aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyle Evans <kevans@FreeBSD.org>2023-06-25 23:47:49 +0000
committerKyle Evans <kevans@FreeBSD.org>2023-06-25 23:49:07 +0000
commitee0aa1ce12b3caea34477a31e9d2111a329e33b9 (patch)
treec92e47b3fbadbabfb68576992686648d0902c709
parentc079bcbc60e8d830e6d59bb96b43dca51a84167e (diff)
downloadsrc-ee0aa1ce12b3caea34477a31e9d2111a329e33b9.tar.gz
src-ee0aa1ce12b3caea34477a31e9d2111a329e33b9.zip
caroot: add new certs
Based on dates, these were likely just missed in the last update... add them now. - Twenty (20) new
-rw-r--r--secure/caroot/trusted/BJCA_Global_Root_CA1.pem135
-rw-r--r--secure/caroot/trusted/BJCA_Global_Root_CA2.pem67
-rw-r--r--secure/caroot/trusted/Certainly_Root_E1.pem66
-rw-r--r--secure/caroot/trusted/Certainly_Root_R1.pem134
-rw-r--r--secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem79
-rw-r--r--secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem79
-rw-r--r--secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem67
-rw-r--r--secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem134
-rw-r--r--secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem73
-rw-r--r--secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem140
-rw-r--r--secure/caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem68
-rw-r--r--secure/caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem136
-rw-r--r--secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem134
-rw-r--r--secure/caroot/trusted/ISRG_Root_X2.pem67
-rw-r--r--secure/caroot/trusted/Security_Communication_ECC_RootCA1.pem67
-rw-r--r--secure/caroot/trusted/Security_Communication_RootCA3.pem135
-rw-r--r--secure/caroot/trusted/Telia_Root_CA_v2.pem138
-rw-r--r--secure/caroot/trusted/TunTrust_Root_CA.pem139
-rw-r--r--secure/caroot/trusted/vTrus_ECC_Root_CA.pem67
-rw-r--r--secure/caroot/trusted/vTrus_Root_CA.pem134
20 files changed, 2059 insertions, 0 deletions
diff --git a/secure/caroot/trusted/BJCA_Global_Root_CA1.pem b/secure/caroot/trusted/BJCA_Global_Root_CA1.pem
new file mode 100644
index 000000000000..889f140decc8
--- /dev/null
+++ b/secure/caroot/trusted/BJCA_Global_Root_CA1.pem
@@ -0,0 +1,135 @@
+##
+## BJCA Global Root CA1
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 55:6f:65:e3:b4:d9:90:6a:1b:09:d1:6c:3e:c0:6c:20
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA1
+ Validity
+ Not Before: Dec 19 03:16:17 2019 GMT
+ Not After : Dec 12 03:16:17 2044 GMT
+ Subject: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:f1:66:08:bd:d9:c5:15:61:cb:84:04:41:a5:69:
+ 37:77:1d:c1:b0:7b:fa:c3:77:48:90:13:72:64:d1:
+ b8:7c:90:35:9d:18:79:88:e3:97:01:3c:47:81:f2:
+ 0e:a2:98:0d:9e:3f:37:e0:19:b2:90:f2:46:1c:92:
+ b1:3a:61:ce:fa:b7:46:9e:03:86:d7:33:6e:ed:f7:
+ 45:8c:76:37:de:6e:96:91:f7:d7:7e:2b:87:17:d5:
+ 8b:35:ee:84:91:72:57:dc:60:c3:c3:b9:e7:c7:67:
+ 24:23:4f:63:0a:63:f6:66:7d:4b:55:a7:3f:78:64:
+ 49:69:12:97:e0:4c:0d:d3:09:a0:32:30:3a:fa:9f:
+ c0:f2:9c:c5:12:2a:2e:1c:b5:04:33:da:a4:38:11:
+ 6a:de:c6:18:f6:47:3a:22:41:87:22:fc:c4:89:28:
+ 54:d8:8c:a5:30:0a:f8:17:16:ca:ac:37:fd:79:a7:
+ 91:17:78:38:99:ad:58:ed:b2:de:cc:89:7d:03:9c:
+ b3:89:65:e7:e3:3b:b1:22:86:8f:06:6d:78:07:fd:
+ 91:12:7f:b0:6b:1c:89:0d:f9:b8:cb:74:5b:07:c2:
+ c8:f4:35:d1:64:63:7a:e9:6e:9a:28:d6:30:bd:e6:
+ 1b:dd:15:af:84:ea:9c:c7:ca:f5:0e:ea:f2:5d:29:
+ 87:8f:69:73:39:be:2e:24:6f:45:21:ac:c5:d4:69:
+ 25:06:83:ad:7a:48:85:13:2c:0d:06:b8:6c:79:56:
+ fc:a3:67:32:81:f5:57:a5:ca:57:42:69:e9:5c:24:
+ 61:ef:e2:30:18:4e:44:98:55:6f:7a:c2:93:d8:19:
+ b6:de:7c:47:8a:11:4e:49:47:db:28:94:02:0b:94:
+ 4a:2c:f9:12:d0:4f:e8:31:7e:6c:7a:bf:a6:3f:9b:
+ 39:3d:02:16:a3:18:b3:67:ac:5b:3f:2c:83:2b:67:
+ 39:81:5c:b9:7e:94:d5:64:dd:9e:8f:6e:ae:e8:7c:
+ 5b:b4:d7:6a:47:48:d7:7e:b3:d4:2d:8e:56:76:4e:
+ cf:69:f1:6e:44:6c:d4:24:ea:8d:24:a1:18:bf:bd:
+ 57:fe:a9:99:35:b5:db:10:77:b8:3d:48:ba:d6:c1:
+ e7:f1:23:3e:d7:df:85:9d:27:3c:d4:40:bd:0a:0c:
+ bd:f5:e7:8d:25:d6:81:74:87:46:d4:29:75:a2:42:
+ 6c:f7:73:89:e7:7d:bf:7a:4a:1f:d3:22:c9:15:55:
+ cf:df:6f:7c:55:d0:a4:8b:07:11:37:5f:83:a6:26:
+ 57:a6:01:5b:7e:fe:58:68:07:a9:e9:7a:d9:b9:e8:
+ ff:50:1f:ab:c2:b4:c0:ce:e8:ea:fd:0f:bd:8d:4d:
+ b8:bc:71
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ C5:EF:ED:CC:D8:8D:21:C6:48:E4:E3:D7:14:2E:A7:16:93:E5:98:01
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ 52:82:ac:21:34:1f:23:f2:a2:d8:f9:b8:af:37:36:20:89:d1:
+ 37:03:d6:69:9f:b8:61:10:ba:a2:31:98:59:47:e8:d1:0d:25:
+ 1e:15:41:0c:e0:2a:55:d5:57:52:cb:f8:e4:c7:69:a3:1d:4d:
+ 71:02:5e:5f:21:45:60:48:5c:09:8e:49:10:c1:04:dc:a9:62:
+ 6b:02:f0:43:c8:4e:9d:38:49:74:c9:32:70:54:6d:c1:47:fc:
+ 8e:b4:36:9e:d4:9c:bd:dd:20:d6:53:c9:18:a9:b5:56:b9:76:
+ 8b:95:67:66:ee:bd:98:fe:ae:ef:be:6e:fb:60:f6:fd:59:c6:
+ 2a:1b:3f:23:4a:94:24:30:27:c8:89:bc:eb:44:24:9a:cb:3d:
+ be:4f:d5:7a:ce:8e:17:cb:62:c1:d9:de:1e:0e:7a:ff:43:86:
+ 34:52:bc:61:3f:3c:5f:bb:d9:76:b4:53:bc:97:b3:fe:8a:4c:
+ 12:2e:2b:f3:d7:ce:e1:a2:ff:dd:7b:70:fb:3b:a1:4d:a4:63:
+ 02:fd:38:97:95:3f:05:70:a0:6b:df:62:81:43:8b:b4:59:0d:
+ 4a:8c:54:9c:c5:bb:81:9f:cd:7d:a5:ef:0b:25:1e:3a:20:db:
+ 1c:fc:1f:98:67:02:0a:d4:73:44:13:db:51:84:1a:55:03:56:
+ e0:00:7e:74:06:ff:38:c4:72:1d:d3:a8:3f:68:31:5d:d3:09:
+ c7:2e:8c:5b:63:e0:e8:dc:1e:d2:ec:61:1e:f2:de:e5:ef:f6:
+ 99:76:60:2d:1e:94:72:71:c6:0b:2a:32:c7:92:4e:d5:46:d7:
+ 1d:f9:a9:19:0a:c8:fa:95:ce:6d:23:98:aa:0b:38:ad:9a:56:
+ 0d:6f:8d:f1:31:00:88:c1:17:9c:cd:19:36:35:fe:55:53:a0:
+ e0:3c:33:5f:96:5e:e2:32:e9:df:33:bb:06:4a:a9:d8:84:73:
+ ce:77:d2:c6:ac:71:e1:5c:a3:1d:0c:bb:0a:df:5f:e2:a3:71:
+ d8:da:37:5a:a0:78:2b:f4:d4:7d:eb:76:ed:f2:61:70:a5:65:
+ 9a:d3:89:34:18:ab:fb:72:3e:d7:b4:3d:79:5c:d8:1f:a1:33:
+ 7b:d9:82:50:0c:93:17:aa:6c:dc:c2:82:bb:02:57:36:af:98:
+ 27:2a:39:50:e1:b0:89:f5:25:97:7e:47:68:10:b4:ec:73:ca:
+ b3:97:d1:24:dc:f6:62:a0:28:d3:b5:a3:b8:64:b7:88:62:42:
+ cf:9d:53:cd:99:be:64:68:8f:4f:1e:12:48:f7:d2:29:c3:98:
+ 28:ca:f2:32:0b:93:8c:29:4f:3c:60:32:cd:05:96:61:ec:f2:
+ af:fe:b3:70:2c:2e:a6:f2
+SHA1 Fingerprint=D5:EC:8D:7B:4C:BA:79:F4:E7:E8:CB:9D:6B:AE:77:83:10:03:21:6A
+-----BEGIN CERTIFICATE-----
+MIIFdDCCA1ygAwIBAgIQVW9l47TZkGobCdFsPsBsIDANBgkqhkiG9w0BAQsFADBU
+MQswCQYDVQQGEwJDTjEmMCQGA1UECgwdQkVJSklORyBDRVJUSUZJQ0FURSBBVVRI
+T1JJVFkxHTAbBgNVBAMMFEJKQ0EgR2xvYmFsIFJvb3QgQ0ExMB4XDTE5MTIxOTAz
+MTYxN1oXDTQ0MTIxMjAzMTYxN1owVDELMAkGA1UEBhMCQ04xJjAkBgNVBAoMHUJF
+SUpJTkcgQ0VSVElGSUNBVEUgQVVUSE9SSVRZMR0wGwYDVQQDDBRCSkNBIEdsb2Jh
+bCBSb290IENBMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAPFmCL3Z
+xRVhy4QEQaVpN3cdwbB7+sN3SJATcmTRuHyQNZ0YeYjjlwE8R4HyDqKYDZ4/N+AZ
+spDyRhySsTphzvq3Rp4Dhtczbu33RYx2N95ulpH3134rhxfVizXuhJFyV9xgw8O5
+58dnJCNPYwpj9mZ9S1WnP3hkSWkSl+BMDdMJoDIwOvqfwPKcxRIqLhy1BDPapDgR
+at7GGPZHOiJBhyL8xIkoVNiMpTAK+BcWyqw3/XmnkRd4OJmtWO2y3syJfQOcs4ll
+5+M7sSKGjwZteAf9kRJ/sGsciQ35uMt0WwfCyPQ10WRjeulumijWML3mG90Vr4Tq
+nMfK9Q7q8l0ph49pczm+LiRvRSGsxdRpJQaDrXpIhRMsDQa4bHlW/KNnMoH1V6XK
+V0Jp6VwkYe/iMBhORJhVb3rCk9gZtt58R4oRTklH2yiUAguUSiz5EtBP6DF+bHq/
+pj+bOT0CFqMYs2esWz8sgytnOYFcuX6U1WTdno9uruh8W7TXakdI136z1C2OVnZO
+z2nxbkRs1CTqjSShGL+9V/6pmTW12xB3uD1IutbB5/EjPtffhZ0nPNRAvQoMvfXn
+jSXWgXSHRtQpdaJCbPdzied9v3pKH9MiyRVVz99vfFXQpIsHETdfg6YmV6YBW37+
+WGgHqel62bno/1Afq8K0wM7o6v0PvY1NuLxxAgMBAAGjQjBAMB0GA1UdDgQWBBTF
+7+3M2I0hxkjk49cULqcWk+WYATAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQE
+AwIBBjANBgkqhkiG9w0BAQsFAAOCAgEAUoKsITQfI/Ki2Pm4rzc2IInRNwPWaZ+4
+YRC6ojGYWUfo0Q0lHhVBDOAqVdVXUsv45Mdpox1NcQJeXyFFYEhcCY5JEMEE3Kli
+awLwQ8hOnThJdMkycFRtwUf8jrQ2ntScvd0g1lPJGKm1Vrl2i5VnZu69mP6u775u
++2D2/VnGKhs/I0qUJDAnyIm860Qkmss9vk/Ves6OF8tiwdneHg56/0OGNFK8YT88
+X7vZdrRTvJez/opMEi4r89fO4aL/3Xtw+zuhTaRjAv04l5U/BXCga99igUOLtFkN
+SoxUnMW7gZ/NfaXvCyUeOiDbHPwfmGcCCtRzRBPbUYQaVQNW4AB+dAb/OMRyHdOo
+P2gxXdMJxy6MW2Pg6Nwe0uxhHvLe5e/2mXZgLR6UcnHGCyoyx5JO1UbXHfmpGQrI
++pXObSOYqgs4rZpWDW+N8TEAiMEXnM0ZNjX+VVOg4DwzX5Ze4jLp3zO7Bkqp2IRz
+znfSxqxx4VyjHQy7Ct9f4qNx2No3WqB4K/TUfet27fJhcKVlmtOJNBir+3I+17Q9
+eVzYH6Eze9mCUAyTF6ps3MKCuwJXNq+YJyo5UOGwifUll35HaBC07HPKs5fRJNz2
+YqAo07WjuGS3iGJCz51TzZm+ZGiPTx4SSPfSKcOYKMryMguTjClPPGAyzQWWYezy
+r/6zcCwupvI=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/BJCA_Global_Root_CA2.pem b/secure/caroot/trusted/BJCA_Global_Root_CA2.pem
new file mode 100644
index 000000000000..da44a530a038
--- /dev/null
+++ b/secure/caroot/trusted/BJCA_Global_Root_CA2.pem
@@ -0,0 +1,67 @@
+##
+## BJCA Global Root CA2
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 2c:17:08:7d:64:2a:c0:fe:85:18:59:06:cf:b4:4a:eb
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA2
+ Validity
+ Not Before: Dec 19 03:18:21 2019 GMT
+ Not After : Dec 12 03:18:21 2044 GMT
+ Subject: C = CN, O = BEIJING CERTIFICATE AUTHORITY, CN = BJCA Global Root CA2
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:9d:cb:80:91:8d:53:67:b5:b9:50:b1:03:f8:e5:
+ 49:1f:41:22:09:b0:51:52:58:d6:2b:34:8f:c5:12:
+ 46:14:c5:8b:2f:2c:84:ff:2c:6e:a8:d5:f1:09:e3:
+ 03:21:14:c4:43:3d:7c:c1:2c:c4:4b:6a:4a:cd:e9:
+ 87:e0:7d:f6:22:be:fa:4a:51:b8:30:8a:fd:e1:de:
+ 18:12:0a:f6:47:b7:e7:17:bf:27:8a:d4:41:4c:96:
+ 3c:60:96:c1:fd:15:1c
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ D2:4A:B1:51:7F:06:F0:D1:82:1F:4E:6E:5F:AB:83:FC:48:D4:B0:91
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:30:1a:bc:5b:d7:fe:a9:d2:54:0e:4a:5d:d2:6d:b1:
+ 40:dc:f4:43:d5:d2:4a:99:19:12:56:80:f7:83:34:e1:35:4e:
+ 48:6d:04:0f:57:31:30:30:2d:b1:aa:9d:03:38:db:06:02:31:
+ 00:cb:cc:87:53:cb:7a:df:20:51:73:90:c0:a8:5b:61:d0:c5:
+ 50:39:fd:85:fe:c1:e3:78:f8:a6:d6:4b:bd:9b:87:8f:0f:e5:
+ d6:53:96:ab:3c:c8:40:da:61:f7:53:a3:f7
+SHA1 Fingerprint=F4:27:86:EB:6E:B8:6D:88:31:67:02:FB:BA:66:A4:53:00:AA:7A:A6
+-----BEGIN CERTIFICATE-----
+MIICJTCCAaugAwIBAgIQLBcIfWQqwP6FGFkGz7RK6zAKBggqhkjOPQQDAzBUMQsw
+CQYDVQQGEwJDTjEmMCQGA1UECgwdQkVJSklORyBDRVJUSUZJQ0FURSBBVVRIT1JJ
+VFkxHTAbBgNVBAMMFEJKQ0EgR2xvYmFsIFJvb3QgQ0EyMB4XDTE5MTIxOTAzMTgy
+MVoXDTQ0MTIxMjAzMTgyMVowVDELMAkGA1UEBhMCQ04xJjAkBgNVBAoMHUJFSUpJ
+TkcgQ0VSVElGSUNBVEUgQVVUSE9SSVRZMR0wGwYDVQQDDBRCSkNBIEdsb2JhbCBS
+b290IENBMjB2MBAGByqGSM49AgEGBSuBBAAiA2IABJ3LgJGNU2e1uVCxA/jlSR9B
+IgmwUVJY1is0j8USRhTFiy8shP8sbqjV8QnjAyEUxEM9fMEsxEtqSs3ph+B99iK+
++kpRuDCK/eHeGBIK9ke35xe/J4rUQUyWPGCWwf0VHKNCMEAwHQYDVR0OBBYEFNJK
+sVF/BvDRgh9Obl+rg/xI1LCRMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
+AgEGMAoGCCqGSM49BAMDA2gAMGUCMBq8W9f+qdJUDkpd0m2xQNz0Q9XSSpkZElaA
+94M04TVOSG0ED1cxMDAtsaqdAzjbBgIxAMvMh1PLet8gUXOQwKhbYdDFUDn9hf7B
+43j4ptZLvZuHjw/l1lOWqzzIQNph91Oj9w==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Certainly_Root_E1.pem b/secure/caroot/trusted/Certainly_Root_E1.pem
new file mode 100644
index 000000000000..0750f7128ae6
--- /dev/null
+++ b/secure/caroot/trusted/Certainly_Root_E1.pem
@@ -0,0 +1,66 @@
+##
+## Certainly Root E1
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 06:25:33:b1:47:03:33:27:5c:f9:8d:9a:b9:bf:cc:f8
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = US, O = Certainly, CN = Certainly Root E1
+ Validity
+ Not Before: Apr 1 00:00:00 2021 GMT
+ Not After : Apr 1 00:00:00 2046 GMT
+ Subject: C = US, O = Certainly, CN = Certainly Root E1
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:de:6f:f8:7f:1c:df:ed:f9:47:87:86:b1:a4:c0:
+ 8a:f8:82:97:80:ea:8f:c8:4a:5e:2a:7d:88:68:a7:
+ 01:62:14:91:24:7a:5c:9e:a3:17:7d:8a:86:21:34:
+ 18:50:1b:10:de:d0:37:4b:26:c7:19:60:80:e9:34:
+ bd:60:19:36:40:d6:29:87:09:3c:91:7a:f6:bc:13:
+ 23:dd:59:4e:04:5e:cf:c8:02:1c:18:53:c1:31:d8:
+ da:20:e9:44:8d:e4:76
