Make WordPress Core

Opened 5 months ago

Closed 2 weeks ago

#64969 closed task (blessed) (fixed)

Update bundled root certificates for 7.1

Reported by: desrosj Owned by:
Priority: normal Milestone: 7.1
Component: Security Version:
Severity: normal Keywords: fixed-major
Cc: Focuses:

Description

This ticket is for updating the Root Certificates bundle included in WordPress Core for the 7.1 release cycle.

Previously:

Note: Some unexpired legacy 1024-bit certificates that were previously included manually for backwards compatibility (see [35919]) are no longer bundled as of the 7.0 cycle (see [61669]).

Change History (5)

#1 @desrosj
3 months ago

In 62393:

Security: Update composer/ca-bundle to version 1.5.12.

This removes 24 certificates from the bundle.

See #64969.

#2 @desrosj
3 months ago

  • Keywords fixed-major added

#3 @adrianduffell
2 weeks ago

@desrosj is this ready to close or is there still work to be done for the release?

#4 @desrosj
2 weeks ago

In 62929:

Security: Update composer/ca-bundle to version 1.5.13.

This removes 2 certificates.

See #64969.

#5 @desrosj
2 weeks ago

  • Resolutionfixed
  • Status newclosed

Just applied the update from earlier this month. The changes attached to this ticket should likely be backported to every version eligible to receive security updates, but that is out of scope of this ticket and the 7.1 release cycle. This can be closed out.

Note: See TracTickets for help on using tickets.