Kai Engert 40d3667
////
Kai Engert 40d3667
Copyright (C) 2013 Red Hat, Inc.
Kai Engert 40d3667
Kai Engert 40d3667
This program is free software; you can redistribute it and/or modify
Kai Engert 40d3667
it under the terms of the GNU General Public License as published by
Kai Engert 40d3667
the Free Software Foundation; either version 2 of the License, or
Kai Engert 40d3667
(at your option) any later version.
Kai Engert 40d3667
Kai Engert 40d3667
This program is distributed in the hope that it will be useful,
Kai Engert 40d3667
but WITHOUT ANY WARRANTY; without even the implied warranty of
Kai Engert 40d3667
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Kai Engert 40d3667
GNU General Public License for more details.
Kai Engert 40d3667
////
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
ca-legacy(8)
Kai Engert 40d3667
============
Kai Engert 40d3667
:doctype: manpage
Kai Engert 40d3667
:man source: ca-legacy
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
NAME
Kai Engert 40d3667
----
Kai Engert 40d3667
ca-legacy - Manage the system configuration for legacy CA certificates
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
SYNOPSIS
Kai Engert 40d3667
--------
Kai Engert 40d3667
*ca-legacy* ['COMMAND']
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
DESCRIPTION
Kai Engert 40d3667
-----------
Kai Engert 40d3667
ca-legacy(8) is used to include or exclude a set of legacy Certificate Authority (CA)
Kai Engert 40d3667
certificates in the system's list of trusted CA certificates.
Kai Engert 40d3667
Kai Engert 40d3667
The list of CA certificates and trust flags included in the ca-certificates package
Kai Engert 40d3667
are based on the decisions made by Mozilla.org according to the Mozilla CA policy.
Kai Engert 40d3667
Kai Engert 4111120
Occasionally, removal or distrust decisions made by Mozilla.org might be incompatible with the requirements
Kai Engert 40d3667
or limitations of some applications that also use the CA certificates list in the Linux environment.
Kai Engert 40d3667
Kai Engert 40d3667
The ca-certificates package might keep some CA certificates included and trusted by default,
Kai Engert 40d3667
as long as it is seen necessary by the maintainers, despite the fact that they have
Kai Engert 40d3667
been removed by Mozilla. These certificates are called legacy CA certificates.
Kai Engert 40d3667
Kai Engert 40d3667
The general requirements to keep legacy CA certificates included and trusted might change over time,
Kai Engert 40d3667
for example if functional limitations of software packages have been resolved.
Kai Engert 40d3667
Future versions of the ca-certificates package might reduce the set of legacy CA certificates
Kai Engert 40d3667
that are included and trusted by default.
Kai Engert 40d3667
Kai Engert 40d3667
The ca-legacy(8) command can be used to override the default behaviour.
Kai Engert 40d3667
Kai Engert 40d3667
The mechanisms to individually trust or distrust CA certificates as described in update-ca-trust(8) still apply.
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
COMMANDS
Kai Engert 40d3667
--------
Kai Engert 40d3667
*check*::
Kai Engert 40d3667
    The current configuration will be shown.
Kai Engert 40d3667
Kai Engert 40d3667
*default*::
Kai Engert 40d3667
    Configure the system to use the default configuration, as recommended
Kai Engert 40d3667
    by the package maintainers.
Kai Engert 40d3667
Kai Engert 40d3667
*disable*::
Kai Engert 40d3667
    Configure the system to explicitly disable legacy CA certificates.
Kai Engert 40d3667
    Using this configuration, the system will use the set of
Kai Engert 40d3667
    included and trusted CA certificates as released by Mozilla.
Kai Engert 40d3667
Kai Engert 40d3667
*install*::
Kai Engert 40d3667
    The configuration file will be read and the system configuration
Kai Engert 40d3667
    will be set accordingly. This command is executed automatically during
Kai Engert 40d3667
    upgrades of the ca-certificates package.
Kai Engert 40d3667
Kai Engert 40d3667
Kai Engert 40d3667
FILES
Kai Engert 40d3667
-----
Kai Engert 40d3667
/etc/pki/ca-trust/ca-legacy.conf::
Kai Engert 40d3667
	A configuration file that will be used and modified by the ca-legacy command.
Kai Engert 40d3667
    The contents of the configuration file will be read on package upgrades.
Kai Engert 40d3667
Kai Engert 40d3667
AUTHOR
Kai Engert 40d3667
------
Kai Engert 40d3667
Written by Kai Engert.