============================================================================== LHC Computing Grid Trust Anchor release 1.145-1 2026.08.31 ============================================================================== This is the wLCG Trust Anchor release, based on the updated IGTF Accredited CA distribution version 1.145-1 with Classic, SLCS and MICS profiles, encoded in meta-package "ca-policy-egi-core-1.145-1" (new installs) and "lcg-CA-1.145-1" (for sites also part of wLCG and/or upgrading from EGEE/JSPG releases). The following notices are republished from the IGTF, inasfar as pertinent to this release. Details are found in the newsletter https://www.eugridpma.org/ Changes from 1.144 to 1.145 --------------------------- (release 31 August 2026) * removed deprecated emSignClass1CAG1 (emSign Class 1 CA - G1) (IN) * removed support for dual-hash (SSLeay, OpenSSL 0.x) trust anchor lookup (note when using fetch-crl(8) dual-hash CRLs will continue to be generated by default. Configure "opensslmode = single" to not create legacy-named CRL files. Continuing to create dual-hash CRLs has no security impact) Your may install BOTH "egi-core" AND "lcg" meta-packages, according to your policies. Note that your organisation or NGI may have a specific policy and may have added or removed CAs compared to the EGI core policy. The CA modifications encoded in both "requires" and "obsoletes" clauses (RPM) and Conflicts/Replaced clauses (Debian) have been incorporated in the above- mentioned meta-packages. This release is best enjoyed with fetch-crl v3 or better, available from GNU/Linux OS add-on repositories Fedora, EPEL, Debian, and from the IGTF at https://www.igtf.net/fetch-crl Version information: ca-policy-lcg = 1.145-1