#download https://www.cyber.mil/pki-pke/tools-configuration-files/ # verify openssl x509 -in dod_pke_chain.pem -subject -issuer -fingerprint -noout # verify openssl crl2pkcs7 -nocrl -certfile dod_pke_chain.pem | openssl pkcs7 -print_certs -noout # verify doas apt install dos2unix openssl smime -verify -in certificates_pkcs7_v5_12_eca.sha256 -inform DER -CAfile dod_pke_chain.pem | dos2unix | sha256sum -c #convert p7b to pem openssl pkcs7 -in certificates_pkcs7_v5_12_eca_der.p7b -inform der -print_certs -out eca_CAs.pem #convert pem to crt openssl x509 -in eca_CAs.pem -out eca_CAs.crt ? doas cp eca_CAs.crt /usr/local/share/ca-certificates/ # download update-certs.sh https://github.com/millermatt/osca/blob/main/update-certs.sh doas sh update-certs.sh eca_CAs.crt