Commit Graph

2 Commits

Author SHA1 Message Date
Martin Weinelt
92f67f68b3 python3Packages.certifi: Ignore /no-cert-file.crt in NIX_SSL_CERT_FILE 2022-12-11 11:24:02 +01:00
Martin Weinelt
8d7cc9cac9 python3Packages.certifi: use system ca-bundle
We update that one more reliably and it allows ties in with module based
configuration applied through `security.pki`.

Also allow overwriting the CA bundle used through `NIX_SSL_CERT_FILE`
as is common throughout nixpkgs.

Fixes: CVE-2022-23491
2022-12-08 16:14:23 +01:00