Bug 28602 - Running cert-sync multiple times reports "1 new certificate added to trust store" each time
Summary: Running cert-sync multiple times reports "1 new certificate added to trust st...
Status: RESOLVED DUPLICATE of bug 30902
Alias: None
Product: Tools
Classification: Mono
Component: other ()
Version: unspecified
Hardware: Other Linux
: --- normal
Target Milestone: ---
Assignee: Bugzilla
Depends on:
Reported: 2015-03-31 14:53 UTC by Alexander Köplinger
Modified: 2016-02-12 13:48 UTC (History)
4 users (show)

Is this bug a regression?: ---
Last known good build:

Notice (2018-05-24): bugzilla.xamarin.com is now in read-only mode.

Please join us on Visual Studio Developer Community and in the Xamarin and Mono organizations on GitHub to continue tracking issues. Bugzilla will remain available for reference in read-only mode. We will continue to work on open Bugzilla bugs, copy them to the new locations as needed for follow-up, and add the new items under Related Links.

Our sincere thanks to everyone who has contributed on this bug tracker over the years. Thanks also for your understanding as we make these adjustments and improvements for the future.

Please create a new report on GitHub or Developer Community with your current version information, steps to reproduce, and relevant error messages or log files if you are hitting an issue that looks similar to this resolved bug and you do not yet see a matching new report.

Related Links:

Description Alexander Köplinger 2015-03-31 14:53:25 UTC
Every time I run cert-sync on my Ubuntu 14.04 box with Mono 3.12.1, it reports that it imported a certain certificate to the trust store. That sounds wrong, since the certificate should be there after the first invocation.


>$ sudo cert-sync /etc/ssl/certs/ca-certificates.crt
>Linux Cert Store Sync - version
>Synchronize local certs with certs from local Linux trust store.
>Copyright 2002, 2003 Motus Technologies. Copyright 2004-2008 Novell. BSD licensed.
>I already trust 172, your new list has 173
>Certificate added: C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
>1 new root certificates were added to your trust store.
>Import process completed.

Note that it is always the StartCom certificate that is reported as newly imported.
Comment 1 Jo Shields 2015-04-14 03:27:48 UTC
This is a unique key issue of some kind.

StartCom_Certification_Authority_2.pem and StartCom_Certification_Authority.pem are almost identical - same hash, same subject, same issue/expiry dates. The fingerprints differ.

According to the ca-certificates changelog, the latter is a reissue/rehash added to distro cert stores in 2012.

Whichever certificate property we're using as the key for building our cert list, it isn't unique enough for real-world use.
Comment 2 Alexander Köplinger [MSFT] 2016-02-12 13:48:43 UTC

*** This bug has been marked as a duplicate of bug 30902 ***