如何从系统中删除证书颁发机构的证书?

如何从系统中删除证书颁发机构的证书?

ca-certificates软件包刚刚更新,它导致我的 Xubuntu 13.10 系统发生以下变化:

Running hooks in /etc/ca-certificates/update.d....
Adding debian:CA_Disig_Root_R1.pem
Adding debian:CA_Disig_Root_R2.pem
Adding debian:China_Internet_Network_Information_Center_EV_Certificates_Root.pem
Adding debian:D-TRUST_Root_Class_3_CA_2_2009.pem
Adding debian:D-TRUST_Root_Class_3_CA_2_EV_2009.pem
Adding debian:PSCProcert.pem
Adding debian:StartCom_Certification_Authority_2.pem
Adding debian:Swisscom_Root_CA_2.pem
Adding debian:Swisscom_Root_EV_CA_2.pem
Adding debian:TURKTRUST_Certificate_Services_Provider_Root_2007.pem
Adding debian:Verisign_Class_3_Public_Primary_Certification_Authority_2.pem
Removing debian:cacert.org_class3.pem
Removing debian:cacert.org_root.pem
Removing debian:Equifax_Secure_eBusiness_CA_2.pem
Removing debian:TC_TrustCenter_Universal_CA_III.pem

我决定不再信任某些 CA,并想删除它们的证书。我该怎么做?

答案1

跑步

sudo dpkg-reconfigure ca-certificates

这将为您提供一个可以取消选择 CA 的列表。

CA 列表存储在文件中/etc/ca-certificates.conf。如果您手动编辑此文件,则需要运行

sudo update-ca-certificates

更新实际的证书/etc/ssl/certs/(如果您使用dpkg-reconfigure,则会自动完成)。

请参阅/usr/share/doc/ca-certificates/README.Debian以了解更多信息。

相关内容