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ F3:28:18:CB:64:75:EE:29:2A:EB:ED:AE:23:58:38:85:EB:C8:22:07
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:31:00:b1:8e:5a:20:c3:b2:19:62:4d:de:b0:4f:df:
+ 6e:d2:70:8a:f1:9f:7e:6a:8c:e6:ba:de:83:69:ca:69:b3:a9:
+ 05:b5:96:92:17:87:c2:d2:ea:d0:7b:ce:d8:41:5b:7c:ae:02:
+ 30:46:de:ea:cb:5d:9a:ec:32:c2:65:16:b0:4c:30:5c:30:f3:
+ da:4e:73:86:06:d8:ce:89:04:48:37:37:f8:dd:33:51:9d:70:
+ af:7b:55:d8:01:2e:7d:05:64:0e:86:b8:91
+SHA1 Fingerprint=F9:E1:6D:DC:01:89:CF:D5:82:45:63:3E:C5:37:7D:C2:EB:93:6F:2B
+-----BEGIN CERTIFICATE-----
+MIIB9zCCAX2gAwIBAgIQBiUzsUcDMydc+Y2aub/M+DAKBggqhkjOPQQDAzA9MQsw
+CQYDVQQGEwJVUzESMBAGA1UEChMJQ2VydGFpbmx5MRowGAYDVQQDExFDZXJ0YWlu
+bHkgUm9vdCBFMTAeFw0yMTA0MDEwMDAwMDBaFw00NjA0MDEwMDAwMDBaMD0xCzAJ
+BgNVBAYTAlVTMRIwEAYDVQQKEwlDZXJ0YWlubHkxGjAYBgNVBAMTEUNlcnRhaW5s
+eSBSb290IEUxMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE3m/4fxzf7flHh4axpMCK
++IKXgOqPyEpeKn2IaKcBYhSRJHpcnqMXfYqGITQYUBsQ3tA3SybHGWCA6TS9YBk2
+QNYphwk8kXr2vBMj3VlOBF7PyAIcGFPBMdjaIOlEjeR2o0IwQDAOBgNVHQ8BAf8E
+BAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQU8ygYy2R17ikq6+2uI1g4
+hevIIgcwCgYIKoZIzj0EAwMDaAAwZQIxALGOWiDDshliTd6wT99u0nCK8Z9+aozm
+ut6Dacpps6kFtZaSF4fC0urQe87YQVt8rgIwRt7qy12a7DLCZRawTDBcMPPaTnOG
+BtjOiQRINzf43TNRnXCve1XYAS59BWQOhriR
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Certainly_Root_R1.pem b/secure/caroot/trusted/Certainly_Root_R1.pem
new file mode 100644
index 000000000000..a4e6f28e33a6
--- /dev/null
+++ b/secure/caroot/trusted/Certainly_Root_R1.pem
@@ -0,0 +1,134 @@
+##
+## Certainly Root R1
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 8e:0f:f9:4b:90:71:68:65:33:54:f4:d4:44:39:b7:e0
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = US, O = Certainly, CN = Certainly Root R1
+ Validity
+ Not Before: Apr 1 00:00:00 2021 GMT
+ Not After : Apr 1 00:00:00 2046 GMT
+ Subject: C = US, O = Certainly, CN = Certainly Root R1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:d0:36:d4:1f:ea:dd:ab:e4:d1:b6:e6:fb:22:c0:
+ dd:13:0d:6a:7b:22:13:1c:97:3c:68:63:66:32:9c:
+ 03:b5:8d:a4:81:83:da:78:30:11:cf:dc:b2:2b:be:
+ 92:bf:8e:e4:c4:13:be:a4:68:4c:da:02:68:16:74:
+ be:b2:dd:04:e4:6b:2a:dd:37:1f:60:2c:db:f5:f7:
+ a1:7c:95:b7:0c:70:86:2e:f1:3a:ef:52:f7:cc:d3:
+ 9b:f9:8b:be:0e:df:31:b7:9d:68:5c:92:a6:f5:e5:
+ f3:0a:34:b5:ff:7b:a2:e4:87:a1:c6:af:17:00:ef:
+ 03:91:ed:a9:1c:4e:71:3d:d2:8b:6c:89:f4:78:86:
+ e6:6a:49:a0:ce:b5:d2:b0:ab:9b:f6:f4:d4:2e:e3:
+ 72:f9:36:c6:eb:15:b7:25:8c:3a:fc:25:0d:b3:22:
+ 73:21:74:c8:4a:96:61:92:f5:2f:0b:18:a5:f4:ad:
+ e2:ee:41:bd:01:79:fa:96:8c:8d:17:02:30:b4:f9:
+ af:78:1a:8c:b4:36:10:10:07:05:70:d0:f4:31:90:
+ 8a:51:c5:86:26:79:b2:11:88:5e:c5:f0:0a:54:cd:
+ 49:a6:bf:02:9c:d2:44:a7:ed:e3:78:ef:46:5e:6d:
+ 71:d1:79:70:1c:46:5f:51:e9:c9:37:dc:5f:7e:69:
+ 7b:41:df:34:45:e0:3b:84:f4:a1:8a:0a:36:9e:37:
+ cc:62:52:e1:89:0d:28:f9:7a:23:b1:0d:3d:3d:9a:
+ fd:9d:81:ef:2c:90:c0:7b:44:4e:bb:49:e0:0e:4a:
+ 56:92:bc:cb:b5:dd:79:17:89:91:de:61:89:74:92:
+ a8:e3:32:85:be:4e:85:a4:4b:59:cb:2b:c5:78:8e:
+ 71:54:d0:02:37:99:8c:e5:49:ea:e0:54:72:a4:11:
+ 06:2f:0b:8c:c1:5b:be:b5:a1:b0:53:6e:9c:b8:60:
+ 91:1f:59:6b:f9:2d:f4:94:0a:97:b5:ec:c5:76:03:
+ 54:1b:65:52:ba:4c:92:56:51:35:a0:40:d8:29:db:
+ ae:52:76:3b:2d:30:40:9b:8a:d0:42:56:b4:b7:88:
+ 01:a4:87:3b:53:96:cd:a3:16:8f:f3:66:aa:17:b1:
+ c7:60:e0:c1:43:05:0c:ee:9b:5b:60:6f:06:5c:87:
+ 5b:27:f9:40:11:9e:9c:33:c1:b7:e5:35:57:05:7f:
+ 27:ce:17:20:8c:1c:fc:f1:fb:da:31:29:49:ed:f5:
+ 0b:84:a7:4f:c1:f6:4e:c2:28:9c:fa:ee:e0:af:07:
+ fb:33:11:7a:21:4f:0b:21:10:b6:40:3a:ab:22:3a:
+ 04:9c:8b:9b:84:86:72:9a:d2:a7:a5:c4:b4:75:91:
+ a9:2b:23
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ E0:AA:3F:25:8D:9F:44:5C:C1:3A:E8:2E:AE:77:4C:84:3E:67:0C:F4
+ Signature Algorithm: sha256WithRSAEncryption
+ b9:57:af:b8:12:da:57:83:8f:68:0b:33:1d:03:53:55:f4:95:
+ 70:e4:2b:3d:b0:39:eb:fa:89:62:fd:f7:d6:18:04:2f:21:34:
+ dd:f1:68:f0:d5:96:5a:de:c2:80:a3:c1:8d:c6:6a:f7:59:77:
+ ae:15:64:cf:5b:79:05:77:66:ea:8c:d3:6b:0d:dd:f1:59:2c:
+ c1:33:a5:30:80:15:45:07:45:1a:31:22:b6:92:00:ab:99:4d:
+ 3a:8f:77:af:a9:22:ca:2f:63:ca:15:d6:c7:c6:f0:3d:6c:fc:
+ 1c:0d:98:10:61:9e:11:a2:22:d7:0a:f2:91:7a:6b:39:0e:2f:
+ 30:c3:36:49:9f:e0:e9:0f:02:44:50:37:94:55:7d:ea:9f:f6:
+ 3b:ba:94:a5:4c:e9:bc:3e:51:b4:e8:ca:92:36:54:6d:5c:25:
+ 28:da:dd:ad:14:fd:d3:ee:e2:22:05:eb:d0:f2:b7:68:12:d7:
+ 5a:8a:41:1a:c6:92:a5:5a:3b:63:45:4f:bf:e1:3a:77:22:2f:
+ 5c:bf:46:f9:5a:03:85:13:42:5f:ca:de:53:d7:62:b5:a6:35:
+ 04:c2:47:ff:99:fd:84:df:5c:ce:e9:5e:80:28:41:f2:7d:e7:
+ 1e:90:d8:4f:76:3e:82:3c:0d:fc:a5:03:fa:7b:1a:d9:45:1e:
+ 60:da:c4:8e:f9:fc:2b:c9:7b:95:c5:2a:ff:aa:89:df:82:31:
+ 0f:72:ff:0c:27:d7:0a:1e:56:00:50:1e:0c:90:c1:96:b5:d8:
+ 14:85:bb:a7:0d:16:c1:f8:07:24:1b:ba:85:a1:1a:05:09:80:
+ ba:95:63:c9:3a:ec:25:9f:7f:9d:ba:a4:47:15:9b:44:70:f1:
+ 6a:4b:d6:38:5e:43:f3:18:7e:50:6e:e9:5a:28:e6:65:e6:77:
+ 1b:3a:fd:1d:be:03:26:a3:db:d4:e1:bb:7e:96:27:2b:1d:ee:
+ a4:fb:da:25:54:13:03:de:39:c6:c3:1f:4d:90:ec:8f:1b:4a:
+ d2:1c:ed:85:95:38:50:79:46:d6:c1:90:50:31:a9:5c:9a:6e:
+ 1d:f5:33:56:8b:a7:99:d2:f2:c8:2c:33:93:92:30:c7:4e:8c:
+ 65:33:10:64:17:fd:24:17:96:d1:8d:c2:3a:6a:2b:eb:13:8b:
+ 44:f2:21:f3:4a:1a:b7:77:5f:d7:ed:88:a4:72:e5:39:1f:95:
+ 9d:be:67:c1:70:11:3d:bb:f4:f8:49:b7:e3:26:97:3a:9f:d2:
+ 5f:7c:fb:c0:99:7c:39:29:e0:7b:1d:bf:0d:a7:8f:d2:29:34:
+ 6e:24:15:cb:de:90:5e:bf:1a:c4:66:ea:c2:e6:ba:39:5f:8a:
+ 99:a9:41:59:07:b0:2c:af
+SHA1 Fingerprint=A0:50:EE:0F:28:71:F4:27:B2:12:6D:6F:50:96:25:BA:CC:86:42:AF
+-----BEGIN CERTIFICATE-----
+MIIFRzCCAy+gAwIBAgIRAI4P+UuQcWhlM1T01EQ5t+AwDQYJKoZIhvcNAQELBQAw
+PTELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUNlcnRhaW5seTEaMBgGA1UEAxMRQ2Vy
+dGFpbmx5IFJvb3QgUjEwHhcNMjEwNDAxMDAwMDAwWhcNNDYwNDAxMDAwMDAwWjA9
+MQswCQYDVQQGEwJVUzESMBAGA1UEChMJQ2VydGFpbmx5MRowGAYDVQQDExFDZXJ0
+YWlubHkgUm9vdCBSMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANA2
+1B/q3avk0bbm+yLA3RMNansiExyXPGhjZjKcA7WNpIGD2ngwEc/csiu+kr+O5MQT
+vqRoTNoCaBZ0vrLdBORrKt03H2As2/X3oXyVtwxwhi7xOu9S98zTm/mLvg7fMbed
+aFySpvXl8wo0tf97ouSHocavFwDvA5HtqRxOcT3Si2yJ9HiG5mpJoM610rCrm/b0
+1C7jcvk2xusVtyWMOvwlDbMicyF0yEqWYZL1LwsYpfSt4u5BvQF5+paMjRcCMLT5
+r3gajLQ2EBAHBXDQ9DGQilHFhiZ5shGIXsXwClTNSaa/ApzSRKft43jvRl5tcdF5
+cBxGX1HpyTfcX35pe0HfNEXgO4T0oYoKNp43zGJS4YkNKPl6I7ENPT2a/Z2B7yyQ
+wHtETrtJ4A5KVpK8y7XdeReJkd5hiXSSqOMyhb5OhaRLWcsrxXiOcVTQAjeZjOVJ
+6uBUcqQRBi8LjMFbvrWhsFNunLhgkR9Za/kt9JQKl7XsxXYDVBtlUrpMklZRNaBA
+2CnbrlJ2Oy0wQJuK0EJWtLeIAaSHO1OWzaMWj/Nmqhexx2DgwUMFDO6bW2BvBlyH
+Wyf5QBGenDPBt+U1VwV/J84XIIwc/PH72jEpSe31C4SnT8H2TsIonPru4K8H+zMR
+eiFPCyEQtkA6qyI6BJyLm4SGcprSp6XEtHWRqSsjAgMBAAGjQjBAMA4GA1UdDwEB
+/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTgqj8ljZ9EXME66C6u
+d0yEPmcM9DANBgkqhkiG9w0BAQsFAAOCAgEAuVevuBLaV4OPaAszHQNTVfSVcOQr
+PbA56/qJYv331hgELyE03fFo8NWWWt7CgKPBjcZq91l3rhVkz1t5BXdm6ozTaw3d
+8VkswTOlMIAVRQdFGjEitpIAq5lNOo93r6kiyi9jyhXWx8bwPWz8HA2YEGGeEaIi
+1wrykXprOQ4vMMM2SZ/g6Q8CRFA3lFV96p/2O7qUpUzpvD5RtOjKkjZUbVwlKNrd
+rRT90+7iIgXr0PK3aBLXWopBGsaSpVo7Y0VPv+E6dyIvXL9G+VoDhRNCX8reU9di
+taY1BMJH/5n9hN9czulegChB8n3nHpDYT3Y+gjwN/KUD+nsa2UUeYNrEjvn8K8l7
+lcUq/6qJ34IxD3L/DCfXCh5WAFAeDJDBlrXYFIW7pw0WwfgHJBu6haEaBQmAupVj
+yTrsJZ9/nbqkRxWbRHDxakvWOF5D8xh+UG7pWijmZeZ3Gzr9Hb4DJqPb1OG7fpYn
+Kx3upPvaJVQTA945xsMfTZDsjxtK0hzthZU4UHlG1sGQUDGpXJpuHfUzVounmdLy
+yCwzk5Iwx06MZTMQZBf9JBeW0Y3COmor6xOLRPIh80oat3df1+2IpHLlOR+Vnb5n
+wXARPbv0+Em34yaXOp/SX3z7wJl8OSngex2/DaeP0ik0biQVy96QXr8axGbqwua6
+OV+KmalBWQewLK8=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem b/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem
new file mode 100644
index 000000000000..758d61032898
--- /dev/null
+++ b/secure/caroot/trusted/D-TRUST_BR_Root_CA_1_2020.pem
@@ -0,0 +1,79 @@
+##
+## D-TRUST BR Root CA 1 2020
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 7c:c9:8f:2b:84:d7:df:ea:0f:c9:65:9a:d3:4b:4d:96
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST BR Root CA 1 2020
+ Validity
+ Not Before: Feb 11 09:45:00 2020 GMT
+ Not After : Feb 11 09:44:59 2035 GMT
+ Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST BR Root CA 1 2020
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:c6:cb:c7:28:d1:fb:84:f5:9a:ef:42:14:20:e1:
+ 43:6b:6e:75:ad:fc:2b:03:84:d4:76:93:25:d7:59:
+ 3b:41:65:6b:1e:e6:34:2a:bb:74:f6:12:ce:e8:6d:
+ e7:ab:e4:3c:4e:3f:44:08:8b:cd:16:71:cb:bf:92:
+ 99:f4:a4:d7:3c:50:54:52:90:85:83:78:94:67:67:
+ a3:1c:09:19:3d:75:34:85:de:ed:60:7d:c7:0c:b4:
+ 41:52:b9:6e:e5:ee:42
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 73:91:10:AB:FF:55:B3:5A:7C:09:25:D5:B2:BA:08:A0:6B:AB:1F:6D
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 CRL Distribution Points:
+
+ Full Name:
+ URI:http://crl.d-trust.net/crl/d-trust_br_root_ca_1_2020.crl
+
+ Full Name:
+ URI:ldap://directory.d-trust.net/CN=D-TRUST%20BR%20Root%20CA%201%202020,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:66:02:31:00:94:90:2d:13:fa:e1:63:f8:61:63:e8:ad:85:
+ 78:54:91:9c:b8:93:38:3e:1a:41:da:40:16:53:42:08:ca:2f:
+ 8e:f1:3e:81:56:c0:aa:d8:ed:18:c4:b0:ae:f4:3e:fa:26:02:
+ 31:00:f3:28:e2:c6:db:2b:99:fb:b7:51:b8:24:a3:a4:94:7a:
+ 1a:3f:e6:36:e2:03:57:33:8a:30:cb:82:c7:d6:14:11:d5:75:
+ 63:5b:14:95:9c:1f:01:cf:d8:d5:72:a7:0f:3b
+SHA1 Fingerprint=1F:5B:98:F0:E3:B5:F7:74:3C:ED:E6:B0:36:7D:32:CD:F4:09:41:67
+-----BEGIN CERTIFICATE-----
+MIIC2zCCAmCgAwIBAgIQfMmPK4TX3+oPyWWa00tNljAKBggqhkjOPQQDAzBIMQsw
+CQYDVQQGEwJERTEVMBMGA1UEChMMRC1UcnVzdCBHbWJIMSIwIAYDVQQDExlELVRS
+VVNUIEJSIFJvb3QgQ0EgMSAyMDIwMB4XDTIwMDIxMTA5NDUwMFoXDTM1MDIxMTA5
+NDQ1OVowSDELMAkGA1UEBhMCREUxFTATBgNVBAoTDEQtVHJ1c3QgR21iSDEiMCAG
+A1UEAxMZRC1UUlVTVCBCUiBSb290IENBIDEgMjAyMDB2MBAGByqGSM49AgEGBSuB
+BAAiA2IABMbLxyjR+4T1mu9CFCDhQ2tuda38KwOE1HaTJddZO0Flax7mNCq7dPYS
+zuht56vkPE4/RAiLzRZxy7+SmfSk1zxQVFKQhYN4lGdnoxwJGT11NIXe7WB9xwy0
+QVK5buXuQqOCAQ0wggEJMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFHOREKv/
+VbNafAkl1bK6CKBrqx9tMA4GA1UdDwEB/wQEAwIBBjCBxgYDVR0fBIG+MIG7MD6g
+PKA6hjhodHRwOi8vY3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X2JyX3Jvb3Rf
+Y2FfMV8yMDIwLmNybDB5oHegdYZzbGRhcDovL2RpcmVjdG9yeS5kLXRydXN0Lm5l
+dC9DTj1ELVRSVVNUJTIwQlIlMjBSb290JTIwQ0ElMjAxJTIwMjAyMCxPPUQtVHJ1
+c3QlMjBHbWJILEM9REU/Y2VydGlmaWNhdGVyZXZvY2F0aW9ubGlzdDAKBggqhkjO
+PQQDAwNpADBmAjEAlJAtE/rhY/hhY+ithXhUkZy4kzg+GkHaQBZTQgjKL47xPoFW
+wKrY7RjEsK70PvomAjEA8yjixtsrmfu3Ubgko6SUeho/5jbiA1czijDLgsfWFBHV
+dWNbFJWcHwHP2NVypw87
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem b/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem
new file mode 100644
index 000000000000..76991855eaa1
--- /dev/null
+++ b/secure/caroot/trusted/D-TRUST_EV_Root_CA_1_2020.pem
@@ -0,0 +1,79 @@
+##
+## D-TRUST EV Root CA 1 2020
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 5f:02:41:d7:7a:87:7c:4c:03:a3:ac:96:8d:fb:ff:d0
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = DE, O = D-Trust GmbH, CN = D-TRUST EV Root CA 1 2020
+ Validity
+ Not Before: Feb 11 10:00:00 2020 GMT
+ Not After : Feb 11 09:59:59 2035 GMT
+ Subject: C = DE, O = D-Trust GmbH, CN = D-TRUST EV Root CA 1 2020
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:f1:0b:dd:86:43:20:19:df:97:85:e8:22:4a:9b:
+ cf:9d:98:bf:b4:05:26:c9:cb:e3:a6:d2:8f:c5:9e:
+ 78:7b:31:89:a9:89:ad:27:3c:65:10:82:fc:df:c3:
+ 9d:4e:f0:33:23:c4:d2:32:f5:1c:b0:df:33:17:5d:
+ c5:f0:b1:8a:f9:ef:b9:b7:14:ca:29:4a:c2:0f:a9:
+ 7f:75:65:49:2a:30:67:f4:64:f7:d6:1a:77:da:c3:
+ c2:97:61:42:7b:49:ad
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 7F:10:01:16:37:3A:A4:28:E4:50:F8:A4:F7:EC:6B:32:B6:FE:E9:8B
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 CRL Distribution Points:
+
+ Full Name:
+ URI:http://crl.d-trust.net/crl/d-trust_ev_root_ca_1_2020.crl
+
+ Full Name:
+ URI:ldap://directory.d-trust.net/CN=D-TRUST%20EV%20Root%20CA%201%202020,O=D-Trust%20GmbH,C=DE?certificaterevocationlist
+
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:66:02:31:00:ca:3c:c6:2a:75:c2:5e:75:62:39:36:00:60:
+ 5a:8b:c1:93:99:cc:d9:db:41:3b:3b:87:99:17:3b:d5:cc:4f:
+ ca:22:f7:a0:80:cb:f9:b4:b1:1b:56:f5:72:d2:fc:19:d1:02:
+ 31:00:91:f7:30:93:3f:10:46:2b:71:a4:d0:3b:44:9b:c0:29:
+ 02:05:b2:41:77:51:f3:79:5a:9e:8e:14:a0:4e:42:d2:5b:81:
+ f3:34:6a:03:e7:22:38:50:5b:ed:19:4f:43:16
+SHA1 Fingerprint=61:DB:8C:21:59:69:03:90:D8:7C:9C:12:86:54:CF:9D:3D:F4:DD:07
+-----BEGIN CERTIFICATE-----
+MIIC2zCCAmCgAwIBAgIQXwJB13qHfEwDo6yWjfv/0DAKBggqhkjOPQQDAzBIMQsw
+CQYDVQQGEwJERTEVMBMGA1UEChMMRC1UcnVzdCBHbWJIMSIwIAYDVQQDExlELVRS
+VVNUIEVWIFJvb3QgQ0EgMSAyMDIwMB4XDTIwMDIxMTEwMDAwMFoXDTM1MDIxMTA5
+NTk1OVowSDELMAkGA1UEBhMCREUxFTATBgNVBAoTDEQtVHJ1c3QgR21iSDEiMCAG
+A1UEAxMZRC1UUlVTVCBFViBSb290IENBIDEgMjAyMDB2MBAGByqGSM49AgEGBSuB
+BAAiA2IABPEL3YZDIBnfl4XoIkqbz52Yv7QFJsnL46bSj8WeeHsxiamJrSc8ZRCC
+/N/DnU7wMyPE0jL1HLDfMxddxfCxivnvubcUyilKwg+pf3VlSSowZ/Rk99Yad9rD
+wpdhQntJraOCAQ0wggEJMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFH8QARY3
+OqQo5FD4pPfsazK2/umLMA4GA1UdDwEB/wQEAwIBBjCBxgYDVR0fBIG+MIG7MD6g
+PKA6hjhodHRwOi8vY3JsLmQtdHJ1c3QubmV0L2NybC9kLXRydXN0X2V2X3Jvb3Rf
+Y2FfMV8yMDIwLmNybDB5oHegdYZzbGRhcDovL2RpcmVjdG9yeS5kLXRydXN0Lm5l
+dC9DTj1ELVRSVVNUJTIwRVYlMjBSb290JTIwQ0ElMjAxJTIwMjAyMCxPPUQtVHJ1
+c3QlMjBHbWJILEM9REU/Y2VydGlmaWNhdGVyZXZvY2F0aW9ubGlzdDAKBggqhkjO
+PQQDAwNpADBmAjEAyjzGKnXCXnViOTYAYFqLwZOZzNnbQTs7h5kXO9XMT8oi96CA
+y/m0sRtW9XLS/BnRAjEAkfcwkz8QRitxpNA7RJvAKQIFskF3UfN5Wp6OFKBOQtJb
+gfM0agPnIjhQW+0ZT0MW
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem b/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem
new file mode 100644
index 000000000000..a6f2e6a0c771
--- /dev/null
+++ b/secure/caroot/trusted/DigiCert_TLS_ECC_P384_Root_G5.pem
@@ -0,0 +1,67 @@
+##
+## DigiCert TLS ECC P384 Root G5
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 09:e0:93:65:ac:f7:d9:c8:b9:3e:1c:0b:04:2a:2e:f3
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS ECC P384 Root G5
+ Validity
+ Not Before: Jan 15 00:00:00 2021 GMT
+ Not After : Jan 14 23:59:59 2046 GMT
+ Subject: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS ECC P384 Root G5
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:c1:44:a1:cf:11:97:50:9a:de:23:82:35:07:cd:
+ d0:cb:18:9d:d2:f1:7f:77:35:4f:3b:dd:94:72:52:
+ ed:c2:3b:f8:ec:fa:7b:6b:58:20:ec:99:ae:c9:fc:
+ 68:b3:75:b9:db:09:ec:c8:13:f5:4e:c6:0a:1d:66:
+ 30:4c:bb:1f:47:0a:3c:61:10:42:29:7c:a5:08:0e:
+ e0:22:e9:d3:35:68:ce:9b:63:9f:84:b5:99:4d:58:
+ a0:8e:f5:54:e7:95:c9
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ C1:51:45:50:59:AB:3E:E7:2C:5A:FA:20:22:12:07:80:88:7C:11:6A
+ X509v3 Key Usage: critical
+ Digital Signature, Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:31:00:89:6a:8d:47:e7:ec:fc:6e:55:03:d9:67:6c:
+ 26:4e:83:c6:fd:c9:fb:2b:13:bc:b7:7a:8c:b4:65:d2:69:69:
+ 63:13:63:3b:26:50:2e:01:a1:79:06:91:9d:48:bf:c2:be:02:
+ 30:47:c3:15:7b:b1:a0:91:99:49:93:a8:3c:7c:e8:46:06:8b:
+ 2c:f2:31:00:94:9d:62:c8:89:bd:19:84:14:e9:a5:fb:01:b8:
+ 0d:76:43:8c:2e:53:cb:7c:df:0c:17:96:50
+SHA1 Fingerprint=17:F3:DE:5E:9F:0F:19:E9:8E:F6:1F:32:26:6E:20:C4:07:AE:30:EE
+-----BEGIN CERTIFICATE-----
+MIICGTCCAZ+gAwIBAgIQCeCTZaz32ci5PhwLBCou8zAKBggqhkjOPQQDAzBOMQsw
+CQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xJjAkBgNVBAMTHURp
+Z2lDZXJ0IFRMUyBFQ0MgUDM4NCBSb290IEc1MB4XDTIxMDExNTAwMDAwMFoXDTQ2
+MDExNDIzNTk1OVowTjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDkRpZ2lDZXJ0LCBJ
+bmMuMSYwJAYDVQQDEx1EaWdpQ2VydCBUTFMgRUNDIFAzODQgUm9vdCBHNTB2MBAG
+ByqGSM49AgEGBSuBBAAiA2IABMFEoc8Rl1Ca3iOCNQfN0MsYndLxf3c1TzvdlHJS
+7cI7+Oz6e2tYIOyZrsn8aLN1udsJ7MgT9U7GCh1mMEy7H0cKPGEQQil8pQgO4CLp
+0zVozptjn4S1mU1YoI71VOeVyaNCMEAwHQYDVR0OBBYEFMFRRVBZqz7nLFr6ICIS
+B4CIfBFqMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MAoGCCqGSM49
+BAMDA2gAMGUCMQCJao1H5+z8blUD2WdsJk6Dxv3J+ysTvLd6jLRl0mlpYxNjOyZQ
+LgGheQaRnUi/wr4CMEfDFXuxoJGZSZOoPHzoRgaLLPIxAJSdYsiJvRmEFOml+wG4
+DXZDjC5Ty3zfDBeWUA==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem b/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem
new file mode 100644
index 000000000000..cb58c6a21418
--- /dev/null
+++ b/secure/caroot/trusted/DigiCert_TLS_RSA4096_Root_G5.pem
@@ -0,0 +1,134 @@
+##
+## DigiCert TLS RSA4096 Root G5
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 08:f9:b4:78:a8:fa:7e:da:6a:33:37:89:de:7c:cf:8a
+ Signature Algorithm: sha384WithRSAEncryption
+ Issuer: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS RSA4096 Root G5
+ Validity
+ Not Before: Jan 15 00:00:00 2021 GMT
+ Not After : Jan 14 23:59:59 2046 GMT
+ Subject: C = US, O = "DigiCert, Inc.", CN = DigiCert TLS RSA4096 Root G5
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:b3:d0:f4:c9:79:11:9d:fd:fc:66:81:e7:cc:d5:
+ e4:bc:ec:81:3e:6a:35:8e:2e:b7:e7:de:af:f9:07:
+ 4d:cf:30:9d:ea:09:0b:99:bd:6c:57:da:18:4a:b8:
+ 78:ac:3a:39:a8:a6:48:ac:2e:72:e5:bd:eb:f1:1a:
+ cd:e7:a4:03:a9:3f:11:b4:d8:2f:89:16:fb:94:01:
+ 3d:bb:2f:f8:13:05:a1:78:1c:8e:28:e0:45:e0:83:
+ f4:59:1b:95:b3:ae:7e:03:45:e5:be:c2:42:fe:ee:
+ f2:3c:b6:85:13:98:32:9d:16:a8:29:c2:0b:1c:38:
+ dc:9f:31:77:5c:bf:27:a3:fc:27:ac:b7:2b:bd:74:
+ 9b:17:2d:f2:81:da:5d:b0:e1:23:17:3e:88:4a:12:
+ 23:d0:ea:cf:9d:de:03:17:b1:42:4a:a0:16:4c:a4:
+ 6d:93:e9:3f:3a:ee:3a:7c:9d:58:9d:f4:4e:8f:fc:
+ 3b:23:c8:6d:b8:e2:05:da:cc:eb:ec:c3:31:f4:d7:
+ a7:29:54:80:cf:44:5b:4c:6f:30:9e:f3:cc:dd:1f:
+ 94:43:9d:4d:7f:70:70:0d:d4:3a:d1:37:f0:6c:9d:
+ 9b:c0:14:93:58:ef:cd:41:38:75:bc:13:03:95:7c:
+ 7f:e3:5c:e9:d5:0d:d5:e2:7c:10:62:aa:6b:f0:3d:
+ 76:f3:3f:a3:e8:b0:c1:fd:ef:aa:57:4d:ac:86:a7:
+ 18:b4:29:c1:2c:0e:bf:64:be:29:8c:d8:02:2d:cd:
+ 5c:2f:f2:7f:ef:15:f4:0c:15:ac:0a:b0:f1:d3:0d:
+ 4f:6a:4d:77:97:01:a0:f1:66:b7:b7:ce:ef:ce:ec:
+ ec:a5:75:ca:ac:e3:e1:63:f7:b8:a1:04:c8:bc:7b:
+ 3f:5d:2d:16:22:56:ed:48:49:fe:a7:2f:79:30:25:
+ 9b:ba:6b:2d:3f:9d:3b:c4:17:e7:1d:2e:fb:f2:cf:
+ a6:fc:e3:14:2c:96:98:21:8c:b4:91:e9:19:60:83:
+ f2:30:2b:06:73:50:d5:98:3b:06:e9:c7:8a:0c:60:
+ 8c:28:f8:52:9b:6e:e1:f6:4d:bb:06:24:9b:d7:2b:
+ 26:3f:fd:2a:2f:71:f5:d6:24:be:7f:31:9e:0f:6d:
+ e8:8f:4f:4d:a3:3f:ff:35:ea:df:49:5e:41:8f:86:
+ f9:f1:77:79:4b:1b:b4:a3:5e:2f:fb:46:02:d0:66:
+ 13:5e:5e:85:4f:ce:d8:70:88:7b:ce:01:b5:96:97:
+ d7:cd:7d:fd:82:f8:c2:24:c1:ca:01:39:4f:8d:a2:
+ c1:14:40:1f:9c:66:d5:0c:09:46:d6:f2:d0:d1:48:
+ 76:56:3a:43:cb:b6:0a:11:39:ba:8c:13:6c:06:b5:
+ 9e:cf:eb
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 51:33:1C:ED:36:40:AF:17:D3:25:CD:69:68:F2:AF:4E:23:3E:B3:41
+ X509v3 Key Usage: critical
+ Digital Signature, Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: sha384WithRSAEncryption
+ 60:a6:af:5b:5f:57:da:89:db:4b:50:a9:c4:23:35:21:ff:d0:
+ 61:30:84:91:b7:3f:10:cf:25:8e:c9:bf:46:34:d9:c1:21:26:
+ 1c:70:19:72:1e:a3:c9:87:fe:a9:43:64:96:3a:c8:53:04:0a:
+ b6:41:bb:c4:47:00:d9:9f:18:18:3b:b2:0e:f3:34:ea:24:f7:
+ dd:af:20:60:ae:92:28:5f:36:e7:5d:e4:de:c7:3c:db:50:39:
+ ad:bb:3d:28:4d:96:7c:76:c6:5b:f4:c1:db:14:a5:ab:19:62:
+ 07:18:40:5f:97:91:dc:9c:c7:ab:b5:51:0d:e6:69:53:55:cc:
+ 39:7d:da:c5:11:55:72:c5:3b:8b:89:f8:34:2d:a4:17:e5:17:
+ e6:99:7d:30:88:21:37:cd:30:17:3d:b8:f2:bc:a8:75:a0:43:
+ dc:3e:89:4b:90:ae:6d:03:e0:1c:a3:a0:96:09:bb:7d:a3:b7:
+ 2a:10:44:4b:46:07:34:63:ed:31:b9:04:ee:a3:9b:9a:ae:e6:
+ 31:78:f4:ea:24:61:3b:ab:58:64:ff:bb:87:27:62:25:81:df:
+ dc:a1:2f:f6:ed:a7:ff:7a:8f:51:2e:30:f8:a4:01:d2:85:39:
+ 5f:01:99:96:6f:5a:5b:70:19:46:fe:86:60:3e:ad:80:10:09:
+ dd:39:25:2f:58:7f:bb:d2:74:f0:f7:46:1f:46:39:4a:d8:53:
+ d0:f3:2e:3b:71:a5:d4:6f:fc:f3:67:e4:07:8f:dd:26:19:e1:
+ 8d:5b:fa:a3:93:11:9b:e9:c8:3a:c3:55:68:9a:92:e1:52:76:
+ 38:e8:e1:ba:bd:fb:4f:d5:ef:b3:e7:48:83:31:f0:82:21:e3:
+ b6:be:a7:ab:6f:ef:9f:df:4c:cf:01:b8:62:6a:23:3d:e7:09:
+ 4d:80:1b:7b:30:a4:c3:dd:07:7f:34:be:a4:26:b2:f6:41:e8:
+ 09:1d:e3:20:98:aa:37:4f:ff:f7:f1:e2:29:70:31:47:3f:74:
+ d0:14:16:fa:21:8a:02:d5:8a:09:94:77:2e:f2:59:28:8b:7c:
+ 50:92:0a:66:78:38:83:75:c4:b5:5a:a8:11:c6:e5:c1:9d:66:
+ 55:cf:53:c4:af:d7:75:85:a9:42:13:56:ec:21:77:81:93:5a:
+ 0c:ea:96:d9:49:ca:a1:08:f2:97:3b:6d:9b:04:18:24:44:8e:
+ 7c:01:f2:dc:25:d8:5e:86:9a:b1:39:db:f5:91:32:6a:d1:a6:
+ 70:8a:a2:f7:de:a4:45:85:26:a8:1e:8c:5d:29:5b:c8:4b:d8:
+ 9a:6a:03:5e:70:f2:85:4f:6c:4b:68:2f:ca:54:f6:8c:da:32:
+ fe:c3:6b:83:3f:38:c6:7e
+SHA1 Fingerprint=A7:88:49:DC:5D:7C:75:8C:8C:DE:39:98:56:B3:AA:D0:B2:A5:71:35
+-----BEGIN CERTIFICATE-----
+MIIFZjCCA06gAwIBAgIQCPm0eKj6ftpqMzeJ3nzPijANBgkqhkiG9w0BAQwFADBN
+MQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xJTAjBgNVBAMT
+HERpZ2lDZXJ0IFRMUyBSU0E0MDk2IFJvb3QgRzUwHhcNMjEwMTE1MDAwMDAwWhcN
+NDYwMTE0MjM1OTU5WjBNMQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQs
+IEluYy4xJTAjBgNVBAMTHERpZ2lDZXJ0IFRMUyBSU0E0MDk2IFJvb3QgRzUwggIi
+MA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCz0PTJeRGd/fxmgefM1eS87IE+
+ajWOLrfn3q/5B03PMJ3qCQuZvWxX2hhKuHisOjmopkisLnLlvevxGs3npAOpPxG0
+2C+JFvuUAT27L/gTBaF4HI4o4EXgg/RZG5Wzrn4DReW+wkL+7vI8toUTmDKdFqgp
+wgscONyfMXdcvyej/Cestyu9dJsXLfKB2l2w4SMXPohKEiPQ6s+d3gMXsUJKoBZM
+pG2T6T867jp8nVid9E6P/DsjyG244gXazOvswzH016cpVIDPRFtMbzCe88zdH5RD
+nU1/cHAN1DrRN/BsnZvAFJNY781BOHW8EwOVfH/jXOnVDdXifBBiqmvwPXbzP6Po
+sMH976pXTayGpxi0KcEsDr9kvimM2AItzVwv8n/vFfQMFawKsPHTDU9qTXeXAaDx
+Zre3zu/O7Oyldcqs4+Fj97ihBMi8ez9dLRYiVu1ISf6nL3kwJZu6ay0/nTvEF+cd
+Lvvyz6b84xQslpghjLSR6Rlgg/IwKwZzUNWYOwbpx4oMYIwo+FKbbuH2TbsGJJvX
+KyY//SovcfXWJL5/MZ4PbeiPT02jP/816t9JXkGPhvnxd3lLG7SjXi/7RgLQZhNe
+XoVPzthwiHvOAbWWl9fNff2C+MIkwcoBOU+NosEUQB+cZtUMCUbW8tDRSHZWOkPL
+tgoRObqME2wGtZ7P6wIDAQABo0IwQDAdBgNVHQ4EFgQUUTMc7TZArxfTJc1paPKv
+TiM+s0EwDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcN
+AQEMBQADggIBAGCmr1tfV9qJ20tQqcQjNSH/0GEwhJG3PxDPJY7Jv0Y02cEhJhxw
+GXIeo8mH/qlDZJY6yFMECrZBu8RHANmfGBg7sg7zNOok992vIGCukihfNudd5N7H
+PNtQOa27PShNlnx2xlv0wdsUpasZYgcYQF+Xkdycx6u1UQ3maVNVzDl92sURVXLF
+O4uJ+DQtpBflF+aZfTCIITfNMBc9uPK8qHWgQ9w+iUuQrm0D4ByjoJYJu32jtyoQ
+REtGBzRj7TG5BO6jm5qu5jF49OokYTurWGT/u4cnYiWB39yhL/btp/96j1EuMPik
+AdKFOV8BmZZvWltwGUb+hmA+rYAQCd05JS9Yf7vSdPD3Rh9GOUrYU9DzLjtxpdRv
+/PNn5AeP3SYZ4Y1b+qOTEZvpyDrDVWiakuFSdjjo4bq9+0/V77PnSIMx8IIh47a+
+p6tv75/fTM8BuGJqIz3nCU2AG3swpMPdB380vqQmsvZB6Akd4yCYqjdP//fx4ilw
+MUc/dNAUFvohigLVigmUdy7yWSiLfFCSCmZ4OIN1xLVaqBHG5cGdZlXPU8Sv13WF
+qUITVuwhd4GTWgzqltlJyqEI8pc7bZsEGCREjnwB8twl2F6GmrE52/WRMmrRpnCK
+ovfepEWFJqgejF0pW8hL2JpqA15w8oVPbEtoL8pU9ozaMv7Da4M/OMZ+
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem b/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
new file mode 100644
index 000000000000..589b4f911531
--- /dev/null
+++ b/secure/caroot/trusted/E-Tugra_Global_Root_CA_ECC_v3.pem
@@ -0,0 +1,73 @@
+##
+## E-Tugra Global Root CA ECC v3
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 26:46:19:77:31:e1:4f:6f:28:36:de:39:51:86:e6:d4:97:88:22:c1
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA ECC v3
+ Validity
+ Not Before: Mar 18 09:46:58 2020 GMT
+ Not After : Mar 12 09:46:58 2045 GMT
+ Subject: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA ECC v3
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:8e:98:29:bf:c7:10:1e:27:db:ab:03:cc:28:2c:
+ d8:5e:48:19:10:29:cc:cb:59:81:cc:8c:b8:92:17:
+ 89:83:2a:92:f6:c3:a4:1d:4c:62:d5:9f:d6:a0:46:
+ dc:1c:bc:76:c1:e3:47:d0:5b:13:da:e7:a5:b3:66:
+ 48:e7:21:9a:4a:4f:86:0a:7d:6c:ea:4d:32:80:0a:
+ b2:7a:09:9b:69:4b:98:81:e2:2e:ec:02:70:96:1f:
+ fd:f5:46:ce:ca:dc:82
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Authority Key Identifier:
+ keyid:FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
+
+ X509v3 Subject Key Identifier:
+ FF:82:31:72:3E:F9:C4:66:6C:AD:38:9E:D1:B0:51:88:A5:90:CC:F5
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:66:02:31:00:e6:05:58:69:61:e5:2d:ca:0d:cb:f1:19:08:
+ bd:d6:fd:51:92:1a:7e:63:54:04:90:91:9a:35:91:39:99:fa:
+ 07:a9:66:93:ba:c8:68:d4:8a:3f:fa:ed:6e:16:02:27:b7:02:
+ 31:00:dd:5a:17:2b:76:1d:65:42:96:a6:ac:5d:8a:79:56:d8:
+ 8a:1b:df:9a:de:5f:c7:50:8f:b1:5b:71:0c:26:df:6a:40:00:
+ ec:33:91:21:71:be:68:e4:23:a4:d9:ad:a1:37
+SHA1 Fingerprint=8A:2F:AF:57:53:B1:B0:E6:A1:04:EC:5B:6A:69:71:6D:F6:1C:E2:84
+-----BEGIN CERTIFICATE-----
+MIICpTCCAiqgAwIBAgIUJkYZdzHhT28oNt45UYbm1JeIIsEwCgYIKoZIzj0EAwMw
+gYAxCzAJBgNVBAYTAlRSMQ8wDQYDVQQHEwZBbmthcmExGTAXBgNVBAoTEEUtVHVn
+cmEgRUJHIEEuUy4xHTAbBgNVBAsTFEUtVHVncmEgVHJ1c3QgQ2VudGVyMSYwJAYD
+VQQDEx1FLVR1Z3JhIEdsb2JhbCBSb290IENBIEVDQyB2MzAeFw0yMDAzMTgwOTQ2
+NThaFw00NTAzMTIwOTQ2NThaMIGAMQswCQYDVQQGEwJUUjEPMA0GA1UEBxMGQW5r
+YXJhMRkwFwYDVQQKExBFLVR1Z3JhIEVCRyBBLlMuMR0wGwYDVQQLExRFLVR1Z3Jh
+IFRydXN0IENlbnRlcjEmMCQGA1UEAxMdRS1UdWdyYSBHbG9iYWwgUm9vdCBDQSBF
+Q0MgdjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAASOmCm/xxAeJ9urA8woLNheSBkQ
+KczLWYHMjLiSF4mDKpL2w6QdTGLVn9agRtwcvHbB40fQWxPa56WzZkjnIZpKT4YK
+fWzqTTKACrJ6CZtpS5iB4i7sAnCWH/31Rs7K3IKjYzBhMA8GA1UdEwEB/wQFMAMB
+Af8wHwYDVR0jBBgwFoAU/4Ixcj75xGZsrTie0bBRiKWQzPUwHQYDVR0OBBYEFP+C
+MXI++cRmbK04ntGwUYilkMz1MA4GA1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAwNp
+ADBmAjEA5gVYaWHlLcoNy/EZCL3W/VGSGn5jVASQkZo1kTmZ+gepZpO6yGjUij/6
+7W4WAie3AjEA3VoXK3YdZUKWpqxdinlW2Iob35reX8dQj7FbcQwm32pAAOwzkSFx
+vmjkI6TZraE3
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem b/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
new file mode 100644
index 000000000000..147ba810d1d6
--- /dev/null
+++ b/secure/caroot/trusted/E-Tugra_Global_Root_CA_RSA_v3.pem
@@ -0,0 +1,140 @@
+##
+## E-Tugra Global Root CA RSA v3
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 0d:4d:c5:cd:16:22:95:96:08:7e:b8:0b:7f:15:06:34:fb:79:10:34
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA RSA v3
+ Validity
+ Not Before: Mar 18 09:07:17 2020 GMT
+ Not After : Mar 12 09:07:17 2045 GMT
+ Subject: C = TR, L = Ankara, O = E-Tugra EBG A.S., OU = E-Tugra Trust Center, CN = E-Tugra Global Root CA RSA v3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:a2:66:f0:89:b7:72:7b:ee:09:c9:63:d2:d3:43:
+ dd:5e:c3:a6:84:38:4a:f1:8d:81:bb:14:bd:47:e8:
+ 40:17:f3:3d:c3:78:45:72:a6:2e:90:de:9a:3a:d4:
+ 20:71:ca:bc:9f:1d:4b:97:0a:c7:31:ba:3e:d7:fe:
+ 25:a9:2a:8e:36:f4:d1:2f:c7:b7:a9:5d:33:dc:30:
+ 70:f8:40:6c:4b:b2:a6:31:61:d1:34:3c:3d:31:7a:
+ c7:af:c4:a7:a7:84:e1:97:a4:e8:4b:f6:17:7c:ee:
+ 3c:07:ed:e2:8a:57:dc:b6:fb:f8:43:25:50:ea:27:
+ 81:a8:86:bc:8f:52:4a:96:3a:60:1a:96:bb:fd:73:
+ f4:85:fd:83:fd:7f:84:6d:34:6c:7f:6a:b7:4b:01:
+ 03:bf:ad:69:b7:d7:32:d9:f5:57:6a:e9:86:82:3e:
+ a5:66:31:b3:16:3d:c2:f3:26:60:32:d3:52:1e:b0:
+ 6c:a4:37:3e:f4:f5:af:eb:e1:df:80:06:cf:2a:41:
+ e7:66:09:e1:4b:97:e7:77:bd:21:6d:29:b6:67:c3:
+ 2d:7e:ed:d6:79:65:d1:cf:3a:b6:d1:b1:5e:56:61:
+ 50:7a:5a:ce:4e:50:31:80:03:98:47:e7:e4:18:7c:
+ 44:5a:c6:a4:b3:3b:c6:c6:c3:3a:f0:6c:c3:8b:c8:
+ a4:91:05:f3:f5:d9:b6:aa:06:a1:b7:ab:e4:b1:ea:
+ 21:14:5c:83:a4:fc:ff:b6:50:d3:8c:12:26:99:76:
+ 70:e9:c0:0f:a6:74:fc:bb:d0:1b:78:ce:72:92:e2:
+ 28:9c:bc:e6:e9:09:d8:3a:d3:89:e6:be:2e:77:df:
+ 01:0a:6f:96:f6:e5:8d:3c:4d:52:76:1a:56:e1:73:
+ 7e:17:ac:3d:ad:6c:a3:52:12:18:70:e6:80:4e:33:
+ f2:7e:26:32:ac:05:8d:38:a4:e6:76:3c:9f:10:69:
+ 0e:6d:9d:d2:c1:79:20:6b:5b:cf:33:8d:d1:94:76:
+ 35:e7:5d:55:c7:b7:ac:28:ab:46:cc:e7:3b:21:b5:
+ 0a:0a:e4:4a:59:dc:81:35:4b:44:95:12:0a:67:a5:
+ a1:ff:5b:00:07:d2:c0:cc:f9:3f:fc:9f:33:f2:00:
+ f8:8c:6c:87:9d:06:2d:f1:ef:e3:e6:06:fa:c5:66:
+ 13:5b:fc:50:07:9e:71:86:b2:da:6f:74:30:cf:93:
+ 53:e8:dc:22:d6:de:20:1f:61:8d:a3:2e:a3:78:32:
+ 90:6c:dc:ac:32:b5:05:e4:f5:3c:33:0d:d6:e0:87:
+ 77:17:4c:9d:b0:d8:09:a8:0d:57:f7:44:85:f0:c8:
+ 04:be:5c:5d:5a:e3:17:8e:54:63:69:7f:49:74:64:
+ 05:8c:a3
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Authority Key Identifier:
+ keyid:B2:B4:AE:E6:2D:F7:26:D5:AA:75:2D:76:4B:C0:1B:53:21:D0:48:EF
+
+ X509v3 Subject Key Identifier:
+ B2:B4:AE:E6:2D:F7:26:D5:AA:75:2D:76:4B:C0:1B:53:21:D0:48:EF
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ 89:a8:72:7f:8c:eb:ce:2e:18:c4:10:80:2d:10:0c:ff:fb:14:
+ cd:04:e0:14:3c:4e:9a:fb:9f:29:bf:22:9e:57:b9:82:73:12:
+ 63:26:b5:cc:90:e9:d2:2a:29:ee:9c:2d:cc:2c:99:be:45:27:
+ e4:b1:71:ed:e4:38:95:31:41:f2:7d:7a:63:78:df:ca:36:16:
+ 2f:82:88:9f:bc:11:47:4f:76:4d:c8:2d:8e:eb:df:2d:7c:4e:
+ 3b:da:ae:f6:e3:da:5d:14:a6:ae:e8:85:44:9d:06:6e:8e:fb:
+ ef:7a:4a:6a:2d:2b:28:18:fe:bf:90:2c:75:16:9f:0f:ea:96:
+ 7d:05:ee:9b:13:a5:44:6c:f8:03:d0:dd:23:e1:fd:03:12:12:
+ 08:f4:18:34:b3:e0:37:0b:77:11:01:48:bf:61:b4:b5:f8:19:
+ d9:cb:4d:ea:a3:8c:ef:fd:f0:06:b5:6d:92:f4:4a:61:50:84:
+ ed:ec:49:d3:e4:be:68:e6:2e:e3:31:0b:54:0b:1a:92:d6:82:
+ d8:b6:a2:65:3c:66:04:f9:55:da:6c:fb:db:b5:14:66:4d:94:
+ 83:3b:cd:1e:a6:2b:b2:fe:77:40:86:ab:e7:df:0a:c9:fd:f6:
+ dd:87:56:18:d8:b0:2c:55:60:96:fa:08:7e:52:90:f5:4b:a6:
+ 2e:87:7c:cb:20:db:06:3e:a0:5d:03:77:7d:a2:3c:13:1b:29:
+ a2:13:55:a0:3d:14:22:af:6f:b8:d0:9a:1b:72:dd:05:01:8d:
+ 86:60:bf:a4:67:ee:b5:a5:0d:d1:7f:e6:1a:2b:62:66:c3:07:
+ ba:e7:a0:48:1c:38:c3:e9:45:fb:a7:7f:fc:ed:02:68:1a:ca:
+ 77:12:77:a6:00:55:28:14:ec:d6:c7:12:a2:1b:65:42:e9:91:
+ e8:cb:3e:87:89:54:5d:d9:af:9d:97:9c:69:e7:0a:ff:0f:5a:
+ 78:8b:63:2a:4c:7d:47:94:3f:de:4b:e9:53:d0:30:f1:c5:f6:
+ 9e:49:df:3b:a0:91:a3:a3:fe:cd:58:cc:ea:df:af:6f:28:3b:
+ a0:69:9b:8f:ec:ac:ae:2b:54:9d:9b:04:b1:47:20:af:96:12:
+ 3e:63:94:1d:04:e7:2e:bb:86:c7:0c:9a:88:bf:76:47:ef:f7:
+ b0:0b:97:66:d2:44:cf:60:52:07:e1:d5:2c:4a:3a:27:61:77:
+ ca:d7:8f:e7:87:0e:30:ff:0c:bb:04:e2:61:c3:a2:c8:97:61:
+ 8e:b4:30:6a:3c:6d:c2:07:5f:4a:73:2f:3f:f9:16:8a:01:66:
+ ef:ba:91:ca:52:57:7b:ae:d4:e6:0f:dd:0b:7a:7f:8b:9e:26:
+ 20:cf:3b:ef:81:71:83:59
+SHA1 Fingerprint=E9:A8:5D:22:14:52:1C:5B:AA:0A:B4:BE:24:6A:23:8A:C9:BA:E2:A9
+-----BEGIN CERTIFICATE-----
+MIIF8zCCA9ugAwIBAgIUDU3FzRYilZYIfrgLfxUGNPt5EDQwDQYJKoZIhvcNAQEL
+BQAwgYAxCzAJBgNVBAYTAlRSMQ8wDQYDVQQHEwZBbmthcmExGTAXBgNVBAoTEEUt
+VHVncmEgRUJHIEEuUy4xHTAbBgNVBAsTFEUtVHVncmEgVHJ1c3QgQ2VudGVyMSYw
+JAYDVQQDEx1FLVR1Z3JhIEdsb2JhbCBSb290IENBIFJTQSB2MzAeFw0yMDAzMTgw
+OTA3MTdaFw00NTAzMTIwOTA3MTdaMIGAMQswCQYDVQQGEwJUUjEPMA0GA1UEBxMG
+QW5rYXJhMRkwFwYDVQQKExBFLVR1Z3JhIEVCRyBBLlMuMR0wGwYDVQQLExRFLVR1
+Z3JhIFRydXN0IENlbnRlcjEmMCQGA1UEAxMdRS1UdWdyYSBHbG9iYWwgUm9vdCBD
+QSBSU0EgdjMwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCiZvCJt3J7
+7gnJY9LTQ91ew6aEOErxjYG7FL1H6EAX8z3DeEVypi6Q3po61CBxyryfHUuXCscx
+uj7X/iWpKo429NEvx7epXTPcMHD4QGxLsqYxYdE0PD0xesevxKenhOGXpOhL9hd8
+7jwH7eKKV9y2+/hDJVDqJ4GohryPUkqWOmAalrv9c/SF/YP9f4RtNGx/ardLAQO/
+rWm31zLZ9Vdq6YaCPqVmMbMWPcLzJmAy01IesGykNz709a/r4d+ABs8qQedmCeFL
+l+d3vSFtKbZnwy1+7dZ5ZdHPOrbRsV5WYVB6Ws5OUDGAA5hH5+QYfERaxqSzO8bG
+wzrwbMOLyKSRBfP12baqBqG3q+Sx6iEUXIOk/P+2UNOMEiaZdnDpwA+mdPy70Bt4
+znKS4iicvObpCdg604nmvi533wEKb5b25Y08TVJ2Glbhc34XrD2tbKNSEhhw5oBO
+M/J+JjKsBY04pOZ2PJ8QaQ5tndLBeSBrW88zjdGUdjXnXVXHt6woq0bM5zshtQoK
+5EpZ3IE1S0SVEgpnpaH/WwAH0sDM+T/8nzPyAPiMbIedBi3x7+PmBvrFZhNb/FAH
+nnGGstpvdDDPk1Po3CLW3iAfYY2jLqN4MpBs3KwytQXk9TwzDdbgh3cXTJ2w2Amo
+DVf3RIXwyAS+XF1a4xeOVGNpf0l0ZAWMowIDAQABo2MwYTAPBgNVHRMBAf8EBTAD
+AQH/MB8GA1UdIwQYMBaAFLK0ruYt9ybVqnUtdkvAG1Mh0EjvMB0GA1UdDgQWBBSy
+tK7mLfcm1ap1LXZLwBtTIdBI7zAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQEL
+BQADggIBAImocn+M684uGMQQgC0QDP/7FM0E4BQ8Tpr7nym/Ip5XuYJzEmMmtcyQ
+6dIqKe6cLcwsmb5FJ+Sxce3kOJUxQfJ9emN438o2Fi+CiJ+8EUdPdk3ILY7r3y18
+Tjvarvbj2l0Upq7ohUSdBm6O++96SmotKygY/r+QLHUWnw/qln0F7psTpURs+APQ
+3SPh/QMSEgj0GDSz4DcLdxEBSL9htLX4GdnLTeqjjO/98Aa1bZL0SmFQhO3sSdPk
+vmjmLuMxC1QLGpLWgti2omU8ZgT5Vdps+9u1FGZNlIM7zR6mK7L+d0CGq+ffCsn9
+9t2HVhjYsCxVYJb6CH5SkPVLpi6HfMsg2wY+oF0Dd32iPBMbKaITVaA9FCKvb7jQ
+mhty3QUBjYZgv6Rn7rWlDdF/5horYmbDB7rnoEgcOMPpRfunf/ztAmgayncSd6YA
+VSgU7NbHEqIbZULpkejLPoeJVF3Zr52XnGnnCv8PWniLYypMfUeUP95L6VPQMPHF
+9p5J3zugkaOj/s1YzOrfr28oO6Bpm4/srK4rVJ2bBLFHIK+WEj5jlB0E5y67hscM
+moi/dkfv97ALl2bSRM9gUgfh1SxKOidhd8rXj+eHDjD/DLsE4mHDosiXYY60MGo8
+bcIHX0pzLz/5FooBZu+6kcpSV3uu1OYP3Qt6f4ueJiDPO++BcYNZ
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem b/secure/caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem
new file mode 100644
index 000000000000..51a7b83efc8b
--- /dev/null
+++ b/secure/caroot/trusted/HARICA_TLS_ECC_Root_CA_2021.pem
@@ -0,0 +1,68 @@
+##
+## HARICA TLS ECC Root CA 2021
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 67:74:9d:8d:77:d8:3b:6a:db:22:f4:ff:59:e2:bf:ce
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = GR, O = Hellenic Academic and Research Institutions CA, CN = HARICA TLS ECC Root CA 2021
+ Validity
+ Not Before: Feb 19 11:01:10 2021 GMT
+ Not After : Feb 13 11:01:09 2045 GMT
+ Subject: C = GR, O = Hellenic Academic and Research Institutions CA, CN = HARICA TLS ECC Root CA 2021
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:38:08:fe:b1:a0:96:d2:7a:ac:af:49:3a:d0:c0:
+ e0:c3:3b:28:aa:f1:72:6d:65:00:47:88:84:fc:9a:
+ 26:6b:aa:4b:ba:6c:04:0a:88:5e:17:f2:55:87:fc:
+ 30:b0:34:e2:34:58:57:1a:84:53:e9:30:d9:a9:f2:
+ 96:74:c3:51:1f:58:49:31:cc:98:4e:60:11:87:75:
+ d3:72:94:90:4f:9b:10:25:2a:a8:78:2d:be:90:41:
+ 58:90:15:72:a7:a1:b7
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ C9:1B:53:81:12:FE:04:D5:16:D1:AA:BC:9A:6F:B7:A0:95:19:6E:CA
+ X509v3 Key Usage: critical
+ Digital Signature, Certificate Sign, CRL Sign
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:64:02:30:11:de:ae:f8:dc:4e:88:b0:a9:f0:22:ad:c2:51:
+ 40:ef:60:71:2d:ee:8f:02:c4:5d:03:70:49:a4:92:ea:c5:14:
+ 88:70:a6:d3:0d:b0:aa:ca:2c:40:9c:fb:e9:82:6e:9a:02:30:
+ 2b:47:9a:07:c6:d1:c2:81:7c:ca:0b:96:18:41:1b:a3:f4:30:
+ 09:9e:b5:23:28:0d:9f:14:b6:3c:53:a2:4c:06:69:7d:fa:6c:
+ 91:c6:2a:49:45:e6:ec:b7:13:e1:3a:6c
+SHA1 Fingerprint=BC:B0:C1:9D:E9:98:92:70:19:38:57:E9:8D:A7:B4:5D:6E:EE:01:48
+-----BEGIN CERTIFICATE-----
+MIICVDCCAdugAwIBAgIQZ3SdjXfYO2rbIvT/WeK/zjAKBggqhkjOPQQDAzBsMQsw
+CQYDVQQGEwJHUjE3MDUGA1UECgwuSGVsbGVuaWMgQWNhZGVtaWMgYW5kIFJlc2Vh
+cmNoIEluc3RpdHV0aW9ucyBDQTEkMCIGA1UEAwwbSEFSSUNBIFRMUyBFQ0MgUm9v
+dCBDQSAyMDIxMB4XDTIxMDIxOTExMDExMFoXDTQ1MDIxMzExMDEwOVowbDELMAkG
+A1UEBhMCR1IxNzA1BgNVBAoMLkhlbGxlbmljIEFjYWRlbWljIGFuZCBSZXNlYXJj
+aCBJbnN0aXR1dGlvbnMgQ0ExJDAiBgNVBAMMG0hBUklDQSBUTFMgRUNDIFJvb3Qg
+Q0EgMjAyMTB2MBAGByqGSM49AgEGBSuBBAAiA2IABDgI/rGgltJ6rK9JOtDA4MM7
+KKrxcm1lAEeIhPyaJmuqS7psBAqIXhfyVYf8MLA04jRYVxqEU+kw2anylnTDUR9Y
+STHMmE5gEYd103KUkE+bECUqqHgtvpBBWJAVcqeht6NCMEAwDwYDVR0TAQH/BAUw
+AwEB/zAdBgNVHQ4EFgQUyRtTgRL+BNUW0aq8mm+3oJUZbsowDgYDVR0PAQH/BAQD
+AgGGMAoGCCqGSM49BAMDA2cAMGQCMBHervjcToiwqfAircJRQO9gcS3ujwLEXQNw
+SaSS6sUUiHCm0w2wqsosQJz76YJumgIwK0eaB8bRwoF8yguWGEEbo/QwCZ61IygN
+nxS2PFOiTAZpffpskcYqSUXm7LcT4Tps
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem b/secure/caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem
new file mode 100644
index 000000000000..bc3fb9b4f80f
--- /dev/null
+++ b/secure/caroot/trusted/HARICA_TLS_RSA_Root_CA_2021.pem
@@ -0,0 +1,136 @@
+##
+## HARICA TLS RSA Root CA 2021
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 39:ca:93:1c:ef:43:f3:c6:8e:93:c7:f4:64:89:38:7e
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = GR, O = Hellenic Academic and Research Institutions CA, CN = HARICA TLS RSA Root CA 2021
+ Validity
+ Not Before: Feb 19 10:55:38 2021 GMT
+ Not After : Feb 13 10:55:37 2045 GMT
+ Subject: C = GR, O = Hellenic Academic and Research Institutions CA, CN = HARICA TLS RSA Root CA 2021
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:8b:c2:e7:af:65:9b:05:67:96:c9:0d:24:b9:d0:
+ 0e:64:fc:ce:e2:24:18:2c:84:7f:77:51:cb:04:11:
+ 36:b8:5e:ed:69:71:a7:9e:e4:25:09:97:67:c1:47:
+ c2:cf:91:16:36:62:3d:38:04:e1:51:82:ff:ac:d2:
+ b4:69:dd:2e:ec:11:a3:45:ee:6b:6b:3b:4c:bf:8c:
+ 8d:a4:1e:9d:11:b9:e9:38:f9:7a:0e:0c:98:e2:23:
+ 1d:d1:4e:63:d4:e7:b8:41:44:fb:6b:af:6b:da:1f:
+ d3:c5:91:88:5b:a4:89:92:d1:81:e6:8c:39:58:a0:
+ d6:69:43:a9:ad:98:52:58:6e:db:0a:fb:6b:cf:68:
+ fa:e3:a4:5e:3a:45:73:98:07:ea:5f:02:72:de:0c:
+ a5:b3:9f:ae:a9:1d:b7:1d:b3:fc:8a:59:e7:6e:72:
+ 65:ad:f5:30:94:23:07:f3:82:16:4b:35:98:9c:53:
+ bb:2f:ca:e4:5a:d9:c7:8d:1d:fc:98:99:fb:2c:a4:
+ 82:6b:f0:2a:1f:8e:0b:5f:71:5c:5c:ae:42:7b:29:
+ 89:81:cb:03:a3:99:ca:88:9e:0b:40:09:41:33:db:
+ e6:58:7a:fd:ae:99:70:c0:5a:0f:d6:13:86:71:2f:
+ 76:69:fc:90:dd:db:2d:6e:d1:f2:9b:f5:1a:6b:9e:
+ 6f:15:8c:7a:f0:4b:28:a0:22:38:80:24:6c:36:a4:
+ 3b:f2:30:91:f3:78:13:cf:c1:3f:35:ab:f1:1d:11:
+ 23:b5:43:22:9e:01:92:b7:18:02:e5:11:d1:82:db:
+ 15:00:cc:61:37:c1:2a:7c:9a:e1:d0:ba:b3:50:46:
+ ee:82:ac:9d:31:f8:fb:23:e2:03:00:48:70:a3:09:
+ 26:79:15:53:60:f3:38:5c:ad:38:ea:81:00:63:14:
+ b9:33:5e:dd:0b:db:a0:45:07:1a:33:09:f8:4d:b4:
+ a7:02:a6:69:f4:c2:59:05:88:65:85:56:ae:4b:cb:
+ e0:de:3c:7d:2d:1a:c8:e9:fb:1f:a3:61:4a:d6:2a:
+ 13:ad:77:4c:1a:18:9b:91:0f:58:d8:06:54:c5:97:
+ f8:aa:3f:20:8a:a6:85:a6:77:f6:a6:fc:1c:e2:ee:
+ 6e:94:33:2a:83:50:84:0a:e5:4f:86:f8:50:45:78:
+ 00:81:eb:5b:68:e3:26:8d:cc:7b:5c:51:f4:14:2c:
+ 40:be:1a:60:1d:7a:72:61:1d:1f:63:2d:88:aa:ce:
+ a2:45:90:08:fc:6b:be:b3:50:2a:5a:fd:a8:48:18:
+ 46:d6:90:40:92:90:0a:84:5e:68:31:f8:eb:ed:0d:
+ d3:1d:c6:7d:99:18:55:56:27:65:2e:8d:45:c5:24:
+ ec:ce:e3
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 0A:48:23:A6:60:A4:92:0A:33:EA:93:5B:C5:57:EA:25:4D:BD:12:EE
+ X509v3 Key Usage: critical
+ Digital Signature, Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ 3e:90:48:aa:6e:62:15:25:66:7b:0c:d5:8c:8b:89:9d:d7:ed:
+ 4e:07:ef:9c:d0:14:5f:5e:50:bd:68:96:90:a4:14:11:aa:68:
+ 6d:09:35:39:40:09:da:f4:09:2c:34:a5:7b:59:84:49:29:97:
+ 74:c8:07:1e:47:6d:f2:ce:1c:50:26:e3:9e:3d:40:53:3f:f7:
+ 7f:96:76:10:c5:46:a5:d0:20:4b:50:f4:35:3b:18:f4:55:6a:
+ 41:1b:47:06:68:3c:bb:09:08:62:d9:5f:55:42:aa:ac:53:85:
+ ac:95:56:36:56:ab:e4:05:8c:c5:a8:da:1f:a3:69:bd:53:0f:
+ c4:ff:dc:ca:e3:7e:f2:4c:88:86:47:46:1a:f3:00:f5:80:91:
+ a2:dc:43:42:94:9b:20:f0:d1:cd:b2:eb:2c:53:c2:53:78:4a:
+ 4f:04:94:41:9a:8f:27:32:c1:e5:49:19:bf:f1:f2:c2:8b:a8:
+ 0a:39:31:28:b4:7d:62:36:2c:4d:ec:1f:33:b6:7e:77:6d:7e:
+ 50:f0:9f:0e:d7:11:8f:cf:18:c5:e3:27:fe:26:ef:05:9d:cf:
+ cf:37:c5:d0:7b:da:3b:b0:16:84:0c:3a:93:d6:be:17:db:0f:
+ 3e:0e:19:78:09:c7:a9:02:72:22:4b:f7:37:76:ba:75:c4:85:
+ 03:5a:63:d5:b1:75:05:c2:b9:bd:94:ad:8c:15:99:a7:93:7d:
+ f6:c5:f3:aa:74:cf:04:85:94:98:00:f4:e2:f9:ca:24:65:bf:
+ e0:62:af:c8:c5:fa:b2:c9:9e:56:48:da:79:fd:96:76:15:be:
+ a3:8e:56:c4:b3:34:fc:be:47:f4:c1:b4:a8:fc:d5:30:88:68:
+ ee:cb:ae:c9:63:c4:76:be:ac:38:18:e1:5e:5c:cf:ae:3a:22:
+ 51:eb:d1:8b:b3:f3:2b:33:07:54:87:fa:b4:b2:13:7b:ba:53:
+ 04:62:01:9d:f1:c0:4f:ee:e1:3a:d4:8b:20:10:fa:02:57:e6:
+ ef:c1:0b:b7:90:46:9c:19:29:8c:dc:6f:a0:4a:69:69:94:b7:
+ 24:65:a0:ff:ac:3f:ce:01:fb:21:2e:fd:68:f8:9b:f2:a5:cf:
+ 31:38:5c:15:aa:e6:97:00:c1:df:5a:a5:a7:39:aa:e9:84:7f:
+ 3c:51:a8:3a:d9:94:5b:8c:bf:4f:08:71:e5:db:a8:5c:d4:d2:
+ a6:fe:00:a3:c6:16:c7:0f:e8:80:ce:1c:28:64:74:19:08:d3:
+ 42:e3:ce:00:5d:7f:b1:dc:13:b0:e1:05:cb:d1:20:aa:86:74:
+ 9e:39:e7:91:fd:ff:5b:d6:f7:ad:a6:2f:03:0b:6d:e3:57:54:
+ eb:76:53:18:8d:11:98:ba
+SHA1 Fingerprint=02:2D:05:82:FA:88:CE:14:0C:06:79:DE:7F:14:10:E9:45:D7:A5:6D
+-----BEGIN CERTIFICATE-----
+MIIFpDCCA4ygAwIBAgIQOcqTHO9D88aOk8f0ZIk4fjANBgkqhkiG9w0BAQsFADBs
+MQswCQYDVQQGEwJHUjE3MDUGA1UECgwuSGVsbGVuaWMgQWNhZGVtaWMgYW5kIFJl
+c2VhcmNoIEluc3RpdHV0aW9ucyBDQTEkMCIGA1UEAwwbSEFSSUNBIFRMUyBSU0Eg
+Um9vdCBDQSAyMDIxMB4XDTIxMDIxOTEwNTUzOFoXDTQ1MDIxMzEwNTUzN1owbDEL
+MAkGA1UEBhMCR1IxNzA1BgNVBAoMLkhlbGxlbmljIEFjYWRlbWljIGFuZCBSZXNl
+YXJjaCBJbnN0aXR1dGlvbnMgQ0ExJDAiBgNVBAMMG0hBUklDQSBUTFMgUlNBIFJv
+b3QgQ0EgMjAyMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAIvC569l
+mwVnlskNJLnQDmT8zuIkGCyEf3dRywQRNrhe7Wlxp57kJQmXZ8FHws+RFjZiPTgE
+4VGC/6zStGndLuwRo0Xua2s7TL+MjaQenRG56Tj5eg4MmOIjHdFOY9TnuEFE+2uv
+a9of08WRiFukiZLRgeaMOVig1mlDqa2YUlhu2wr7a89o+uOkXjpFc5gH6l8Cct4M
+pbOfrqkdtx2z/IpZ525yZa31MJQjB/OCFks1mJxTuy/K5FrZx40d/JiZ+yykgmvw
+Kh+OC19xXFyuQnspiYHLA6OZyoieC0AJQTPb5lh6/a6ZcMBaD9YThnEvdmn8kN3b
+LW7R8pv1GmuebxWMevBLKKAiOIAkbDakO/IwkfN4E8/BPzWr8R0RI7VDIp4BkrcY
+AuUR0YLbFQDMYTfBKnya4dC6s1BG7oKsnTH4+yPiAwBIcKMJJnkVU2DzOFytOOqB
+AGMUuTNe3QvboEUHGjMJ+E20pwKmafTCWQWIZYVWrkvL4N48fS0ayOn7H6NhStYq
+E613TBoYm5EPWNgGVMWX+Ko/IIqmhaZ39qb8HOLubpQzKoNQhArlT4b4UEV4AIHr
+W2jjJo3Me1xR9BQsQL4aYB16cmEdH2MtiKrOokWQCPxrvrNQKlr9qEgYRtaQQJKQ
+CoReaDH46+0N0x3GfZkYVVYnZS6NRcUk7M7jAgMBAAGjQjBAMA8GA1UdEwEB/wQF
+MAMBAf8wHQYDVR0OBBYEFApII6ZgpJIKM+qTW8VX6iVNvRLuMA4GA1UdDwEB/wQE
+AwIBhjANBgkqhkiG9w0BAQsFAAOCAgEAPpBIqm5iFSVmewzVjIuJndftTgfvnNAU
+X15QvWiWkKQUEapobQk1OUAJ2vQJLDSle1mESSmXdMgHHkdt8s4cUCbjnj1AUz/3
+f5Z2EMVGpdAgS1D0NTsY9FVqQRtHBmg8uwkIYtlfVUKqrFOFrJVWNlar5AWMxaja
+H6NpvVMPxP/cyuN+8kyIhkdGGvMA9YCRotxDQpSbIPDRzbLrLFPCU3hKTwSUQZqP
+JzLB5UkZv/HywouoCjkxKLR9YjYsTewfM7Z+d21+UPCfDtcRj88YxeMn/ibvBZ3P
+zzfF0HvaO7AWhAw6k9a+F9sPPg4ZeAnHqQJyIkv3N3a6dcSFA1pj1bF1BcK5vZSt
+jBWZp5N99sXzqnTPBIWUmAD04vnKJGW/4GKvyMX6ssmeVkjaef2WdhW+o45WxLM0
+/L5H9MG0qPzVMIho7suuyWPEdr6sOBjhXlzPrjoiUevRi7PzKzMHVIf6tLITe7pT
+BGIBnfHAT+7hOtSLIBD6Alfm78ELt5BGnBkpjNxvoEppaZS3JGWg/6w/zgH7IS79
+aPib8qXPMThcFarmlwDB31qlpzmq6YR/PFGoOtmUW4y/Twhx5duoXNTSpv4Ao8YW
+xw/ogM4cKGR0GQjTQuPOAF1/sdwTsOEFy9EgqoZ0njnnkf3/W9b3raYvAwtt41dU
+63ZTGI0RmLo=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem b/secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem
new file mode 100644
index 000000000000..2c0e84b01e40
--- /dev/null
+++ b/secure/caroot/trusted/HiPKI_Root_CA_-_G1.pem
@@ -0,0 +1,134 @@
+##
+## HiPKI Root CA - G1
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 2d:dd:ac:ce:62:97:94:a1:43:e8:b0:cd:76:6a:5e:60
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = TW, O = "Chunghwa Telecom Co., Ltd.", CN = HiPKI Root CA - G1
+ Validity
+ Not Before: Feb 22 09:46:04 2019 GMT
+ Not After : Dec 31 15:59:59 2037 GMT
+ Subject: C = TW, O = "Chunghwa Telecom Co., Ltd.", CN = HiPKI Root CA - G1
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:f4:1e:7f:52:73:32:0c:73:e4:bd:13:74:a3:d4:
+ 30:a8:d0:ae:4b:d8:b6:df:75:47:66:f4:7c:e7:39:
+ 04:1e:6a:70:20:d2:5a:47:72:67:55:f4:a5:e8:9d:
+ d5:1e:21:a1:f0:67:ba:cc:21:68:be:44:53:bf:8d:
+ f9:e2:dc:2f:55:c8:37:3f:1f:a4:c0:9c:b3:e4:77:
+ 5c:a0:46:fe:77:fa:1a:a0:38:ea:ed:9a:72:de:2b:
+ bd:94:57:3a:ba:ec:79:e7:5f:7d:42:64:39:7a:26:
+ 36:f7:24:f0:d5:2f:ba:95:98:11:66:ad:97:35:d6:
+ 75:01:80:e0:af:f4:84:61:8c:0d:1e:5f:7c:87:96:
+ 5e:41:af:eb:87:ea:f8:5d:f1:2e:88:05:3e:4c:22:
+ bb:da:1f:2a:dd:52:46:64:39:f3:42:ce:d9:9e:0c:
+ b3:b0:77:97:64:9c:c0:f4:a3:2e:1f:95:07:b0:17:
+ df:30:db:00:18:96:4c:a1:81:4b:dd:04:6d:53:a3:
+ 3d:fc:07:ac:d4:c5:37:82:eb:e4:95:08:19:28:82:
+ d2:42:3a:a3:d8:53:ec:79:89:60:48:60:c8:72:92:
+ 50:dc:03:8f:83:3f:b2:42:57:5a:db:6a:e9:11:97:
+ dd:85:28:bc:30:4c:ab:e3:c2:b1:45:44:47:1f:e0:
+ 8a:16:07:96:d2:21:0f:53:c0:ed:a9:7e:d4:4e:ec:
+ 9b:09:ec:af:42:ac:30:d6:bf:d1:10:45:e0:a6:16:
+ b2:a5:c5:d3:4f:73:94:33:71:02:a1:6a:a3:d6:33:
+ 97:4f:21:63:1e:5b:8f:d9:c1:5e:45:71:77:0f:81:
+ 5d:5f:21:9a:ad:83:cc:fa:5e:d6:8d:23:5f:1b:3d:
+ 41:af:20:75:66:5a:4a:f6:9f:fb:ab:18:f7:71:c0:
+ b6:1d:31:ec:3b:20:eb:cb:e2:b8:f5:ae:92:b2:f7:
+ e1:84:4b:f2:a2:f2:93:9a:22:9e:d3:14:6f:36:54:
+ bd:1f:5e:59:15:b9:73:a8:c1:7c:6f:7b:62:e9:16:
+ 6c:47:5a:65:f3:0e:11:9b:46:d9:fd:6d:dc:d6:9c:
+ c0:b4:7d:a5:b0:dd:3f:56:6f:a1:f9:f6:e4:12:48:
+ fd:06:7f:12:57:b6:a9:23:4f:5b:03:c3:e0:71:2a:
+ 23:b7:f7:b0:b1:3b:bc:98:bd:d6:98:a8:0c:6b:f6:
+ 8e:12:67:a6:f2:b2:58:e4:02:09:13:3c:a9:bb:10:
+ b4:d2:30:45:f1:ec:f7:00:11:df:65:f8:dc:2b:43:
+ 55:bf:16:97:c4:0f:d5:2c:61:84:aa:72:86:fe:e6:
+ 3a:7e:c2:3f:7d:ee:fc:2f:14:3e:e6:85:dd:50:6f:
+ b7:49:ed
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ F2:77:17:FA:5E:A8:FE:F6:3D:71:D5:68:BA:C9:46:0C:38:D8:AF:B0
+ X509v3 Key Usage: critical
+ Digital Signature, Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ 50:51:f0:75:dc:70:04:e3:ff:aa:75:d4:71:a2:cb:9e:8f:a8:
+ a9:d3:af:75:c7:54:cf:3a:1c:04:99:22:ac:c4:11:e2:ef:33:
+ 4a:a6:23:1d:0e:0d:47:d8:37:c7:6f:af:34:7f:4f:81:6b:35:
+ 4f:e9:72:a5:31:e2:78:e7:f7:4e:94:18:5b:40:7d:cf:6b:21:
+ 54:86:e6:95:7a:fb:c6:ca:ea:9c:48:4e:57:09:5d:2f:ac:f4:
+ a5:b4:97:33:58:d5:ac:79:a9:cc:5f:f9:85:fa:52:c5:8d:f8:
+ 91:14:eb:3a:0d:17:d0:52:c2:7b:e3:c2:73:8e:46:78:06:38:
+ 2c:e8:5c:da:66:c4:f4:a4:f0:56:19:33:29:5a:65:92:05:47:
+ 46:4a:ab:84:c3:1e:27:a1:1f:11:92:99:27:75:93:0f:bc:36:
+ 3b:97:57:8f:26:5b:0c:bb:9c:0f:d4:6e:30:07:d4:dc:5f:36:
+ 68:66:39:83:96:27:26:8a:c8:c4:39:fe:9a:21:6f:d5:72:86:
+ e9:7f:62:e5:97:4e:d0:24:d0:40:b0:d0:75:08:8e:bd:68:ee:
+ 08:d7:6e:7c:10:70:46:1b:7c:e0:88:b2:9e:72:86:99:01:e3:
+ bf:9f:49:19:b4:25:be:56:65:ae:17:63:e5:1e:df:e8:ff:47:
+ a5:bf:e1:26:05:84:e4:b0:c0:af:e7:08:99:a8:0c:5e:26:80:
+ 45:d4:f8:68:2f:96:8f:ae:e2:4a:1c:9c:16:0c:13:6f:38:87:
+ f6:bb:c8:34:5f:92:03:51:79:70:a6:df:cb:f5:99:4d:79:cd:
+ 4e:bc:57:9f:43:4e:6b:2e:2b:18:f8:6a:73:8c:ba:c5:35:ef:
+ 39:6a:41:1e:cf:71:a8:a2:b2:86:07:5b:3a:c9:e1:ef:3f:65:
+ 04:80:47:32:44:70:95:4e:31:67:6a:74:5b:10:45:75:ea:b0:
+ 9f:d0:e6:35:fe:4e:9f:8b:cc:2b:92:45:5b:6e:25:60:85:46:
+ cd:d1:aa:b0:76:66:93:77:96:be:83:be:38:b6:24:4e:26:0b:
+ cc:ed:7a:56:1a:e0:e9:5a:c6:64:ad:4c:7a:00:48:44:2f:b9:
+ 40:bb:13:3e:be:15:78:9d:85:81:4a:2a:57:de:d5:19:43:da:
+ db:ca:5b:47:86:83:0b:3f:b6:0d:76:78:73:79:22:5e:b1:80:
+ 1f:cf:be:d1:3f:56:10:98:2b:95:87:a1:1f:9d:64:14:60:39:
+ 2c:b3:00:55:2e:e4:f5:b3:0e:57:c4:91:41:00:9c:3f:e8:a5:
+ df:ea:f6:ff:c8:f0:ad:6d:52:a8:17:ab:9b:61:fc:12:51:35:
+ e4:25:fd:af:aa:6a:86:39
+SHA1 Fingerprint=6A:92:E4:A8:EE:1B:EC:96:45:37:E3:29:57:49:CD:96:E3:E5:D2:60
+-----BEGIN CERTIFICATE-----
+MIIFajCCA1KgAwIBAgIQLd2szmKXlKFD6LDNdmpeYDANBgkqhkiG9w0BAQsFADBP
+MQswCQYDVQQGEwJUVzEjMCEGA1UECgwaQ2h1bmdod2EgVGVsZWNvbSBDby4sIEx0
+ZC4xGzAZBgNVBAMMEkhpUEtJIFJvb3QgQ0EgLSBHMTAeFw0xOTAyMjIwOTQ2MDRa
+Fw0zNzEyMzExNTU5NTlaME8xCzAJBgNVBAYTAlRXMSMwIQYDVQQKDBpDaHVuZ2h3
+YSBUZWxlY29tIENvLiwgTHRkLjEbMBkGA1UEAwwSSGlQS0kgUm9vdCBDQSAtIEcx
+MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA9B5/UnMyDHPkvRN0o9Qw
+qNCuS9i233VHZvR85zkEHmpwINJaR3JnVfSl6J3VHiGh8Ge6zCFovkRTv4354twv
+Vcg3Px+kwJyz5HdcoEb+d/oaoDjq7Zpy3iu9lFc6uux55199QmQ5eiY29yTw1S+6
+lZgRZq2XNdZ1AYDgr/SEYYwNHl98h5ZeQa/rh+r4XfEuiAU+TCK72h8q3VJGZDnz
+Qs7ZngyzsHeXZJzA9KMuH5UHsBffMNsAGJZMoYFL3QRtU6M9/Aes1MU3guvklQgZ
+KILSQjqj2FPseYlgSGDIcpJQ3AOPgz+yQlda22rpEZfdhSi8MEyr48KxRURHH+CK
+FgeW0iEPU8DtqX7UTuybCeyvQqww1r/REEXgphaypcXTT3OUM3ECoWqj1jOXTyFj
+HluP2cFeRXF3D4FdXyGarYPM+l7WjSNfGz1BryB1ZlpK9p/7qxj3ccC2HTHsOyDr
+y+K49a6SsvfhhEvyovKTmiKe0xRvNlS9H15ZFblzqMF8b3ti6RZsR1pl8w4Rm0bZ
+/W3c1pzAtH2lsN0/Vm+h+fbkEkj9Bn8SV7apI09bA8PgcSojt/ewsTu8mL3WmKgM
+a/aOEmem8rJY5AIJEzypuxC00jBF8ez3ABHfZfjcK0NVvxaXxA/VLGGEqnKG/uY6
+fsI/fe78LxQ+5oXdUG+3Se0CAwEAAaNCMEAwDwYDVR0TAQH/BAUwAwEB/zAdBgNV
+HQ4EFgQU8ncX+l6o/vY9cdVouslGDDjYr7AwDgYDVR0PAQH/BAQDAgGGMA0GCSqG
+SIb3DQEBCwUAA4ICAQBQUfB13HAE4/+qddRxosuej6ip0691x1TPOhwEmSKsxBHi
+7zNKpiMdDg1H2DfHb680f0+BazVP6XKlMeJ45/dOlBhbQH3PayFUhuaVevvGyuqc
+SE5XCV0vrPSltJczWNWseanMX/mF+lLFjfiRFOs6DRfQUsJ748JzjkZ4Bjgs6Fza
+ZsT0pPBWGTMpWmWSBUdGSquEwx4noR8RkpkndZMPvDY7l1ePJlsMu5wP1G4wB9Tc
+XzZoZjmDlicmisjEOf6aIW/Vcobpf2Lll07QJNBAsNB1CI69aO4I1258EHBGG3zg
+iLKecoaZAeO/n0kZtCW+VmWuF2PlHt/o/0elv+EmBYTksMCv5wiZqAxeJoBF1Pho
+L5aPruJKHJwWDBNvOIf2u8g0X5IDUXlwpt/L9ZlNec1OvFefQ05rLisY+GpzjLrF
+Ne85akEez3GoorKGB1s6yeHvP2UEgEcyRHCVTjFnanRbEEV16rCf0OY1/k6fi8wr
+kkVbbiVghUbN0aqwdmaTd5a+g744tiROJgvM7XpWGuDpWsZkrUx6AEhEL7lAuxM+
+vhV4nYWBSipX3tUZQ9rbyltHhoMLP7YNdnhzeSJesYAfz77RP1YQmCuVh6EfnWQU
+YDksswBVLuT1sw5XxJFBAJw/6KXf6vb/yPCtbVKoF6ubYfwSUTXkJf2vqmqGOQ==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/ISRG_Root_X2.pem b/secure/caroot/trusted/ISRG_Root_X2.pem
new file mode 100644
index 000000000000..834653f2800d
--- /dev/null
+++ b/secure/caroot/trusted/ISRG_Root_X2.pem
@@ -0,0 +1,67 @@
+##
+## ISRG Root X2
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 41:d2:9d:d1:72:ea:ee:a7:80:c1:2c:6c:e9:2f:87:52
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = US, O = Internet Security Research Group, CN = ISRG Root X2
+ Validity
+ Not Before: Sep 4 00:00:00 2020 GMT
+ Not After : Sep 17 16:00:00 2040 GMT
+ Subject: C = US, O = Internet Security Research Group, CN = ISRG Root X2
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:cd:9b:d5:9f:80:83:0a:ec:09:4a:f3:16:4a:3e:
+ 5c:cf:77:ac:de:67:05:0d:1d:07:b6:dc:16:fb:5a:
+ 8b:14:db:e2:71:60:c4:ba:45:95:11:89:8e:ea:06:
+ df:f7:2a:16:1c:a4:b9:c5:c5:32:e0:03:e0:1e:82:
+ 18:38:8b:d7:45:d8:0a:6a:6e:e6:00:77:fb:02:51:
+ 7d:22:d8:0a:6e:9a:5b:77:df:f0:fa:41:ec:39:dc:
+ 75:ca:68:07:0c:1f:ea
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Subject Key Identifier:
+ 7C:42:96:AE:DE:4B:48:3B:FA:92:F8:9E:8C:CF:6D:8B:A9:72:37:95
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:30:7b:79:4e:46:50:84:c2:44:87:46:1b:45:70:ff:
+ 58:99:de:f4:fd:a4:d2:55:a6:20:2d:74:d6:34:bc:41:a3:50:
+ 5f:01:27:56:b4:be:27:75:06:af:12:2e:75:98:8d:fc:02:31:
+ 00:8b:f5:77:6c:d4:c8:65:aa:e0:0b:2c:ee:14:9d:27:37:a4:
+ f9:53:a5:51:e4:29:83:d7:f8:90:31:5b:42:9f:0a:f5:fe:ae:
+ 00:68:e7:8c:49:0f:b6:6f:5b:5b:15:f2:e7
+SHA1 Fingerprint=BD:B1:B9:3C:D5:97:8D:45:C6:26:14:55:F8:DB:95:C7:5A:D1:53:AF
+-----BEGIN CERTIFICATE-----
+MIICGzCCAaGgAwIBAgIQQdKd0XLq7qeAwSxs6S+HUjAKBggqhkjOPQQDAzBPMQsw
+CQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJuZXQgU2VjdXJpdHkgUmVzZWFyY2gg
+R3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBYMjAeFw0yMDA5MDQwMDAwMDBaFw00
+MDA5MTcxNjAwMDBaME8xCzAJBgNVBAYTAlVTMSkwJwYDVQQKEyBJbnRlcm5ldCBT
+ZWN1cml0eSBSZXNlYXJjaCBHcm91cDEVMBMGA1UEAxMMSVNSRyBSb290IFgyMHYw
+EAYHKoZIzj0CAQYFK4EEACIDYgAEzZvVn4CDCuwJSvMWSj5cz3es3mcFDR0HttwW
++1qLFNvicWDEukWVEYmO6gbf9yoWHKS5xcUy4APgHoIYOIvXRdgKam7mAHf7AlF9
+ItgKbppbd9/w+kHsOdx1ymgHDB/qo0IwQDAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0T
+AQH/BAUwAwEB/zAdBgNVHQ4EFgQUfEKWrt5LSDv6kviejM9ti6lyN5UwCgYIKoZI
+zj0EAwMDaAAwZQIwe3lORlCEwkSHRhtFcP9Ymd70/aTSVaYgLXTWNLxBo1BfASdW
+tL4ndQavEi51mI38AjEAi/V3bNTIZargCyzuFJ0nN6T5U6VR5CmD1/iQMVtCnwr1
+/q4AaOeMSQ+2b1tbFfLn
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Security_Communication_ECC_RootCA1.pem b/secure/caroot/trusted/Security_Communication_ECC_RootCA1.pem
new file mode 100644
index 000000000000..be449b7b695a
--- /dev/null
+++ b/secure/caroot/trusted/Security_Communication_ECC_RootCA1.pem
@@ -0,0 +1,67 @@
+##
+## Security Communication ECC RootCA1
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ d6:5d:9b:b3:78:81:2e:eb
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = Security Communication ECC RootCA1
+ Validity
+ Not Before: Jun 16 05:15:28 2016 GMT
+ Not After : Jan 18 05:15:28 2038 GMT
+ Subject: C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = Security Communication ECC RootCA1
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:a4:a5:6f:60:03:03:c3:bd:31:f4:d3:17:9c:2b:
+ 84:75:ac:e5:fd:3d:57:6e:d7:63:bf:e6:04:89:92:
+ 8e:81:9c:e3:e9:47:6e:ca:90:12:c8:13:e0:a7:9d:
+ f7:65:74:1f:6c:10:b2:e8:e4:e9:ef:6d:85:32:99:
+ 44:b1:5e:fd:cc:76:10:d8:5b:bd:a2:c6:f9:d6:42:
+ e4:57:76:dc:90:c2:35:a9:4b:88:3c:12:47:6d:5c:
+ ff:49:4f:1a:4a:50:b1
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 86:1C:E7:FE:2D:A5:4A:8B:08:FE:28:11:FA:BE:A3:66:F8:60:59:2F
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:30:15:5d:42:3d:fc:b6:ee:f7:3b:b1:36:e8:9e:f6:
+ c4:46:28:49:33:d0:58:43:2a:63:29:cc:4d:b1:b4:7a:a2:b9:
+ 0d:38:a5:5d:48:2a:fd:cb:b2:73:5d:a3:88:08:c7:0c:02:31:
+ 00:c0:ab:2d:0e:6d:ed:18:a2:db:53:e9:25:db:55:08:e0:50:
+ cc:df:44:61:16:82:ab:49:b0:b2:81:ec:73:87:78:b4:4c:b2:
+ 62:1b:12:fa:16:4d:25:4b:63:bd:1e:37:d9
+SHA1 Fingerprint=B8:0E:26:A9:BF:D2:B2:3B:C0:EF:46:C9:BA:C7:BB:F6:1D:0D:41:41
+-----BEGIN CERTIFICATE-----
+MIICODCCAb6gAwIBAgIJANZdm7N4gS7rMAoGCCqGSM49BAMDMGExCzAJBgNVBAYT
+AkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMSswKQYD
+VQQDEyJTZWN1cml0eSBDb21tdW5pY2F0aW9uIEVDQyBSb290Q0ExMB4XDTE2MDYx
+NjA1MTUyOFoXDTM4MDExODA1MTUyOFowYTELMAkGA1UEBhMCSlAxJTAjBgNVBAoT
+HFNFQ09NIFRydXN0IFN5c3RlbXMgQ08uLExURC4xKzApBgNVBAMTIlNlY3VyaXR5
+IENvbW11bmljYXRpb24gRUNDIFJvb3RDQTEwdjAQBgcqhkjOPQIBBgUrgQQAIgNi
+AASkpW9gAwPDvTH00xecK4R1rOX9PVdu12O/5gSJko6BnOPpR27KkBLIE+Cnnfdl
+dB9sELLo5OnvbYUymUSxXv3MdhDYW72ixvnWQuRXdtyQwjWpS4g8EkdtXP9JTxpK
+ULGjQjBAMB0GA1UdDgQWBBSGHOf+LaVKiwj+KBH6vqNm+GBZLzAOBgNVHQ8BAf8E
+BAMCAQYwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAwNoADBlAjAVXUI9/Lbu
+9zuxNuie9sRGKEkz0FhDKmMpzE2xtHqiuQ04pV1IKv3LsnNdo4gIxwwCMQDAqy0O
+be0YottT6SXbVQjgUMzfRGEWgqtJsLKB7HOHeLRMsmIbEvoWTSVLY70eN9k=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Security_Communication_RootCA3.pem b/secure/caroot/trusted/Security_Communication_RootCA3.pem
new file mode 100644
index 000000000000..1f00f6dacfa1
--- /dev/null
+++ b/secure/caroot/trusted/Security_Communication_RootCA3.pem
@@ -0,0 +1,135 @@
+##
+## Security Communication RootCA3
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ e1:7c:37:40:fd:1b:fe:67
+ Signature Algorithm: sha384WithRSAEncryption
+ Issuer: C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = Security Communication RootCA3
+ Validity
+ Not Before: Jun 16 06:17:16 2016 GMT
+ Not After : Jan 18 06:17:16 2038 GMT
+ Subject: C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = Security Communication RootCA3
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:e3:c9:72:49:f7:30:de:09:7c:a9:40:81:58:d3:
+ b4:3a:dd:ba:61:0f:93:50:6e:69:3c:35:c2:ee:5b:
+ 73:90:1b:67:4c:21:ec:5f:35:bb:39:3e:2b:0a:60:
+ ef:bb:6d:2b:86:fb:71:a2:c8:ac:e4:56:94:f9:c9:
+ af:b1:72:d4:20:ac:74:d2:b8:15:ad:51:fe:85:74:
+ a1:b9:10:fe:05:80:f9:52:93:b3:40:3d:75:10:ac:
+ c0:96:b7:a7:7e:76:bc:e3:1b:52:19:ce:11:1f:0b:
+ 04:34:f5:d8:f5:69:3c:77:f3:64:f4:0d:aa:85:de:
+ e0:09:50:04:17:96:84:b7:c8:8a:bc:4d:72:fc:1c:
+ bb:cf:f3:06:4d:f9:9f:64:f7:7e:a6:66:86:35:71:
+ c8:11:80:4c:c1:71:40:58:1e:be:a0:73:f6:fc:3e:
+ 50:e1:e0:2f:26:3d:7e:5c:23:b5:79:70:de:fa:e0:
+ d1:a5:d6:0c:41:71:7b:f7:ea:8c:1c:88:c7:ec:8b:
+ f5:d1:2f:55:96:46:7c:5a:3b:58:3b:fb:ba:d8:2d:
+ b5:25:da:7a:4e:cf:44:ae:21:a6:9e:98:ca:20:6e:
+ 7c:bb:88:85:5b:fb:c0:10:62:bb:f2:f9:27:47:ef:
+ d1:89:39:43:c4:df:de:e1:41:bf:54:73:20:97:2d:
+ 6c:da:f3:d4:07:a3:e6:b9:d8:6f:ae:fc:8c:19:2e:
+ d3:67:67:2b:95:db:58:5c:b5:6a:02:f3:b8:83:5e:
+ b4:6b:be:41:7e:57:09:75:44:50:55:cd:5a:11:61:
+ 21:0a:61:c2:a9:88:fd:13:bc:2d:89:2f:cd:61:e0:
+ 95:be:ca:b5:7b:e1:7b:34:67:0b:1f:b6:0c:c7:7c:
+ 1e:19:53:ca:a7:b1:4a:15:20:56:14:70:3d:2b:82:
+ 2c:0f:9d:15:1d:47:80:47:ff:78:99:0e:31:af:6f:
+ 3e:8f:ed:86:69:1e:7b:18:88:14:b2:c2:fc:82:33:
+ 2e:9c:4b:2d:fb:70:3b:71:aa:2b:7b:26:27:f3:1a:
+ c2:dc:fb:17:b8:a1:ea:cb:a0:b4:ae:d3:94:7e:7a:
+ d0:ab:c3:ec:38:2d:11:2e:88:bf:d4:3f:ad:12:3b:
+ 42:ac:8f:02:6e:7d:cc:d1:5f:61:be:a1:bc:3a:6a:
+ 48:ea:26:55:22:16:5d:5f:0d:ff:27:33:9f:18:03:
+ 74:8a:5b:52:20:47:6b:45:4d:22:77:8c:55:27:f0:
+ af:1e:8c:c9:83:22:54:b7:9a:d0:4f:d9:ce:fc:d9:
+ 2e:1c:96:28:b1:02:d3:03:bd:25:52:1c:34:66:4f:
+ 23:ab:f4:77:82:96:1d:d1:57:30:08:11:05:fd:57:
+ d1:d9:c7
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 64:14:7C:FC:58:72:16:A6:0A:29:34:15:6F:2A:CB:BC:FC:AF:A8:AB
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: sha384WithRSAEncryption
+ dc:02:23:08:e2:ef:21:3a:c7:0d:b7:26:d2:62:93:a7:a5:23:
+ 72:07:20:82:60:df:18:d7:54:ad:69:25:92:9e:d9:14:cf:99:
+ b9:52:81:cf:ae:6c:8a:3b:5a:39:c8:6c:01:43:c2:22:6d:02:
+ f0:62:cd:4e:63:43:c0:14:da:f4:63:f0:ea:f4:71:ee:4e:87:
+ e3:71:a9:f4:c9:57:e5:2e:5f:1c:79:bb:23:aa:87:44:57:e9:
+ bd:35:4d:41:bb:4b:28:a3:98:b2:1b:d9:0b:17:07:e5:f7:ea:
+ 9d:f5:76:d7:bf:c4:b6:81:58:ff:c8:ff:64:69:62:79:ad:6e:
+ 0e:1f:7f:ee:1d:69:e5:b7:72:71:b3:fe:a5:01:35:94:54:2b:
+ c0:52:6d:8f:55:c4:c9:d2:b8:cb:ca:34:08:51:85:a0:f5:bc:
+ b4:17:58:ea:0a:5c:7a:bd:63:c6:3a:2f:ff:96:49:19:84:ea:
+ 67:d8:04:b1:61:f4:00:5b:4a:b7:9c:71:37:19:85:79:bf:81:
+ b0:c7:13:0e:76:71:3e:3a:80:06:ae:06:16:a7:8d:b5:c2:c4:
+ cb:ff:40:a5:5c:8d:a5:c9:3a:ed:72:81:ca:5c:98:3c:d2:34:
+ 03:77:08:fd:f0:29:59:5d:21:08:c7:60:bf:a4:71:7b:b8:d9:
+ 1e:82:be:09:af:65:6f:28:ab:bf:4b:b5:ee:3e:08:47:27:a0:
+ 0f:6f:0f:8b:3f:ac:95:18:f3:b9:0e:dc:67:55:6e:62:9e:46:
+ 0e:d1:04:78:ca:72:ae:76:d9:a5:f8:b2:df:88:09:61:8b:ef:
+ 24:4e:d1:59:3f:5a:d4:3d:c9:93:3c:2b:64:f5:81:0d:16:96:
+ f7:92:c3:fe:31:6f:e8:2a:32:74:0e:f4:4c:98:4a:18:0e:30:
+ 54:d5:c5:eb:bc:c5:15:9e:e8:99:21:eb:27:2b:09:0a:db:f1:
+ e6:70:18:56:bb:0c:e4:be:f9:e8:10:a4:13:92:b8:1c:e0:db:
+ 67:1d:53:03:a4:22:a7:dc:5d:92:10:3c:ea:ff:fc:1b:10:1a:
+ c3:d8:d0:9c:9d:65:cb:d0:2b:27:31:03:1e:36:e1:3d:76:75:
+ 0c:ff:45:26:b9:dd:51:bc:23:c7:5f:d8:d8:87:10:40:12:0d:
+ 3d:38:37:e7:44:3c:18:c0:53:09:64:8f:ff:d5:9a:a6:7c:70:
+ 2e:73:55:21:e8:df:ff:83:b9:1d:3e:32:1e:d6:a6:7d:2c:f1:
+ 66:e9:5c:1d:a7:a3:ce:5e:25:32:2b:e3:95:ac:2a:07:ce:b4:
+ 28:78:86:3c:2d:a6:9d:4d:d2:74:30:dd:64:51:15:db:83:83:
+ 51:d7:af:fd:33:9d:4d:66
+SHA1 Fingerprint=C3:03:C8:22:74:92:E5:61:A2:9C:5F:79:91:2B:1E:44:13:91:30:3A
+-----BEGIN CERTIFICATE-----
+MIIFfzCCA2egAwIBAgIJAOF8N0D9G/5nMA0GCSqGSIb3DQEBDAUAMF0xCzAJBgNV
+BAYTAkpQMSUwIwYDVQQKExxTRUNPTSBUcnVzdCBTeXN0ZW1zIENPLixMVEQuMScw
+JQYDVQQDEx5TZWN1cml0eSBDb21tdW5pY2F0aW9uIFJvb3RDQTMwHhcNMTYwNjE2
+MDYxNzE2WhcNMzgwMTE4MDYxNzE2WjBdMQswCQYDVQQGEwJKUDElMCMGA1UEChMc
+U0VDT00gVHJ1c3QgU3lzdGVtcyBDTy4sTFRELjEnMCUGA1UEAxMeU2VjdXJpdHkg
+Q29tbXVuaWNhdGlvbiBSb290Q0EzMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIIC
+CgKCAgEA48lySfcw3gl8qUCBWNO0Ot26YQ+TUG5pPDXC7ltzkBtnTCHsXzW7OT4r
+CmDvu20rhvtxosis5FaU+cmvsXLUIKx00rgVrVH+hXShuRD+BYD5UpOzQD11EKzA
+lrenfna84xtSGc4RHwsENPXY9Wk8d/Nk9A2qhd7gCVAEF5aEt8iKvE1y/By7z/MG
+TfmfZPd+pmaGNXHIEYBMwXFAWB6+oHP2/D5Q4eAvJj1+XCO1eXDe+uDRpdYMQXF7
+9+qMHIjH7Iv10S9VlkZ8WjtYO/u62C21Jdp6Ts9EriGmnpjKIG58u4iFW/vAEGK7
+8vknR+/RiTlDxN/e4UG/VHMgly1s2vPUB6PmudhvrvyMGS7TZ2crldtYXLVqAvO4
+g160a75BflcJdURQVc1aEWEhCmHCqYj9E7wtiS/NYeCVvsq1e+F7NGcLH7YMx3we
+GVPKp7FKFSBWFHA9K4IsD50VHUeAR/94mQ4xr28+j+2GaR57GIgUssL8gjMunEst
++3A7caoreyYn8xrC3PsXuKHqy6C0rtOUfnrQq8PsOC0RLoi/1D+tEjtCrI8Cbn3M
+0V9hvqG8OmpI6iZVIhZdXw3/JzOfGAN0iltSIEdrRU0id4xVJ/CvHozJgyJUt5rQ
+T9nO/NkuHJYosQLTA70lUhw0Zk8jq/R3gpYd0VcwCBEF/VfR2ccCAwEAAaNCMEAw
+HQYDVR0OBBYEFGQUfPxYchamCik0FW8qy7z8r6irMA4GA1UdDwEB/wQEAwIBBjAP
+BgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDAUAA4ICAQDcAiMI4u8hOscNtybS
+YpOnpSNyByCCYN8Y11StaSWSntkUz5m5UoHPrmyKO1o5yGwBQ8IibQLwYs1OY0PA
+FNr0Y/Dq9HHuTofjcan0yVflLl8cebsjqodEV+m9NU1Bu0soo5iyG9kLFwfl9+qd
+9XbXv8S2gVj/yP9kaWJ5rW4OH3/uHWnlt3Jxs/6lATWUVCvAUm2PVcTJ0rjLyjQI
+UYWg9by0F1jqClx6vWPGOi//lkkZhOpn2ASxYfQAW0q3nHE3GYV5v4GwxxMOdnE+
+OoAGrgYWp421wsTL/0ClXI2lyTrtcoHKXJg80jQDdwj98ClZXSEIx2C/pHF7uNke
+gr4Jr2VvKKu/S7XuPghHJ6APbw+LP6yVGPO5DtxnVW5inkYO0QR4ynKudtml+LLf
+iAlhi+8kTtFZP1rUPcmTPCtk9YENFpb3ksP+MW/oKjJ0DvRMmEoYDjBU1cXrvMUV
+nuiZIesnKwkK2/HmcBhWuwzkvvnoEKQTkrgc4NtnHVMDpCKn3F2SEDzq//wbEBrD
+2NCcnWXL0CsnMQMeNuE9dnUM/0Umud1RvCPHX9jYhxBAEg09ODfnRDwYwFMJZI//
+1ZqmfHAuc1Uh6N//g7kdPjIe1qZ9LPFm6Vwdp6POXiUyK+OVrCoHzrQoeIY8Laad
+TdJ0MN1kURXbg4NR16/9M51NZg==
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/Telia_Root_CA_v2.pem b/secure/caroot/trusted/Telia_Root_CA_v2.pem
new file mode 100644
index 000000000000..a48f003eeb6b
--- /dev/null
+++ b/secure/caroot/trusted/Telia_Root_CA_v2.pem
@@ -0,0 +1,138 @@
+##
+## Telia Root CA v2
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 01:67:5f:27:d6:fe:7a:e3:e4:ac:be:09:5b:05:9e
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = FI, O = Telia Finland Oyj, CN = Telia Root CA v2
+ Validity
+ Not Before: Nov 29 11:55:54 2018 GMT
+ Not After : Nov 29 11:55:54 2043 GMT
+ Subject: C = FI, O = Telia Finland Oyj, CN = Telia Root CA v2
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:b2:d0:3f:07:bc:e2:7b:d0:6b:99:f8:e2:77:69:
+ e7:ce:9d:a4:03:bc:82:6d:a1:fe:81:65:1f:4c:27:
+ ac:8e:00:ba:16:7b:eb:30:6a:00:c0:b3:74:68:7e:
+ b2:af:c7:d5:62:b3:7a:3f:50:ca:8c:36:44:24:63:
+ d2:36:e9:0c:85:f6:43:76:d5:4c:a1:60:72:67:e2:
+ 28:33:a5:cb:31:b8:3a:22:23:34:b8:7d:bd:56:22:
+ 40:9d:ea:f4:7b:03:ad:68:fc:b2:81:4f:98:d0:74:
+ ea:8d:e5:7d:cd:63:c3:a3:f6:de:92:c2:58:19:e0:
+ 96:bb:c5:c4:a9:3d:a5:74:96:fe:af:f9:89:aa:bd:
+ 95:17:54:d8:78:44:f1:0c:77:15:92:e0:98:42:a7:
+ a4:d6:aa:20:92:cd:c1:a0:b3:96:b2:3a:84:42:8d:
+ 7d:d5:95:e4:d6:db:e9:62:c4:58:b3:79:c5:8c:d3:
+ 35:33:83:9f:75:a1:52:27:61:38:f1:59:3d:8e:50:
+ e0:bd:79:3c:e7:6c:96:fe:5e:d9:02:65:b4:8e:5c:
+ d0:11:34:df:5d:bf:52:a7:81:00:c3:7f:99:45:99:
+ 15:d5:17:c8:0a:53:ec:63:f3:99:7d:cc:69:12:86:
+ c2:17:f0:01:9e:bf:84:bc:d1:52:cb:1b:92:66:ce:
+ a4:53:e5:a1:bf:c4:db:09:d6:e6:89:56:2b:c8:e3:
+ 7c:de:e3:ff:89:e5:35:6e:28:e8:6c:0b:23:51:a9:
+ 25:05:eb:48:f8:dd:b1:ca:fa:6c:08:51:ef:b7:18:
+ 6c:44:ca:26:e1:73:c6:89:06:81:e5:8a:ac:b0:e2:
+ 29:c6:b9:24:b3:6b:44:11:f4:a5:43:c2:4c:43:e5:
+ 70:36:8c:b6:33:57:7a:95:2e:82:a0:f4:5c:10:b3:
+ 61:83:f6:02:05:86:2e:7c:2d:6c:dc:03:46:6e:35:
+ 93:d5:7a:95:2f:de:20:d8:5b:7e:94:90:04:6a:ba:
+ 59:3d:04:05:75:9d:37:a2:0e:2e:3d:eb:c1:a4:52:
+ 83:fe:d0:6b:d4:66:8e:dc:c6:e9:12:4e:1d:2a:57:
+ aa:10:bc:7c:5e:82:7d:a6:a6:c9:f2:2d:b9:f5:17:
+ 27:ad:d1:0e:89:54:2b:95:fa:c0:ad:1d:98:14:78:
+ 33:42:86:0a:a9:73:b5:fb:74:0d:b7:1b:30:19:c4:
+ 5a:0e:1c:27:b7:da:18:d0:ff:8a:c8:05:ba:f1:aa:
+ 1c:a2:37:b7:e6:48:a4:46:2c:94:ea:a8:76:62:47:
+ 8b:10:53:07:48:57:6c:e2:92:4d:b6:ae:05:cb:dc:
+ c1:4a:5e:8f:ac:3d:19:4e:c2:ed:60:75:2b:db:c1:
+ ca:42:d5
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Authority Key Identifier:
+ keyid:72:AC:E4:33:79:AA:45:87:F6:FD:AC:1D:9E:D6:C7:2F:86:D8:24:39
+
+ X509v3 Subject Key Identifier:
+ 72:AC:E4:33:79:AA:45:87:F6:FD:AC:1D:9E:D6:C7:2F:86:D8:24:39
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ Signature Algorithm: sha256WithRSAEncryption
+ a0:3b:59:a7:09:94:3e:36:84:d2:7e:2f:39:a5:96:97:fa:11:
+ ad:fc:67:f3:71:09:f2:b2:89:84:67:44:af:b9:ef:ed:96:ec:
+ 9c:64:db:32:30:6f:67:9a:ac:7e:5f:b2:ab:01:36:7e:81:fa:
+ e4:84:5e:d2:ac:36:e0:6b:62:c5:7d:4b:0e:82:6d:d2:76:62:
+ d1:fe:97:f8:9f:30:7c:18:f9:b4:52:77:82:1d:76:db:d3:1d:
+ a9:f0:c1:9a:00:bd:6d:75:d8:7d:e7:fa:c7:38:a3:9c:70:e8:
+ 46:79:03:af:2e:74:db:75:f8:6e:53:0c:03:c8:99:1a:89:35:
+ 19:3c:d3:c9:54:7c:a8:f0:2c:e6:6e:07:79:6f:6a:e1:e6:ea:
+ 91:82:69:0a:1d:c3:7e:59:a2:9e:6b:46:15:98:5b:d3:af:46:
+ 1d:62:c8:ce:80:52:49:11:3f:c9:04:12:c3:13:7c:3f:3b:8a:
+ 96:db:3c:a0:1e:0a:b4:8b:54:b2:24:67:0d:ef:82:cb:be:3c:
+ 7d:d1:e2:7f:ae:16:d6:56:58:b9:da:20:b1:83:15:a1:ef:8a:
+ 4d:32:6f:41:2f:13:52:82:94:d7:1a:c1:78:a2:51:dd:2b:70:
+ 6d:b7:1a:f9:f7:b0:e0:67:97:56:db:7c:61:53:09:03:28:02:
+ 40:c7:b3:d8:fd:9c:70:6a:c6:28:c3:85:e9:e2:ed:1a:93:a0:
+ de:4b:98:a2:84:3e:05:77:01:96:3d:fb:b4:20:0f:9c:72:02:
+ 7a:12:2f:d5:a3:ba:51:78:af:2a:2b:44:65:4e:b5:fd:0a:e8:
+ c1:cd:79:87:61:2b:de:80:57:45:bf:67:f1:9b:91:5e:a5:a4:
+ ec:59:48:10:0d:38:c7:b0:fa:c3:44:6d:04:f5:78:50:1c:92:
+ 96:5b:da:f5:b8:2e:ba:5b:cf:e5:f0:6a:9d:4b:2f:58:73:2d:
+ 4f:2d:c4:1c:3e:f4:b3:3f:ab:15:0e:3b:19:41:8a:a4:c1:57:
+ 12:66:71:4c:fa:53:e3:57:eb:62:95:09:9e:54:dd:d1:c2:3c:
+ 57:3c:bd:38:ad:98:64:b7:b8:03:9a:53:56:60:5d:b3:d8:42:
+ 1b:5c:4b:12:8a:1c:eb:eb:7d:c6:7a:69:c7:27:7f:a4:f8:8b:
+ f2:e4:94:66:87:4b:e9:94:07:09:12:79:8a:b2:eb:74:04:dc:
+ ce:f4:44:59:e0:16:ca:c5:2c:58:d7:3c:7b:cf:62:86:6a:50:
+ 7d:35:36:66:a7:fb:37:e7:28:c7:d8:d0:ad:a5:69:94:8f:e8:
+ c1:df:24:f8:1b:07:31:87:81:d8:5d:f6:e8:28:d8:4a:52:80:
+ ac:13:ee:50:14:1e:98:c7
+SHA1 Fingerprint=B9:99:CD:D1:73:50:8A:C4:47:05:08:9C:8C:88:FB:BE:A0:2B:40:CD
+-----BEGIN CERTIFICATE-----
+MIIFdDCCA1ygAwIBAgIPAWdfJ9b+euPkrL4JWwWeMA0GCSqGSIb3DQEBCwUAMEQx
+CzAJBgNVBAYTAkZJMRowGAYDVQQKDBFUZWxpYSBGaW5sYW5kIE95ajEZMBcGA1UE
+AwwQVGVsaWEgUm9vdCBDQSB2MjAeFw0xODExMjkxMTU1NTRaFw00MzExMjkxMTU1
+NTRaMEQxCzAJBgNVBAYTAkZJMRowGAYDVQQKDBFUZWxpYSBGaW5sYW5kIE95ajEZ
+MBcGA1UEAwwQVGVsaWEgUm9vdCBDQSB2MjCCAiIwDQYJKoZIhvcNAQEBBQADggIP
+ADCCAgoCggIBALLQPwe84nvQa5n44ndp586dpAO8gm2h/oFlH0wnrI4AuhZ76zBq
+AMCzdGh+sq/H1WKzej9Qyow2RCRj0jbpDIX2Q3bVTKFgcmfiKDOlyzG4OiIjNLh9
+vVYiQJ3q9HsDrWj8soFPmNB06o3lfc1jw6P23pLCWBnglrvFxKk9pXSW/q/5iaq9
+lRdU2HhE8Qx3FZLgmEKnpNaqIJLNwaCzlrI6hEKNfdWV5Nbb6WLEWLN5xYzTNTOD
+n3WhUidhOPFZPY5Q4L15POdslv5e2QJltI5c0BE0312/UqeBAMN/mUWZFdUXyApT
+7GPzmX3MaRKGwhfwAZ6/hLzRUssbkmbOpFPlob/E2wnW5olWK8jjfN7j/4nlNW4o
+6GwLI1GpJQXrSPjdscr6bAhR77cYbETKJuFzxokGgeWKrLDiKca5JLNrRBH0pUPC
+TEPlcDaMtjNXepUugqD0XBCzYYP2AgWGLnwtbNwDRm41k9V6lS/eINhbfpSQBGq6
+WT0EBXWdN6IOLj3rwaRSg/7Qa9RmjtzG6RJOHSpXqhC8fF6CfaamyfItufUXJ63R
+DolUK5X6wK0dmBR4M0KGCqlztft0DbcbMBnEWg4cJ7faGND/isgFuvGqHKI3t+ZI
+pEYslOqodmJHixBTB0hXbOKSTbauBcvcwUpej6w9GU7C7WB1K9vBykLVAgMBAAGj
+YzBhMB8GA1UdIwQYMBaAFHKs5DN5qkWH9v2sHZ7Wxy+G2CQ5MB0GA1UdDgQWBBRy
+rOQzeapFh/b9rB2e1scvhtgkOTAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/BAUw
+AwEB/zANBgkqhkiG9w0BAQsFAAOCAgEAoDtZpwmUPjaE0n4vOaWWl/oRrfxn83EJ
+8rKJhGdEr7nv7ZbsnGTbMjBvZ5qsfl+yqwE2foH65IRe0qw24GtixX1LDoJt0nZi
+0f6X+J8wfBj5tFJ3gh1229MdqfDBmgC9bXXYfef6xzijnHDoRnkDry5023X4blMM
+A8iZGok1GTzTyVR8qPAs5m4HeW9q4ebqkYJpCh3DflminmtGFZhb069GHWLIzoBS
+SRE/yQQSwxN8PzuKlts8oB4KtItUsiRnDe+Cy748fdHif64W1lZYudogsYMVoe+K
+TTJvQS8TUoKU1xrBeKJR3Stwbbca+few4GeXVtt8YVMJAygCQMez2P2ccGrGKMOF
+6eLtGpOg3kuYooQ+BXcBlj37tCAPnHICehIv1aO6UXivKitEZU61/Qrowc15h2Er
+3oBXRb9n8ZuRXqWk7FlIEA04x7D6w0RtBPV4UBySllva9bguulvP5fBqnUsvWHMt
+Ty3EHD70sz+rFQ47GUGKpMFXEmZxTPpT41frYpUJnlTd0cI8Vzy9OK2YZLe4A5pT
+VmBds9hCG1xLEooc6+t9xnppxyd/pPiL8uSUZodL6ZQHCRJ5irLrdATczvREWeAW
+ysUsWNc8e89ihmpQfTU2Zqf7N+cox9jQraVplI/owd8k+BsHMYeB2F326CjYSlKA
+rBPuUBQemMc=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/TunTrust_Root_CA.pem b/secure/caroot/trusted/TunTrust_Root_CA.pem
new file mode 100644
index 000000000000..b578a9d8c5b0
--- /dev/null
+++ b/secure/caroot/trusted/TunTrust_Root_CA.pem
@@ -0,0 +1,139 @@
+##
+## TunTrust Root CA
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 13:02:d5:e2:40:4c:92:46:86:16:67:5d:b4:bb:bb:b2:6b:3e:fc:13
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = TN, O = Agence Nationale de Certification Electronique, CN = TunTrust Root CA
+ Validity
+ Not Before: Apr 26 08:57:56 2019 GMT
+ Not After : Apr 26 08:57:56 2044 GMT
+ Subject: C = TN, O = Agence Nationale de Certification Electronique, CN = TunTrust Root CA
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:c3:cd:d3:fc:bd:04:53:dd:0c:20:3a:d5:88:2e:
+ 05:4b:41:f5:83:82:7e:f7:59:9f:9e:9e:63:e8:73:
+ da:f6:06:a9:4f:1f:b4:f9:0b:1f:39:8c:9a:20:d0:
+ 7e:06:d4:ec:34:d9:86:bc:75:5b:87:88:f0:d2:d9:
+ d4:a3:0a:b2:6c:1b:eb:49:2c:3e:ac:5d:d8:94:03:
+ a0:ec:34:e5:30:c4:35:7d:fb:26:4d:1b:6e:30:54:
+ d8:f5:80:45:9c:39:ad:9c:c9:25:04:4d:9a:90:3e:
+ 4e:40:6e:8a:6b:cd:29:67:c6:cc:2d:e0:74:e8:05:
+ 57:0a:48:50:fa:7a:43:da:7e:ec:5b:9a:0e:62:76:
+ fe:ea:9d:1d:85:72:ec:11:bb:35:e8:1f:27:bf:c1:
+ a1:c7:bb:48:16:dd:56:d7:cc:4e:a0:e1:b9:ac:db:
+ d5:83:19:1a:85:d1:94:97:d7:ca:a3:65:0b:f3:38:
+ f9:02:ae:dd:f6:67:cf:c9:3f:f5:8a:2c:47:1a:99:
+ 6f:05:0d:fd:d0:1d:82:31:fc:29:cc:00:58:97:91:
+ 4c:80:00:1c:33:85:96:2f:cb:41:c2:8b:10:84:c3:
+ 09:24:89:1f:b5:0f:d9:d9:77:47:18:92:94:60:5c:
+ c7:99:03:3c:fe:f7:95:a7:7d:50:a1:80:c2:a9:83:
+ ad:58:96:55:21:db:86:59:d4:af:c6:bc:dd:81:6e:
+ 07:db:60:62:fe:ec:10:6e:da:68:01:f4:83:1b:a9:
+ 3e:a2:5b:23:d7:64:c6:df:dc:a2:7d:d8:4b:ba:82:
+ d2:51:f8:66:bf:06:46:e4:79:2a:26:36:79:8f:1f:
+ 4e:99:1d:b2:8f:0c:0e:1c:ff:c9:5d:c0:fd:90:10:
+ a6:b1:37:f3:cd:3a:24:6e:b4:85:90:bf:80:b9:0c:
+ 8c:d5:9b:d6:c8:f1:56:3f:1a:80:89:7a:a9:e2:1b:
+ 32:51:2c:3e:f2:df:7b:f6:5d:7a:29:19:8e:e5:c8:
+ bd:36:71:8b:5d:4c:c2:1d:3f:ad:58:a2:cf:3d:70:
+ 4d:a6:50:98:25:dc:23:f9:b8:58:41:08:71:bf:4f:
+ b8:84:a0:8f:00:54:15:fc:91:6d:58:a7:96:3b:eb:
+ 4b:96:27:cd:6b:a2:a1:86:ac:0d:7c:54:e6:66:4c:
+ 66:5f:90:be:21:9a:02:46:2d:e4:83:c2:80:b9:cf:
+ 4b:3e:e8:7f:3c:01:ec:8f:5e:cd:7f:d2:28:42:01:
+ 95:8a:e2:97:3d:10:21:7d:f6:9d:1c:c5:34:a1:ec:
+ 2c:0e:0a:52:2c:12:55:70:24:3d:cb:c2:14:35:43:
+ 5d:27:4e:be:c0:bd:aa:7c:96:e7:fc:9e:61:ad:44:
+ d3:00:97
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 06:9A:9B:1F:53:7D:F1:F5:A4:C8:D3:86:3E:A1:73:59:B4:F7:44:21
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Authority Key Identifier:
+ keyid:06:9A:9B:1F:53:7D:F1:F5:A4:C8:D3:86:3E:A1:73:59:B4:F7:44:21
+
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ aa:05:6e:b6:dd:15:c9:bf:b3:c6:20:f6:06:47:b0:86:93:25:
+ d3:8d:b9:c8:00:3f:97:f5:52:27:88:71:c9:74:fd:eb:ca:64:
+ db:5b:ef:1e:5d:ba:bf:d1:eb:ee:5c:69:ba:16:c8:f3:b9:8f:
+ d3:36:2e:40:49:07:0d:59:de:8b:10:b0:49:05:e2:ff:91:3f:
+ 4b:b7:dd:02:8e:f8:81:28:5c:cc:dc:6d:af:5f:14:9c:7d:58:
+ 78:0d:f6:80:09:b9:e9:0e:97:29:19:b8:b7:eb:f8:16:cb:55:
+ 12:e4:c6:7d:bb:c4:ec:f8:b5:1c:4e:3e:67:bf:c5:5f:1b:6d:
+ 6d:47:28:aa:04:58:61:d6:76:bf:22:7f:d0:07:6a:a7:64:53:
+ f0:97:8d:9d:80:3f:bb:c1:07:db:65:af:e6:9b:32:9a:c3:54:
+ 93:c4:1c:08:c3:44:fb:7b:63:11:43:d1:6a:1a:61:6a:79:6d:
+ 90:4f:29:8e:47:05:c1:12:69:69:d6:c6:36:31:e1:fc:fa:80:
+ ba:5c:4f:c4:eb:b7:32:ac:f8:75:61:17:d7:10:19:b9:f1:d2:
+ 09:ef:7a:42:9d:5b:5a:0b:d4:c6:95:4e:2a:ce:ff:07:d7:4f:
+ 7e:18:06:88:f1:19:b5:d9:98:bb:ae:71:c4:1c:e7:74:59:58:
+ ef:0c:89:cf:8b:1f:75:93:1a:04:14:92:48:50:a9:eb:57:29:
+ 00:16:e3:36:1c:c8:f8:bf:f0:33:d5:41:0f:c4:cc:3c:dd:e9:
+ 33:43:01:91:10:2b:1e:d1:b9:5d:cd:32:19:8b:8f:8c:20:77:
+ d7:22:c4:42:dc:84:16:9b:25:6d:e8:b4:55:71:7f:b0:7c:b3:
+ d3:71:49:b9:cf:52:a4:04:3f:dc:3d:a0:bb:af:33:9e:0a:30:
+ 60:8e:db:9d:5d:94:a8:bd:60:e7:62:80:76:81:83:0c:8c:cc:
+ 30:46:49:e2:0c:d2:a8:af:eb:61:71:ef:e7:22:62:a9:f7:5c:
+ 64:6c:9f:16:8c:67:36:27:45:f5:09:7b:bf:f6:10:0a:f1:b0:
+ 8d:54:43:8c:04:ba:a3:3f:ef:e2:35:c7:f9:74:e0:6f:34:41:
+ d0:bf:73:65:57:20:f9:9b:67:7a:66:68:24:4e:80:65:bd:10:
+ 99:06:59:f2:65:af:b8:c6:47:bb:fd:90:78:8b:41:73:2e:af:
+ 55:1f:dc:3b:92:72:6e:84:d3:d0:61:4c:0d:cc:76:57:e2:2d:
+ 85:22:15:36:0d:eb:01:9d:eb:d8:eb:c4:84:99:fb:c0:0c:cc:
+ 32:e8:e3:77:da:83:44:8b:9e:55:28:c0:8b:58:d3:90:3e:4e:
+ 1b:00:f1:15:ad:83:2b:9a
+SHA1 Fingerprint=CF:E9:70:84:0F:E0:73:0F:9D:F6:0C:7F:2C:4B:EE:20:46:34:9C:BB
+-----BEGIN CERTIFICATE-----
+MIIFszCCA5ugAwIBAgIUEwLV4kBMkkaGFmddtLu7sms+/BMwDQYJKoZIhvcNAQEL
+BQAwYTELMAkGA1UEBhMCVE4xNzA1BgNVBAoMLkFnZW5jZSBOYXRpb25hbGUgZGUg
+Q2VydGlmaWNhdGlvbiBFbGVjdHJvbmlxdWUxGTAXBgNVBAMMEFR1blRydXN0IFJv
+b3QgQ0EwHhcNMTkwNDI2MDg1NzU2WhcNNDQwNDI2MDg1NzU2WjBhMQswCQYDVQQG
+EwJUTjE3MDUGA1UECgwuQWdlbmNlIE5hdGlvbmFsZSBkZSBDZXJ0aWZpY2F0aW9u
+IEVsZWN0cm9uaXF1ZTEZMBcGA1UEAwwQVHVuVHJ1c3QgUm9vdCBDQTCCAiIwDQYJ
+KoZIhvcNAQEBBQADggIPADCCAgoCggIBAMPN0/y9BFPdDCA61YguBUtB9YOCfvdZ
+n56eY+hz2vYGqU8ftPkLHzmMmiDQfgbU7DTZhrx1W4eI8NLZ1KMKsmwb60ksPqxd
+2JQDoOw05TDENX37Jk0bbjBU2PWARZw5rZzJJQRNmpA+TkBuimvNKWfGzC3gdOgF
+VwpIUPp6Q9p+7FuaDmJ2/uqdHYVy7BG7NegfJ7/Boce7SBbdVtfMTqDhuazb1YMZ
+GoXRlJfXyqNlC/M4+QKu3fZnz8k/9YosRxqZbwUN/dAdgjH8KcwAWJeRTIAAHDOF
+li/LQcKLEITDCSSJH7UP2dl3RxiSlGBcx5kDPP73lad9UKGAwqmDrViWVSHbhlnU
+r8a83YFuB9tgYv7sEG7aaAH0gxupPqJbI9dkxt/con3YS7qC0lH4Zr8GRuR5KiY2
+eY8fTpkdso8MDhz/yV3A/ZAQprE38806JG60hZC/gLkMjNWb1sjxVj8agIl6qeIb
+MlEsPvLfe/ZdeikZjuXIvTZxi11Mwh0/rViizz1wTaZQmCXcI/m4WEEIcb9PuISg
+jwBUFfyRbVinljvrS5YnzWuioYasDXxU5mZMZl+QviGaAkYt5IPCgLnPSz7ofzwB
+7I9ezX/SKEIBlYrilz0QIX32nRzFNKHsLA4KUiwSVXAkPcvCFDVDXSdOvsC9qnyW
+5/yeYa1E0wCXAgMBAAGjYzBhMB0GA1UdDgQWBBQGmpsfU33x9aTI04Y+oXNZtPdE
+ITAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFAaamx9TffH1pMjThj6hc1m0
+90QhMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAgEAqgVutt0Vyb+z
+xiD2BkewhpMl0425yAA/l/VSJ4hxyXT968pk21vvHl26v9Hr7lxpuhbI87mP0zYu
+QEkHDVneixCwSQXi/5E/S7fdAo74gShczNxtr18UnH1YeA32gAm56Q6XKRm4t+v4
+FstVEuTGfbvE7Pi1HE4+Z7/FXxttbUcoqgRYYdZ2vyJ/0Adqp2RT8JeNnYA/u8EH
+22Wv5psymsNUk8QcCMNE+3tjEUPRahphanltkE8pjkcFwRJpadbGNjHh/PqAulxP
+xOu3Mqz4dWEX1xAZufHSCe96Qp1bWgvUxpVOKs7/B9dPfhgGiPEZtdmYu65xxBzn
+dFlY7wyJz4sfdZMaBBSSSFCp61cpABbjNhzI+L/wM9VBD8TMPN3pM0MBkRArHtG5
+Xc0yGYuPjCB31yLEQtyEFpslbei0VXF/sHyz03FJuc9SpAQ/3D2gu68zngowYI7b
+nV2UqL1g52KAdoGDDIzMMEZJ4gzSqK/rYXHv5yJiqfdcZGyfFoxnNidF9Ql7v/YQ
+CvGwjVRDjAS6oz/v4jXH+XTgbzRB0L9zZVcg+ZtnemZoJE6AZb0QmQZZ8mWvuMZH
+u/2QeItBcy6vVR/cO5JyboTT0GFMDcx2V+IthSIVNg3rAZ3r2OvEhJn7wAzMMujj
+d9qDRIueVSjAi1jTkD5OGwDxFa2DK5o=
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/vTrus_ECC_Root_CA.pem b/secure/caroot/trusted/vTrus_ECC_Root_CA.pem
new file mode 100644
index 000000000000..f5274c2d7ca5
--- /dev/null
+++ b/secure/caroot/trusted/vTrus_ECC_Root_CA.pem
@@ -0,0 +1,67 @@
+##
+## vTrus ECC Root CA
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 6e:6a:bc:59:aa:53:be:98:39:67:a2:d2:6b:a4:3b:e6:6d:1c:d6:da
+ Signature Algorithm: ecdsa-with-SHA384
+ Issuer: C = CN, O = "iTrusChina Co.,Ltd.", CN = vTrus ECC Root CA
+ Validity
+ Not Before: Jul 31 07:26:44 2018 GMT
+ Not After : Jul 31 07:26:44 2043 GMT
+ Subject: C = CN, O = "iTrusChina Co.,Ltd.", CN = vTrus ECC Root CA
+ Subject Public Key Info:
+ Public Key Algorithm: id-ecPublicKey
+ Public-Key: (384 bit)
+ pub:
+ 04:65:50:4a:ae:8c:79:96:4a:aa:1c:08:c3:a3:a2:
+ cd:fe:59:56:41:77:fd:26:94:42:bb:1d:cd:08:db:
+ 73:b2:5b:75:f3:cf:9c:4e:82:f4:bf:f8:61:26:85:
+ 6c:d6:85:5b:72:70:d2:fd:db:62:b4:df:53:8b:bd:
+ b1:44:58:62:42:09:c7:fa:7f:5b:10:e7:fe:40:fd:
+ c0:d8:c3:2b:32:e7:70:a6:b7:a6:20:55:1d:7b:80:
+ 5d:4b:8f:67:4c:f1:10
+ ASN1 OID: secp384r1
+ NIST CURVE: P-384
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 98:39:CD:BE:D8:B2:8C:F7:B2:AB:E1:AD:24:AF:7B:7C:A1:DB:1F:CF
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: ecdsa-with-SHA384
+ 30:65:02:30:57:9d:dd:56:f1:c7:e3:e9:b8:49:50:6b:9b:69:
+ c3:6f:ec:c3:7d:25:e4:57:95:13:40:9b:52:d3:3b:f3:40:19:
+ bc:26:c7:2d:06:9e:b5:7b:36:9f:f5:25:d4:63:6b:00:02:31:
+ 00:e9:d3:c6:9e:56:9a:2a:cc:a1:da:3f:c8:66:2b:d3:58:9c:
+ 20:85:fa:ab:91:8a:70:70:11:38:60:64:0b:62:09:91:58:00:
+ f9:4d:fb:34:68:da:09:ad:21:06:18:94:ce
+SHA1 Fingerprint=F6:9C:DB:B0:FC:F6:02:13:B6:52:32:A6:A3:91:3F:16:70:DA:C3:E1
+-----BEGIN CERTIFICATE-----
+MIICDzCCAZWgAwIBAgIUbmq8WapTvpg5Z6LSa6Q75m0c1towCgYIKoZIzj0EAwMw
+RzELMAkGA1UEBhMCQ04xHDAaBgNVBAoTE2lUcnVzQ2hpbmEgQ28uLEx0ZC4xGjAY
+BgNVBAMTEXZUcnVzIEVDQyBSb290IENBMB4XDTE4MDczMTA3MjY0NFoXDTQzMDcz
+MTA3MjY0NFowRzELMAkGA1UEBhMCQ04xHDAaBgNVBAoTE2lUcnVzQ2hpbmEgQ28u
+LEx0ZC4xGjAYBgNVBAMTEXZUcnVzIEVDQyBSb290IENBMHYwEAYHKoZIzj0CAQYF
+K4EEACIDYgAEZVBKrox5lkqqHAjDo6LN/llWQXf9JpRCux3NCNtzslt188+cToL0
+v/hhJoVs1oVbcnDS/dtitN9Ti72xRFhiQgnH+n9bEOf+QP3A2MMrMudwpremIFUd
+e4BdS49nTPEQo0IwQDAdBgNVHQ4EFgQUmDnNvtiyjPeyq+GtJK97fKHbH88wDwYD
+VR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwCgYIKoZIzj0EAwMDaAAwZQIw
+V53dVvHH4+m4SVBrm2nDb+zDfSXkV5UTQJtS0zvzQBm8JsctBp61ezaf9SXUY2sA
+AjEA6dPGnlaaKsyh2j/IZivTWJwghfqrkYpwcBE4YGQLYgmRWAD5Tfs0aNoJrSEG
+GJTO
+-----END CERTIFICATE-----
diff --git a/secure/caroot/trusted/vTrus_Root_CA.pem b/secure/caroot/trusted/vTrus_Root_CA.pem
new file mode 100644
index 000000000000..dba35fd1f454
--- /dev/null
+++ b/secure/caroot/trusted/vTrus_Root_CA.pem
@@ -0,0 +1,134 @@
+##
+## vTrus Root CA
+##
+## This is a single X.509 certificate for a public Certificate
+## Authority (CA). It was automatically extracted from Mozilla's
+## root CA list (the file `certdata.txt' in security/nss).
+##
+## It contains a certificate trusted for server authentication.
+##
+## Extracted from nss
+## with $FreeBSD$
+##
+## @generated
+##
+Certificate:
+ Data:
+ Version: 3 (0x2)
+ Serial Number:
+ 43:e3:71:13:d8:b3:59:14:5d:b7:ce:8c:fd:35:fd:6f:bc:05:8d:45
+ Signature Algorithm: sha256WithRSAEncryption
+ Issuer: C = CN, O = "iTrusChina Co.,Ltd.", CN = vTrus Root CA
+ Validity
+ Not Before: Jul 31 07:24:05 2018 GMT
+ Not After : Jul 31 07:24:05 2043 GMT
+ Subject: C = CN, O = "iTrusChina Co.,Ltd.", CN = vTrus Root CA
+ Subject Public Key Info:
+ Public Key Algorithm: rsaEncryption
+ RSA Public-Key: (4096 bit)
+ Modulus:
+ 00:bd:55:7c:61:d3:b8:1d:04:62:05:a0:ae:6c:b7:
+ 70:b4:41:ea:4b:03:5e:10:3f:90:5a:1c:8b:3b:b0:
+ 66:8b:6c:48:a6:1c:22:ba:d5:40:92:ee:33:b2:23:
+ 59:c9:8e:bc:58:da:8b:9e:d0:19:f2:2f:59:c6:8c:
+ 63:5a:ba:9f:a3:0b:b0:b3:9a:5c:ba:11:b8:12:e9:
+ 0c:bb:cf:6e:6c:80:87:29:14:03:2c:8d:24:9a:c8:
+ 64:83:b5:6a:ac:13:2c:33:f1:9f:dc:2c:61:3c:1a:
+ 3f:70:55:9b:ad:00:52:7f:cf:04:b9:fe:36:fa:9c:
+ c0:16:ae:62:fe:96:4c:43:7e:55:14:be:1a:b3:d2:
+ 6d:c2:af:76:66:95:6b:2a:b0:94:77:85:5e:04:0f:
+ 62:1d:63:75:f7:6b:e7:cb:5b:9a:70:ec:3e:67:05:
+ f0:fe:07:08:80:cf:28:db:05:c6:14:27:2f:86:7d:
+ f0:27:de:ff:e6:7e:33:48:e7:0b:1e:58:d1:27:2b:
+ 53:0e:57:4a:65:d7:fb:a2:80:60:fc:4c:bc:35:53:
+ 01:6a:97:72:82:af:f1:1d:70:e8:9c:f5:ef:5e:c2:
+ 6c:c7:47:7e:5a:94:85:26:4d:3b:ba:eb:4c:e8:b0:
+ 09:c2:65:c2:9d:9d:09:9b:4e:b5:97:05:ac:f5:06:
+ a0:f7:36:05:7e:f4:90:b2:6b:c4:b4:f9:64:ea:e9:
+ 1a:0a:c8:0d:a8:ed:27:c9:d4:e7:b3:b9:ab:82:22:
+ 90:27:3d:2a:e8:7c:90:ef:bc:4f:fd:e2:0a:24:a7:
+ de:65:24:a4:5d:ea:c0:76:30:d3:77:50:f8:0d:04:
+ 9b:94:36:01:73:ca:06:58:a6:d3:3b:dc:fa:04:46:
+ 13:55:8a:c9:44:47:b8:51:39:1a:2e:e8:34:e2:79:
+ cb:59:4a:0a:7f:bc:a6:ef:1f:03:67:6a:59:2b:25:
+ 62:93:d9:53:19:66:3c:27:62:29:86:4d:a4:6b:ee:
+ ff:d4:4e:ba:d5:b4:e2:8e:48:5a:00:19:09:f1:05:
+ d9:ce:91:b1:f7:eb:e9:39:4f:f6:6f:04:43:9a:55:
+ f5:3e:05:14:bd:bf:b3:59:b4:d8:8e:33:84:a3:90:
+ 52:aa:b3:02:95:60:f9:0c:4c:68:f9:ee:d5:17:0d:
+ f8:71:57:b5:25:e4:29:ee:65:5d:af:d1:ee:3c:17:
+ 0b:5a:43:c5:a5:86:ea:24:9e:e2:05:07:dc:34:42:
+ 12:91:d6:39:74:ae:4c:41:82:db:f2:a6:48:d1:b3:
+ 9b:f3:33:aa:f3:a6:c0:c5:4e:f5:f4:9d:76:63:e6:
+ 02:c6:22:4b:c1:95:3f:50:64:2c:54:e5:b6:f0:3c:
+ 29:cf:57
+ Exponent: 65537 (0x10001)
+ X509v3 extensions:
+ X509v3 Subject Key Identifier:
+ 54:62:70:63:F1:75:84:43:58:8E:D1:16:20:B1:C6:AC:1A:BC:F6:89
+ X509v3 Basic Constraints: critical
+ CA:TRUE
+ X509v3 Key Usage: critical
+ Certificate Sign, CRL Sign
+ Signature Algorithm: sha256WithRSAEncryption
+ 29:ba:92:49:a7:ad:f0:f1:70:c3:e4:97:f0:9f:a9:25:d5:6b:
+ 9e:34:fe:e6:1a:64:f6:3a:6b:52:b2:10:78:1a:9f:4c:da:8a:
+ da:ec:1c:37:52:e0:42:4b:fb:6c:76:ca:24:0b:39:12:15:9d:
+ 9f:11:2d:fc:79:64:dc:e0:e0:f5:dd:e0:57:c9:a5:b2:76:70:
+ 50:a4:fe:b7:0a:70:d5:a0:34:f1:75:d7:4d:49:ba:11:d1:b3:
+ d8:ec:82:ff:eb:0e:c4:bf:64:2d:7d:63:6e:17:78:ec:5d:7c:
+ 88:c8:eb:8e:57:76:d9:59:04:fa:bc:52:1f:45:ac:f0:7a:80:
+ ec:ec:6f:76:ae:91:db:10:8e:04:dc:92:df:a0:f6:e6:ae:49:
+ d3:c1:6c:12:1b:cc:29:aa:f9:08:a5:e2:37:14:ca:b1:b8:66:
+ ef:1a:82:e4:f0:f8:f1:a7:16:69:b7:db:a9:61:3c:9f:f5:31:
+ cb:e4:00:46:c2:2f:74:b1:b1:d7:81:ee:a8:26:95:bc:88:af:
+ 4c:35:07:2a:02:ca:78:14:6d:47:2b:40:56:e9:cb:2a:60:a1:
+ 67:03:a0:ce:8c:bc:b0:72:67:c4:31:ce:db:34:e5:25:03:60:
+ 25:7b:71:98:e4:c0:1b:2b:5f:74:42:d2:4b:c5:59:08:07:87:
+ be:c5:c3:7f:e7:96:d9:e1:dc:28:97:d6:8f:05:e3:f5:9b:4e:
+ ca:1d:50:47:05:53:b0:ca:39:e7:85:a0:89:c1:05:3b:01:37:
+ d3:3f:49:e2:77:eb:23:c8:88:66:3b:3d:39:76:21:46:f1:ec:
+ 5f:23:b8:eb:a2:66:75:74:c1:40:f7:d8:68:9a:93:e2:2d:a9:
+ 2e:bd:1c:a3:1e:c8:74:c6:a4:2d:7a:20:ab:3b:b8:b0:46:fd:
+ 6f:dd:5f:52:55:75:62:f0:97:a0:7c:d7:38:fd:25:df:cd:a0:
+ 9b:10:cf:8b:b8:38:5e:5e:c5:b4:a6:02:36:a1:1e:5f:1c:cf:
+ e2:96:9d:29:aa:fd:98:ae:52:e1:f3:41:52:fb:a9:2e:72:96:
+ 9f:27:e3:aa:73:7d:f8:1a:23:66:7b:3b:ab:65:b0:32:01:4b:
+ 15:3e:3d:a2:4f:0c:2b:35:a2:c6:d9:67:12:35:30:cd:76:2e:
+ 16:b3:99:9e:4d:4f:4e:2d:3b:34:43:e1:9a:0e:0d:a4:66:97:
+ ba:d2:1c:4a:4c:2c:2a:8b:8b:81:4f:71:1a:a9:dd:5c:7b:7b:
+ 08:c5:00:0d:37:40:e3:7c:7b:54:5f:2f:85:5f:76:f6:f7:a7:
+ b0:1c:57:56:c1:72:e8:ad:a2:af:8d:33:49:ba:1f:8a:dc:e6:
+ 74:7c:60:86:6f:87:97:7b
+SHA1 Fingerprint=84:1A:69:FB:F5:CD:1A:25:34:13:3D:E3:F8:FC:B8:99:D0:C9:14:B7
+-----BEGIN CERTIFICATE-----
+MIIFVjCCAz6gAwIBAgIUQ+NxE9izWRRdt86M/TX9b7wFjUUwDQYJKoZIhvcNAQEL
+BQAwQzELMAkGA1UEBhMCQ04xHDAaBgNVBAoTE2lUcnVzQ2hpbmEgQ28uLEx0ZC4x
+FjAUBgNVBAMTDXZUcnVzIFJvb3QgQ0EwHhcNMTgwNzMxMDcyNDA1WhcNNDMwNzMx
+MDcyNDA1WjBDMQswCQYDVQQGEwJDTjEcMBoGA1UEChMTaVRydXNDaGluYSBDby4s
+THRkLjEWMBQGA1UEAxMNdlRydXMgUm9vdCBDQTCCAiIwDQYJKoZIhvcNAQEBBQAD
+ggIPADCCAgoCggIBAL1VfGHTuB0EYgWgrmy3cLRB6ksDXhA/kFocizuwZotsSKYc
+IrrVQJLuM7IjWcmOvFjai57QGfIvWcaMY1q6n6MLsLOaXLoRuBLpDLvPbmyAhykU
+AyyNJJrIZIO1aqwTLDPxn9wsYTwaP3BVm60AUn/PBLn+NvqcwBauYv6WTEN+VRS+
+GrPSbcKvdmaVayqwlHeFXgQPYh1jdfdr58tbmnDsPmcF8P4HCIDPKNsFxhQnL4Z9
+8Cfe/+Z+M0jnCx5Y0ScrUw5XSmXX+6KAYPxMvDVTAWqXcoKv8R1w6Jz1717CbMdH
+flqUhSZNO7rrTOiwCcJlwp2dCZtOtZcFrPUGoPc2BX70kLJrxLT5ZOrpGgrIDajt
+J8nU57O5q4IikCc9Kuh8kO+8T/3iCiSn3mUkpF3qwHYw03dQ+A0Em5Q2AXPKBlim
+0zvc+gRGE1WKyURHuFE5Gi7oNOJ5y1lKCn+8pu8fA2dqWSslYpPZUxlmPCdiKYZN
+pGvu/9ROutW04o5IWgAZCfEF2c6Rsffr6TlP9m8EQ5pV9T4FFL2/s1m02I4zhKOQ
+UqqzApVg+QxMaPnu1RcN+HFXtSXkKe5lXa/R7jwXC1pDxaWG6iSe4gUH3DRCEpHW
+OXSuTEGC2/KmSNGzm/MzqvOmwMVO9fSddmPmAsYiS8GVP1BkLFTltvA8Kc9XAgMB
+AAGjQjBAMB0GA1UdDgQWBBRUYnBj8XWEQ1iO0RYgscasGrz2iTAPBgNVHRMBAf8E
+BTADAQH/MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAgEAKbqSSaet
+8PFww+SX8J+pJdVrnjT+5hpk9jprUrIQeBqfTNqK2uwcN1LgQkv7bHbKJAs5EhWd
+nxEt/Hlk3ODg9d3gV8mlsnZwUKT+twpw1aA08XXXTUm6EdGz2OyC/+sOxL9kLX1j
+bhd47F18iMjrjld22VkE+rxSH0Ws8HqA7Oxvdq6R2xCOBNyS36D25q5J08FsEhvM
+Kar5CKXiNxTKsbhm7xqC5PD48acWabfbqWE8n/Uxy+QARsIvdLGx14HuqCaVvIiv
+TDUHKgLKeBRtRytAVunLKmChZwOgzoy8sHJnxDHO2zTlJQNgJXtxmOTAGytfdELS
+S8VZCAeHvsXDf+eW2eHcKJfWjwXj9ZtOyh1QRwVTsMo554WgicEFOwE30z9J4nfr
+I8iIZjs9OXYhRvHsXyO466JmdXTBQPfYaJqT4i2pLr0cox7IdMakLXogqzu4sEb9
+b91fUlV1YvCXoHzXOP0l382gmxDPi7g4Xl7FtKYCNqEeXxzP4padKar9mK5S4fNB
+UvupLnKWnyfjqnN9+BojZns7q2WwMgFLFT49ok8MKzWixtlnEjUwzXYuFrOZnk1P
+Ti07NEPhmg4NpGaXutIcSkwsKouLgU9xGqndXHt7CMUADTdA43x7VF8vhV929ven
+sBxXVsFy6K2ir40zSbofitzmdHxghm+Hl3s=
+-----END CERTIFICATE-----