aboutsummaryrefslogtreecommitdiffstats
path: root/certs
AgeCommit message (Expand)AuthorFilesLines
2021-05-18drop certificate DST Root CA X3...Let's Encrypt planned the transition to ISRG's root certificate ("ISRG Root X1") on July 8, 2019, but postponed several times. Finally they found another solution: A certificate 'ISRG Root X1', but cross-signed with 'DST Root CA X3' and with a livetime that exceeds that of the root CA. This is said to work for most operating system where root certificate authorities are just 'trust anchors'. I doubt this is true for RouterOS, where certificates are just imported into the certificate store. So let's migrate to 'ISRG Root X1' now. Gravatar Christian Hesse1-77/+0
2021-02-24global-functions: $GetMacVendor: requires certificate "Cloudflare Inc ECC CA-...Gravatar Christian Hesse1-0/+166
2020-12-30certs: add plain text info about certificates...Also order certificates, so we have: * intermediate * root * alternative root, if any Let's add 'ISRG Root X1' for 'E1' as there will be a valid cross-signed chain 'E1' -> 'ISRG Root X2' -> 'ISRG Root X1'. Gravatar Christian Hesse6-68/+1028
2020-12-18certs: remove Let's Encrypt Authority X3Gravatar Christian Hesse1-83/+0
2020-12-17certs: add new Let's Encrypt certificates...https://letsencrypt.org/certificates/ Gravatar Christian Hesse2-0/+112
2020-06-10add certificate 'GTS CA 1O1'...This is used by DNS over HTTPS services: https://dns.google/dns-query Gravatar Christian Hesse1-0/+47
2020-03-20add certificate 'DigiCert ECC Secure Server CA'...This is used by DNS over HTTPS services: https://cloudflare-dns.com/dns-query https://dns9.quad9.net/dns-query (secured) https://dns10.quad9.net/dns-query (unsecured) https://github.com/curl/curl/wiki/DNS-over-HTTPS Gravatar Christian Hesse1-0/+44
2019-04-30global-functions: $CertificateAvailable: fetch by CommonName...Now that we have a proper $UrlEncode function... Fetch certificates by CommonName. Also remove the PEM after import. Gravatar Christian Hesse3-0/+0
2019-01-02update-tunnelbroker: verify certificateGravatar Christian Hesse1-0/+52
2018-12-20global-functions: make $CertificateAvailable work on CommonName...This should prevent endless certificate switching for Let's Encrypt cross-signed intermediate certificates. Gravatar Christian Hesse4-136/+134
2018-12-20README: add Root CA certificate DST Root CA X3...This is used by Let's Encrypt to cross-sign. Gravatar Christian Hesse1-0/+20
2018-10-16README: download certificates from repositoryGravatar Christian Hesse2-0/+64
2018-10-16global-functions: import certificates if required...Signed-off-by: Christian Hesse <mail@eworm.de> Gravatar Christian Hesse2-0/+52