Stop trusting the SPI CA for debian.org services.
[mirror/dsa-puppet.git] / modules / ssl / files / servicecerts / db.debian.org.crt
index 0b81a4c..86fe185 100644 (file)
@@ -2,12 +2,12 @@ Certificate:
     Data:
         Version: 3 (0x2)
         Serial Number:
-            35:d0:d1:17:98:48:34:58:bb:90:07:8a:d1:f3:f9:16
-    Signature Algorithm: sha1WithRSAEncryption
-        Issuer: C=FR, O=GANDI SAS, CN=Gandi Standard SSL CA
+            3d:23:f3:07:48:4a:e7:00:04:b2:04:c2:4b:11:02:c4
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: C=FR, ST=Paris, L=Paris, O=Gandi, CN=Gandi Standard SSL CA 2
         Validity
-            Not Before: Dec 31 00:00:00 2013 GMT
-            Not After : Dec 31 23:59:59 2014 GMT
+            Not Before: Dec 11 00:00:00 2015 GMT
+            Not After : Jan 20 23:59:59 2017 GMT
         Subject: OU=Domain Control Validated, OU=Gandi Standard SSL, CN=db.debian.org
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
@@ -42,7 +42,7 @@ Certificate:
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
             X509v3 Authority Key Identifier: 
-                keyid:B6:A8:FF:A2:A8:2F:D0:A6:CD:4B:B1:68:F3:E7:50:10:31:A7:79:21
+                keyid:B3:90:A7:D8:C9:AF:4E:CD:61:3C:9F:7C:AD:5D:7F:41:FD:69:30:EA
 
             X509v3 Subject Key Identifier: 
                 32:46:59:7C:E7:0A:EF:FE:AB:21:4B:0A:65:08:E1:C9:97:CB:50:C2
@@ -54,64 +54,65 @@ Certificate:
                 TLS Web Server Authentication, TLS Web Client Authentication
             X509v3 Certificate Policies: 
                 Policy: 1.3.6.1.4.1.6449.1.2.2.26
-                  CPS: http://www.gandi.net/contracts/fr/ssl/cps/pdf/
+                  CPS: https://cps.usertrust.com
                 Policy: 2.23.140.1.2.1
 
             X509v3 CRL Distribution Points: 
 
                 Full Name:
-                  URI:http://crl.gandi.net/GandiStandardSSLCA.crl
+                  URI:http://crl.usertrust.com/GandiStandardSSLCA2.crl
 
             Authority Information Access: 
-                CA Issuers - URI:http://crt.gandi.net/GandiStandardSSLCA.crt
-                OCSP - URI:http://ocsp.gandi.net
+                CA Issuers - URI:http://crt.usertrust.com/GandiStandardSSLCA2.crt
+                OCSP - URI:http://ocsp.usertrust.com
 
