Debian Security Advisory

DLA-2593-1 ca-certificates -- LTS security update

Date Reported:
14 Mar 2021
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 962596.
More information:

This update reverts the Symantec CA blacklist (which was originally + GeoTrust Global CA + GeoTrust Primary Certification Authority + "GeoTrust Primary Certification Authority - G2" + "GeoTrust Primary Certification Authority - G3" + GeoTrust Universal CA + thawte Primary Root CA + "thawte Primary Root CA - G2" + "thawte Primary Root CA - G3" + "VeriSign Class 3 Public Primary Certification Authority - G4" + "VeriSign Class 3 Public Primary Certification Authority - G5" + VeriSign Universal Root Certification Authority

Note: due to bug #743339, CA certificates added back in this version won't automatically be trusted again on upgrade. Affected users may need to reconfigure the package to restore the desired state.

For Debian 9 stretch, this problem has been fixed in version 20200601~deb9u2.

We recommend that you upgrade your ca-certificates packages.

For the detailed security status of ca-certificates please refer to its security tracker page at:

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: