提交 bcab1f08 编写于 作者: K Kohsuke Kawaguchi

[INFRA-1502] bake the new UC root CA.

The current UC root CA will expire in 2021. Since this key certificate
is baked into jenkins.war, it needs a plenty of time to rotate. I think
two years window would be sufficient, but since I looked, we might as
well start now.

The new key is also now 4096 bits, upgraded from previous 2048 bits.

I've also used the opportunity to remove old hudson-community root CA,
which was used during the transition period from me leaving Sun and the
birth of Jenkins. It's been long since we stopped using this cert, so no
need to honor it anymore.
上级 d366abc1
-----BEGIN CERTIFICATE-----
MIIE1jCCA76gAwIBAgIJAImLL4rgC+O7MA0GCSqGSIb3DQEBBQUAMIGiMQswCQYD
VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEUMBIGA1UEBxMLU2FudGEgQ2xh
cmExFzAVBgNVBAoTDkh1ZHNvbiBwcm9qZWN0MRcwFQYDVQQLEw5IdWRzb24gUm9v
dCBDQTEXMBUGA1UEAxMOSHVkc29uIFJvb3QgQ0ExHTAbBgkqhkiG9w0BCQEWDmh1
ZHNvbkBzdW4uY29tMB4XDTA5MTAyNTE3NTI0MFoXDTE5MTAyMzE3NTI0MFowgaIx
CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRQwEgYDVQQHEwtTYW50
YSBDbGFyYTEXMBUGA1UEChMOSHVkc29uIHByb2plY3QxFzAVBgNVBAsTDkh1ZHNv
biBSb290IENBMRcwFQYDVQQDEw5IdWRzb24gUm9vdCBDQTEdMBsGCSqGSIb3DQEJ
ARYOaHVkc29uQHN1bi5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQCp1h/pnrYRAGK6nse+3d2W4xshInJwwnR/1D3NwBLA9xs/DOrlxX96b8CbXNoW
DGc7DpvlwpKfnhOx2jgT5/Jf3bbwQdIntXp9DPQyYLFzekNBZyd3aRySgODpdRW0
nHcNtQWqn7jvMfu16njUer0x+ipPDCMxOvEZCSjYKrok2PUlQhN/BeS3av9vxSPi
3FDhDukYimzhiuZiteXb1oij67FBWdI3cYAsQmU1KJyxBwLJ44cLmfLf0I1Sl6Tz
XcTiSAYvxLogf/ESYtchBjdvmEupv611HWYjbdi4XnjW0tj+NzOcaEcsDC6f5BSt
TxSJ3T69pIpNZjjxHNMHB01vAgMBAAGjggELMIIBBzAdBgNVHQ4EFgQUUaZC6oV8
pWg5kT4VoAkNH5etnF8wgdcGA1UdIwSBzzCBzIAUUaZC6oV8pWg5kT4VoAkNH5et
nF+hgaikgaUwgaIxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRQw
EgYDVQQHEwtTYW50YSBDbGFyYTEXMBUGA1UEChMOSHVkc29uIHByb2plY3QxFzAV
BgNVBAsTDkh1ZHNvbiBSb290IENBMRcwFQYDVQQDEw5IdWRzb24gUm9vdCBDQTEd
MBsGCSqGSIb3DQEJARYOaHVkc29uQHN1bi5jb22CCQCJiy+K4AvjuzAMBgNVHRME
BTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAYAYVICF98VHVt/0L8MjxKtuHNjZ2q
5Wius5tT+uWufer5y083YGlnQzch/622NNR14koJMioD0FR3XqEGeakJexB3hj3K
Iqp7+nkqFcjZycujGTsix6zJ8Mwc2lHbCTt5EZsr5YYzeT6IWbeOofsRBsqA1Ygc
L6pT0oFf1nl+RKxa0EANj6RO9fOjAp9cTndZjynvE8J8S1RDPC98IRmSCiwZKCQc
9KE6D+Sk9XZO3pff6NGo8DA1MOoMGB8lxXWZxMvqkaZdB6UTnvWsvPvpqwFA/mj0
M/hYpqAOSqTttQMLuQBuYj5YbPjh0843azZXP5xm62TK+E+q7sdedeuA
-----END CERTIFICATE-----
