Re: Enhancements to mk-ca-bundle

From: Patrick Watson <>
Date: Mon, 17 Mar 2014 23:31:30 -0400

I finally got around to cleaning up the outstanding suggestions from
this chain. The new patch now:
1. uses a different switch for the criteria for including
certificates: -p <list of trust purposes>:<list of trust levels>
2. adds the -s <list of algorithms> switch that allows the user to
select which signature/hash/fingerprint algorithms to use when
outputting in plain text mode.
3. outputs human readable certificate purposes and trust levels only
when in plain text mode
4. Includes updates to the man file documentation as well. I'm not
sure what process is used to push updates to the cURL site, but I did
verify that the man file can be transformed into intelligible HTML via
Daniel Stenberg's roffit script.
5. I double checked and can confirm that when run with default
options, the script outputs identically to before these changes. When
run in plain text mode, but otherwise default options, the only
difference is that the trust information from #2 is added.

Please let me know if I can do anything else to help,

