Proposal on interim TLS roots behavior
3 unresolved threads
I could be swayed to go either way here, but if we want to minimize the amount of work needed right now I still think it is the right thing to move this proposal forward as typed up here.
Turns out old systems actually doesn't use the named file that is in stboot main now. It was changed from
/etc/https_roots.pem
to/etc/ssl/certs/isrgrootx1.pem
on Fri Jan 27 10:53:11 2023 +0100.Maybe we should just go ahead with the refactor we wanted all along and in our release notes say that stboot build scripts need to change the location of their file with trusted HTTPS roots. It is not a that big ask as long as we make it clear.