9.8o-1 Secure Socket Layer (SSL) binary a ca-certificates recommends no packages. ca-certificates suggests no packages. -- debconf information: * ca-certificates/enable_crts: debconf.org/ca.crt ca-certificates/new_crts: * ca-certificates/trust_new_crts: ask -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org