             X509v3 Subject Alternative Name: 
                 DNS:db.debian.org, DNS:www.db.debian.org
-    Signature Algorithm: sha1WithRSAEncryption
-         af:a2:c7:b1:10:34:f8:14:a8:3c:78:ea:00:0f:89:f7:26:e9:
-         bd:85:bd:7a:be:82:d9:41:f6:1e:94:68:30:ce:ed:fc:43:ce:
-         6a:14:e5:5e:16:b5:d0:4c:e6:eb:c8:7c:e9:a9:78:db:82:c4:
-         f6:a3:d7:c7:14:96:3f:4f:3e:32:f7:78:ae:37:50:25:6e:eb:
-         0e:61:37:7a:76:ff:60:4f:bc:58:d0:46:1b:41:70:87:04:5a:
-         c3:1a:97:50:c2:b5:2f:ef:08:19:10:b7:59:52:81:de:3f:c6:
-         23:1f:2b:87:10:62:dc:11:bb:8e:e0:07:41:ee:33:69:5e:71:
-         81:c0:e3:61:02:e6:1a:ae:a5:8f:f6:b4:7a:39:e0:07:72:53:
-         8e:93:c6:05:10:72:6d:1e:89:c2:ed:62:e4:e3:21:84:16:75:
-         48:0c:f7:68:5e:0f:0f:1c:69:ec:b9:18:a2:f6:fd:39:98:33:
-         68:96:cb:f7:2c:14:b9:b8:b4:90:30:3c:cb:6f:cb:52:96:74:
-         94:04:8a:a6:08:b8:8f:4b:6f:8f:f1:3b:28:d2:c1:53:4b:20:
-         99:9b:13:31:3a:49:db:3d:b2:3c:6a:11:c5:38:09:ca:27:4d:
-         52:5a:ce:f1:d9:b6:70:51:57:c1:a2:45:82:9a:77:fc:60:43:
-         a2:7e:fd:9d
+    Signature Algorithm: sha256WithRSAEncryption
+         83:56:ba:ff:87:59:52:0a:ec:fe:23:0e:90:c5:64:49:64:28:
+         a1:af:90:05:e2:a2:3d:ee:c9:a3:07:6f:b6:e4:ed:a3:e0:f0:
+         bd:cb:0b:db:8e:92:98:cf:d1:3a:bb:a0:dd:72:a8:24:aa:98:
+         88:f5:cb:9c:04:05:32:dc:6c:9b:cc:71:1a:7f:a6:48:c5:de:
+         57:a7:7e:aa:9f:51:87:2a:f9:74:17:4f:53:64:5c:7e:15:ef:
+         a8:d1:5b:45:4a:b7:69:6b:9b:1b:bf:53:51:6c:a8:a8:e7:d9:
+         94:1e:81:d0:7b:11:17:f3:4d:8c:ed:f8:d0:fb:0f:f1:bb:7e:
+         96:2e:94:a9:2d:9c:77:24:15:4f:9b:46:58:ff:bb:af:9b:44:
+         d6:02:e4:8c:f7:3d:2e:c3:d9:cb:a9:24:35:9a:f1:70:d6:46:
+         8c:1e:eb:e4:f8:d9:71:8d:69:40:1d:26:66:85:87:05:3f:e7:
+         13:4b:d9:c9:66:52:fc:3b:f5:b8:72:64:f6:57:74:d1:b3:f1:
+         15:3a:45:e4:d9:28:f2:f5:98:f6:8a:90:60:eb:c7:08:dc:39:
+         8f:04:55:13:49:98:00:32:3a:57:ae:23:f9:9f:1b:cb:99:68:
+         43:b2:18:f5:7a:91:b5:02:53:a8:ce:ec:2a:42:dc:de:fd:ef:
+         06:16:40:2d
 -----BEGIN CERTIFICATE-----
-MIIFXzCCBEegAwIBAgIQNdDRF5hINFi7kAeK0fP5FjANBgkqhkiG9w0BAQUFADBB
-MQswCQYDVQQGEwJGUjESMBAGA1UEChMJR0FOREkgU0FTMR4wHAYDVQQDExVHYW5k
-aSBTdGFuZGFyZCBTU0wgQ0EwHhcNMTMxMjMxMDAwMDAwWhcNMTQxMjMxMjM1OTU5
-WjBYMSEwHwYDVQQLExhEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsT
-EkdhbmRpIFN0YW5kYXJkIFNTTDEWMBQGA1UEAxMNZGIuZGViaWFuLm9yZzCCAaIw
-DQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAN/7DlZZKR5SELzF7rdn6LWxuebp
-VyFu1eXltzxi+Mig9cR0ZZD3hp0JcUresABOzE66AuhGtcFus/J/88CGM2r39u3n
-5ac5O/4Ypp57997YJRV725dL4oX75Vpc4p8jEI/LyIFteZN22ziv9zW7qCKKahnq
-1tuqDkV+84BEARpVdIaaWmn/KqsEgxeNKomyOLvn96IVCTAF78rudPmJHfSCl++N
-Fmg0yu7DPyuXf8YJfA6j8/kFueanK2B1y/ww8MSbL3iAdgLwVtRJkwRYyKn8p5+y
-bwzX9L36GWgYs9OXUn8x494T5GjbGQVxUNt7qJnRtiUwYVoiOARrv1EI0Cq4ANXV
-aLDckc5y0a2PY3c4NWVlKGYbdxdQC1n6nH93mWDIr6vu7JX3CqDDr8FBlNVVtiBi
-v0q/eiVb9dzBzOntt3hA6GOJFAuwDDf7g7nqGq8qqcr7EIyVB8ytQ5XMgtLCpmJk
-LzIdRYfdsQMa7cAbl0THAwwXigcotFA0aYIPBQIDAQABo4IBujCCAbYwHwYDVR0j
