Author: Michael Shuler
Revision Date: 2015-04-26 10:37:48 UTC

* debian/postinst:
  Set mode and group of /usr/local/share/ca-certificates based on current
  /usr/local permissions and ownership. Closes: #611501
* sbin/update-ca-certificates:
  Allow customisation of the paths used by update-ca-certificates.
  Add an option to set the certs in a directory to the defaults.
  Thanks for the patches, Paul Wise. Closes: #774059, #774201
  Fix shellcheck warnings and a little indentation.
* sbin/update-ca-certificates.8:
  Correct concatenated file name in man page from certificates.crt to
  ca-certificates.crt. Closes: #782230
* mozilla/{certdata.txt,nssckbi.h}:
  Update Mozilla certificate authority bundle to version 2.4.
  The following certificate authorities were added (+):
  + "COMODO RSA Certification Authority"
  + "Entrust Root Certification Authority - EC1"
  + "Entrust Root Certification Authority - G2"
  + "GlobalSign ECC Root CA - R4"
  + "GlobalSign ECC Root CA - R5"
  + "IdenTrust Commercial Root CA 1"
  + "IdenTrust Public Sector Root CA 1"
  + "S-TRUST Universal Root CA"
  + "Staat der Nederlanden EV Root CA"
  + "Staat der Nederlanden Root CA - G3"
  + "USERTrust ECC Certification Authority"
  + "USERTrust RSA Certification Authority" Closes: #762709
  The following certificate authorities were removed (-):
  - "America Online Root Certification Authority 1"
  - "America Online Root Certification Authority 2"
  - "E-Guven Kok Elektronik Sertifika Hizmet Saglayicisi"
  - "GTE CyberTrust Global Root"
  - "Thawte Premium Server CA"
  - "Thawte Server CA"