This root CA is used to hand out certificates to the community members, allowing people to run update centers without using an expensive regular certificates from vendors like VeriSign.
-----BEGIN CERTIFICATE-----
MIIF6TCCA9GgAwIBAgIJAODsOx91KoaMMA0GCSqGSIb3DQEBCwUAMIGKMQswCQYD
VQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTERMA8GA1UEBwwIU2FuIEpvc2Ux
GDAWBgNVBAoMD0plbmtpbnMgUHJvamVjdDEaMBgGA1UEAwwRS29oc3VrZSBLYXdh
Z3VjaGkxHTAbBgkqhkiG9w0BCQEWDmtrQGtvaHN1a2Uub3JnMB4XDTE4MDQwODE5
NTcxMFoXDTI4MDQwNTE5NTcxMFowgYoxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApD
YWxpZm9ybmlhMREwDwYDVQQHDAhTYW4gSm9zZTEYMBYGA1UECgwPSmVua2lucyBQ
cm9qZWN0MRowGAYDVQQDDBFLb2hzdWtlIEthd2FndWNoaTEdMBsGCSqGSIb3DQEJ
ARYOa2tAa29oc3VrZS5vcmcwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoIC
AQDFlDbPDKOdbqNdxTdVUkCsSAqbl/K+c0Q9BR43P1KUsUbKnNlZalibgE0clduz
W75lwH7Qt7qqNXJIy4qR3ETS45fxgtg2lJdVCOV0i3PhigdyBWbHmD7/ER/LTAfN
Z2HOOrujZ3giz6vo2eTluNk4zmIW8YBaf6j67GyWMd1Mnx/t6G7DWvZRXQS7HSXt
mPsbBzDB4Z6WdIlR5EYsqnw55Lb0h2Bh4RWg6RWL9Vxxc4z+EUT8hH2VBLbm5sAJ
avS5kgCZM72VqREdxb7LleqgetLC9WJ3wGoW6RmrCMIN9Ast5WGI91JE1VQh7i8y
AZG626hJp/Ax4P0kIQ3nySV+/kzQB1i8kuhRq6pBcVU7flETw44ENaVXJ7IUE3YK
QghgwDW0Mf5+oSG+t4atOBFxy0VudOLoQ8AHUgsotLMzGOwOluxEunymiSL1AK0V
7FIXg5tWlcXLvZaY2PQSttvSklYxHjoH+JuiazrOjqu96iLSEyY7JVZ5X2/D2Nv7
T9JPTvdu1H3vtzr32qbMWV7hAqCR3hSDGCHmmuRDJ5CM4G4G5vQ1XE4dRfzBt+5m
68ecwRGFp8C2byF5Wn1LyFrYs/uHp99TL/DMpqXBfc9z7oQZI2zzPmji5dC9qnD3
P5+k2ksuEURK8AJAf5f17sjUfsjQAPSUMaKVKzmrszL2PQIDAQABo1AwTjAdBgNV
HQ4EFgQUEcbl1DAt6VXGAbVrUHLSNn60AYcwHwYDVR0jBBgwFoAUEcbl1DAt6VXG
AbVrUHLSNn60AYcwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEAVBiW
OrRdGBUKd/Gyb+qdFq3q0YtmfARw3TfO0rL9rtjU6S4aOo+XcmM8TbjHrxnBd0Wx
2rQhtkZQPcu45LCUYMmseFMM36T4ahDKwrI6l0uJKvGO7W3gg26GP9A7D0x9KpYL
QemVbwzpG9pQyJJOE+VmgFK1Bk3bDZu9m7FFi2NRmgexvRPS1tpl5WPFRnGY7Duv
xPAVey33cKxa4malrFdxjI4WiVdtqQu+GPcN6WNJfPhYxeWlcyQGCxqprLLdoG0l
ncd95evObgj0y6STY7/x29hRguYOnXnOYpJB53Iaard34gL8JV34gyCBkfy48eOD
D9rw/kdQYUhyxLQnoCS2q4Ueyk/mtnAs/eUE/aFoD0ElX/5CAzL8ZbrRTKgwqmB5
yP8Wgd/G8du3kRtTWaSc19Wdr6hFOaCfXgvyJvl/S5XaFyJF2lotKdM6O3EGdTOF
b10ZJSYa/6o6Y4CY4P2J3WHF8uyBPpH92p/csbt4nqPIdQWm0/KGsy2Hr7z+QYvc
V1ipjxDLCj/RVPRuoGHVeW61Q9FEhatDgryYAq3VWOfazLHE5W/JHZQkcpDJLNdN
2EWvSD3/jxFUuqbWCBmiy8klzUzN97tKGLDSAsxgW2J+kydvL8souNl+cVV/ttlT
T1JjZA8VNmdlKiPqf4S9u/kTAojeLB9zU0cTSW0=
-----END CERTIFICATE-----
Root CA for the Jenkins community. Used to generate official update center.
This is the v2 key generated in preparation for the expiration of the v1 key.
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册