-BBgwFoAUtqj/oqgv0KbNS7Fo8+dQEDGneSEwHQYDVR0OBBYEFDJGWXznCu/+qyFL
-CmUI4cmXy1DCMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQW
-MBQGCCsGAQUFBwMBBggrBgEFBQcDAjBgBgNVHSAEWTBXMEsGCysGAQQBsjEBAgIa
-MDwwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZ2FuZGkubmV0L2NvbnRyYWN0cy9m
-ci9zc2wvY3BzL3BkZi8wCAYGZ4EMAQIBMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6
-Ly9jcmwuZ2FuZGkubmV0L0dhbmRpU3RhbmRhcmRTU0xDQS5jcmwwagYIKwYBBQUH
-AQEEXjBcMDcGCCsGAQUFBzAChitodHRwOi8vY3J0LmdhbmRpLm5ldC9HYW5kaVN0
-YW5kYXJkU1NMQ0EuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5nYW5kaS5u
-ZXQwKwYDVR0RBCQwIoINZGIuZGViaWFuLm9yZ4IRd3d3LmRiLmRlYmlhbi5vcmcw
-DQYJKoZIhvcNAQEFBQADggEBAK+ix7EQNPgUqDx46gAPifcm6b2FvXq+gtlB9h6U
-aDDO7fxDzmoU5V4WtdBM5uvIfOmpeNuCxPaj18cUlj9PPjL3eK43UCVu6w5hN3p2
-/2BPvFjQRhtBcIcEWsMal1DCtS/vCBkQt1lSgd4/xiMfK4cQYtwRu47gB0HuM2le
-cYHA42EC5hqupY/2tHo54AdyU46TxgUQcm0eicLtYuTjIYQWdUgM92heDw8caey5
-GKL2/TmYM2iWy/csFLm4tJAwPMtvy1KWdJQEiqYIuI9Lb4/xOyjSwVNLIJmbEzE6
-Sds9sjxqEcU4CconTVJazvHZtnBRV8GiRYKad/xgQ6J+/Z0=
+MIIFdjCCBF6gAwIBAgIQPSPzB0hK5wAEsgTCSxECxDANBgkqhkiG9w0BAQsFADBf
+MQswCQYDVQQGEwJGUjEOMAwGA1UECBMFUGFyaXMxDjAMBgNVBAcTBVBhcmlzMQ4w
+DAYDVQQKEwVHYW5kaTEgMB4GA1UEAxMXR2FuZGkgU3RhbmRhcmQgU1NMIENBIDIw
+HhcNMTUxMjExMDAwMDAwWhcNMTcwMTIwMjM1OTU5WjBYMSEwHwYDVQQLExhEb21h
+aW4gQ29udHJvbCBWYWxpZGF0ZWQxGzAZBgNVBAsTEkdhbmRpIFN0YW5kYXJkIFNT
+TDEWMBQGA1UEAxMNZGIuZGViaWFuLm9yZzCCAaIwDQYJKoZIhvcNAQEBBQADggGP
+ADCCAYoCggGBAN/7DlZZKR5SELzF7rdn6LWxuebpVyFu1eXltzxi+Mig9cR0ZZD3
+hp0JcUresABOzE66AuhGtcFus/J/88CGM2r39u3n5ac5O/4Ypp57997YJRV725dL
+4oX75Vpc4p8jEI/LyIFteZN22ziv9zW7qCKKahnq1tuqDkV+84BEARpVdIaaWmn/
+KqsEgxeNKomyOLvn96IVCTAF78rudPmJHfSCl++NFmg0yu7DPyuXf8YJfA6j8/kF
+ueanK2B1y/ww8MSbL3iAdgLwVtRJkwRYyKn8p5+ybwzX9L36GWgYs9OXUn8x494T
+5GjbGQVxUNt7qJnRtiUwYVoiOARrv1EI0Cq4ANXVaLDckc5y0a2PY3c4NWVlKGYb
+dxdQC1n6nH93mWDIr6vu7JX3CqDDr8FBlNVVtiBiv0q/eiVb9dzBzOntt3hA6GOJ
+FAuwDDf7g7nqGq8qqcr7EIyVB8ytQ5XMgtLCpmJkLzIdRYfdsQMa7cAbl0THAwwX
+igcotFA0aYIPBQIDAQABo4IBszCCAa8wHwYDVR0jBBgwFoAUs5Cn2MmvTs1hPJ98
+rV1/Qf1pMOowHQYDVR0OBBYEFDJGWXznCu/+qyFLCmUI4cmXy1DCMA4GA1UdDwEB
+/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
+BQcDAjBLBgNVHSAERDBCMDYGCysGAQQBsjEBAgIaMCcwJQYIKwYBBQUHAgEWGWh0
+dHBzOi8vY3BzLnVzZXJ0cnVzdC5jb20wCAYGZ4EMAQIBMEEGA1UdHwQ6MDgwNqA0
+oDKGMGh0dHA6Ly9jcmwudXNlcnRydXN0LmNvbS9HYW5kaVN0YW5kYXJkU1NMQ0Ey
+LmNybDBzBggrBgEFBQcBAQRnMGUwPAYIKwYBBQUHMAKGMGh0dHA6Ly9jcnQudXNl
+cnRydXN0LmNvbS9HYW5kaVN0YW5kYXJkU1NMQ0EyLmNydDAlBggrBgEFBQcwAYYZ
+aHR0cDovL29jc3AudXNlcnRydXN0LmNvbTArBgNVHREEJDAigg1kYi5kZWJpYW4u
+b3JnghF3d3cuZGIuZGViaWFuLm9yZzANBgkqhkiG9w0BAQsFAAOCAQEAg1a6/4dZ
+Ugrs/iMOkMVkSWQooa+QBeKiPe7JowdvtuTto+DwvcsL246SmM/ROrug3XKoJKqY
+iPXLnAQFMtxsm8xxGn+mSMXeV6d+qp9Rhyr5dBdPU2RcfhXvqNFbRUq3aWubG79T
+UWyoqOfZlB6B0HsRF/NNjO340PsP8bt+li6UqS2cdyQVT5tGWP+7r5tE1gLkjPc9
+LsPZy6kkNZrxcNZGjB7r5PjZcY1pQB0mZoWHBT/nE0vZyWZS/Dv1uHJk9ld00bPx
+FTpF5Nko8vWY9oqQYOvHCNw5jwRVE0mYADI6V64j+Z8by5loQ7IY9XqRtQJTqM7s
+KkLc3v3vBhZALQ==
 -----END CERTIFICATE-----