### this file is sourced not run
PKGVER=1.12
PKGBUILD=1
PKGARCH=noarch

# source: BLFS 11.3 + james
TARBALL=make-ca-$PKGVER.tar.xz
MD5SUM=67e0b911e73a859fc326171c5153d455
SRC_URL=https://github.com/lfs-book/make-ca/releases/download/v$PKGVER/$TARBALL
BUNDLE=

SLACKREQ=
SLACKDESC="make-ca: make-ca $PKGVER (LFS tools to make CA certs)
make-ca: 
make-ca: make-ca is a utility to deliver and manage a complete PKI
make-ca: configuration for workstations and servers using only standard Unix
make-ca: utilities and OpenSSL. It will optionally generate keystores for
make-ca: OpenJDK and NSS if already installed, using a Mozilla cacerts.txt or
make-ca: like formatted file.
make-ca: 
make-ca: https://github.com/lfs-book/make-ca
make-ca: 
make-ca: 
"

### standard pkg_download
### standard pkg_prepare
### standard pkg_prepare

### build
pkg_build() {
	cd /tmp/make-ca* &&
	install -dm755 /etc/ssl/local &&
		
	make && make install &&
	pkg_build_slackdesc
}

<< "EOF"

BLFS 11.3 Notes
==============

Configuring make-ca
---

For most users, no additional configuration is necessary, however, the
default certdata.txt file provided by make-ca is obtained from the
mozilla-release branch, and is modified to provide a Mercurial revision.
This will be the correct version for most systems.

There are several other variants of the file available for use that might
be preferred for one reason or another, including the files shipped with
Mozilla products in this book. RedHat and OpenSUSE, for instance, use the
version included in nss-3.88.1. Additional upstream downloads are available
at the links included in /etc/make-ca/make-ca.conf.dist. Simply copy the
file to /etc/make-ca.conf and edit as appropriate.

About Trust Arguments
---

There are three trust types that are recognized by the make-ca script,
SSL/TLS, S/Mime, and code signing. For OpenSSL, these are serverAuth,
emailProtection, and codeSigning respectively. If one of the three trust
arguments is omitted, the certificate is neither trusted, nor rejected
for that role. Clients that use OpenSSL or NSS encountering this certificate
will present a warning to the user. Clients using GnuTLS without p11-kit
support are not aware of trusted certificates. To include this CA into the
ca-bundle.crt, email-ca-bundle.crt, or objsign-ca-bundle.crt files (the GnuTLS l
egacy bundles), it must have the appropriate trust arguments.

Adding Additional CA Certificates
---

The /etc/ssl/local directory is available to add additional CA certificates
to the system trust store. This directory is also used to store certificates
that were added to or modified in the system trust store by p11-kit-0.24.1
so that trust values are maintained across upgrades. Files in this directory
must be in the OpenSSL trusted certificate format. Certificates imported
using the trust utility from p11-kit-0.24.1 will utilize the x509 Extended Key Usage
values to assign default trust values for the system anchors.

If you need to override trust values, or otherwise need to create an OpenSSL
trusted certificate manually from a regular PEM encoded file, you need to
add trust arguments to the openssl command, and create a new certificate.
For example, using the CAcert roots, if you want to trust both for all three
roles, the following commands will create appropriate OpenSSL trusted
certificates (run as the root user after Wget-1.21.3 is installed):

	wget http://www.cacert.org/certs/root.crt &&
	wget http://www.cacert.org/certs/class3.crt &&
	openssl x509 -in root.crt -text -fingerprint -setalias "CAcert Class 1 root" \
			-addtrust serverAuth -addtrust emailProtection -addtrust codeSigning \
			> /etc/ssl/local/CAcert_Class_1_root.pem &&
	openssl x509 -in class3.crt -text -fingerprint -setalias "CAcert Class 3 root" \
			-addtrust serverAuth -addtrust emailProtection -addtrust codeSigning \
			> /etc/ssl/local/CAcert_Class_3_root.pem &&
	/usr/sbin/make-ca -r

Overriding Mozilla Trust
---

Occasionally, there may be instances where you don't agree with Mozilla's
inclusion of a particular certificate authority. If you'd like to override
the default trust of a particular CA, simply create a copy of the existing
certificate in /etc/ssl/local with different trust arguments. For example,
if you'd like to distrust the "Makebelieve_CA_Root" file, run the following
commands:

	openssl x509 -in /etc/ssl/certs/Makebelieve_CA_Root.pem \
				 -text \
				 -fingerprint \
				 -setalias "Disabled Makebelieve CA Root" \
				 -addreject serverAuth \
				 -addreject emailProtection \
				 -addreject codeSigning \
		   > /etc/ssl/local/Disabled_Makebelieve_CA_Root.pem &&
	/usr/sbin/make-ca -r

Using make-ca with Python3
---

When Python3 was installed in LFS it included the pip3 module with vendored
certificates from the Certifi module. That was necessary, but it means that
whenever pip3 is used it can reference those certificates, primarily when
creating a virtual environment or when installing a module with all its
wheel dependencies in one go.

It is generally considered that the System Administrator should be in charge
of which certificates are available. Now that make-ca-1.12 and p11-kit-0.24.1
have been installed and make-ca has been configured, it is possible to make
pip3 use the system certificates.

The vendored certificates installed in LFS are a snapshot from when the
pulled-in version of Certifi was created. If you regularly update the system
certificates, the vendored version will become out of date.

To use the system certificates in Python3 you should set _PIP_STANDALONE_CERT
to point to them, e.g for the bash shell:

	export _PIP_STANDALONE_CERT=/etc/pki/tls/certs/ca-bundle.crt

Warning
---

If you have created virtual environments, for example when testing modules,
and those include the Requests and Certifi modules in ~/.local/lib/python3.11/
then those local modules will be used instead of the system certificates
unless you remove the local modules.

To use the system certificates in Python3 with the BLFS profiles add the
following variable to your system or personal profiles:

	mkdir -pv /etc/profile.d &&
	cat > /etc/profile.d/pythoncerts.sh << "EOF"
	# Begin /etc/profile.d/pythoncerts.sh

	export _PIP_STANDALONE_CERT=/etc/pki/tls/certs/ca-bundle.crt

	# End /etc/profile.d/pythoncerts.sh
	EOF


EOF
