Your message dated Sun, 16 Aug 2026 23:12:50 +0200
with message-id <[email protected]>
and subject line Re: Bug#1139720: ca-certificates: Include Root CA from Let's
Encrypt
has caused the Debian Bug report #1139720,
regarding ca-certificates: Include Root CA from Let's Encrypt
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139720: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139720
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: ca-certificates
Version: 20250419
Severity: important
Dear Maintainer,
Because Let's Encrypt has been signed the new certificate with the gen-y
root certificate, would you please include the new Root CA from Let's
Encrypt? At the moment, we got problem with Thunderbird, etc. because the
certificate isn't trusted.
https://letsencrypt.org/certs/gen-y/root-ye.pem
https://letsencrypt.org/certs/gen-y/root-yr.pem
Thank you and regards,
Daniel Sugondo.
-- System Information:
Debian Release: 13.5
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 6.12.90+deb13.1-amd64 (SMP w/40 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE,
TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages ca-certificates depends on:
ii debconf [debconf-2.0] 1.5.91
ii openssl 3.5.6-1~deb13u2
ca-certificates recommends no packages.
ca-certificates suggests no packages.
-- debconf information excluded
-- debsums errors found:
debsums: missing file
/usr/share/ca-certificates/mozilla/Baltimore_CyberTrust_Root.crt (from
ca-certificates package)
--- End Message ---
--- Begin Message ---
Hi,
New CAs are included as they are trusted by the Mozilla root program.
As far as I know that has not happened yet for those roots. And it's
also unnecessary, since they're cross-signed by the existing X1 and X2
roots, so whatever problem you have has a different cause.
Cheers,
Julien
On Thu, Jun 11, 2026 at 22:58:03 +0200, Daniel Haryo Sugondo wrote:
> Package: ca-certificates
> Version: 20250419
> Severity: important
>
> Dear Maintainer,
>
> Because Let's Encrypt has been signed the new certificate with the gen-y
> root certificate, would you please include the new Root CA from Let's
> Encrypt? At the moment, we got problem with Thunderbird, etc. because the
> certificate isn't trusted.
>
> https://letsencrypt.org/certs/gen-y/root-ye.pem
> https://letsencrypt.org/certs/gen-y/root-yr.pem
>
> Thank you and regards,
>
> Daniel Sugondo.
>
> -- System Information:
> Debian Release: 13.5
> APT prefers stable-updates
> APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
> 'stable')
> Architecture: amd64 (x86_64)
>
> Kernel: Linux 6.12.90+deb13.1-amd64 (SMP w/40 CPU threads; PREEMPT)
> Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE,
> TAINT_UNSIGNED_MODULE
> Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
> LANGUAGE=en_US:en
> Shell: /bin/sh linked to /usr/bin/dash
> Init: systemd (via /run/systemd/system)
> LSM: AppArmor: enabled
>
> Versions of packages ca-certificates depends on:
> ii debconf [debconf-2.0] 1.5.91
> ii openssl 3.5.6-1~deb13u2
>
> ca-certificates recommends no packages.
>
> ca-certificates suggests no packages.
>
> -- debconf information excluded
>
> -- debsums errors found:
> debsums: missing file
> /usr/share/ca-certificates/mozilla/Baltimore_CyberTrust_Root.crt (from
> ca-certificates package)
>
--- End Message ---