Skip to content

Update Orbit CA certs (Mozilla root store sync) for fleetd v1.59.0 #49161

Description

@lucasmrod

Summary

Track the automated Orbit CA certificate bundle update in #49160, which syncs orbit/pkg/packaging/certs.pem to the latest Mozilla root store so fleetd ships in v1.59.0 with an up-to-date set of trusted CAs.

Details

  • Source: automated update-certs.yml GitHub Action (PR Update Orbit CA certs [automated] #49160)
  • Mozilla snapshot: Jan 5 2026 → Jul 10 2026
  • mk-ca-bundle.pl: v1.30 → v1.33
  • Net change: 1 CA added, 24 CAs removed (144 → 121 roots)

Added (1)

  • e-Szigno TLS Root CA 2023

Removed (24)

  • Trustwave (exiting CA business): Trustwave Global CA, Trustwave Global ECC P256, Trustwave Global ECC P384, SecureTrust CA, Secure Global CA
  • Entrust distrust (incl. Entrust-owned AffirmTrust): Entrust Root CA – G2, Entrust Root CA – EC1, AffirmTrust Commercial, AffirmTrust Networking, AffirmTrust Premium, AffirmTrust Premium ECC
  • Legacy DigiCert / QuoVadis roots: DigiCert Assured ID Root CA, DigiCert Global Root CA, DigiCert High Assurance EV Root CA, QuoVadis Root CA 2, QuoVadis Root CA 3
  • Compliance distrust: GLOBALTRUST 2020
  • Other retirements: COMODO Certification Authority, SwissSign Gold CA – G2, TeliaSonera Root CA v1, Certigna, certSIGN ROOT CA, FIRMAPROFESIONAL CA ROOT-A WEB, GTS Root R2

Acceptance criteria

References

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status
✅ Ready for release

Relationships

None yet

Development

No branches or pull requests

Issue actions