SSL / TLS connection getting established successfully even when CA certificate has been removed from trust store.
Issue
- SSL / TLS connection getting established successfully even when CA certificate has been removed.
- CA certificate removal is failing with following error.
# trust anchor --remove pkcs11:id=%15%F5%08%56%E0%6C%64%23%D0%56%70%91%87%8A%2B%2C%C6%5C%DD%34;type=cert
p11-kit: couldn't remove read-only certificate
p11-kit: couldn't remove read-only nss-trust
p11-kit: 2 errors while processing
Environment
- Red Hat Enterprise Linux 8
- ca-certificates
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.