You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
32 lines
1.4 KiB
32 lines
1.4 KiB
# Additional CA Certificates
|
|
|
|
This folder contains certificate authorities loaded by the Additional CA custom
|
|
integration at Home Assistant startup.
|
|
|
|
The live Additional CA custom component install is intentionally kept out of
|
|
source control. Maintain it through HACS/manual install in the Home Assistant
|
|
environment while this workaround is needed.
|
|
|
|
## Rheem EcoNet temporary workaround
|
|
|
|
`DigiCertGlobalRootCA.crt.pem` temporarily restores trust for the Rheem EcoNet
|
|
ClearBlade endpoint while `rheem.clearblade.com` still chains to the legacy
|
|
DigiCert Global Root CA (G1).
|
|
|
|
Local tracker: https://github.com/CCOSTAN/Home-AssistantConfig/issues/1820
|
|
|
|
Upstream references:
|
|
- https://github.com/home-assistant/core/issues/172228
|
|
- https://github.com/home-assistant/operating-system/issues/4775
|
|
- https://docs.clearblade.com/iotcore/digicert-g1-root-ca-distrust
|
|
- https://knowledge.digicert.com/alerts/digicert-root-strategy-aligning-with-industry-standards
|
|
|
|
Verification values for the installed PEM:
|
|
- PEM SHA256: `39FDCF28AEFFE08D03251FCCAF645E3C5DE19FA4EBBAFC89B4EDE2A422148BAB`
|
|
- Certificate DER fingerprint: `4348A0E9444C78CB265E058D5E8944B4D84F9662BD26DB257F8934A443C70161`
|
|
|
|
Remove this certificate, the `additional_ca` entry in `configuration.yaml`, and
|
|
the Additional CA custom component if it has no other use after the upstream
|
|
Rheem/ClearBlade certificate chain validates with the stock Home Assistant trust
|
|
store.
|