diff --git a/README.md b/README.md index 2ce472574568063a1f63b5cfcaf2eb35cbdadcac..234d77f122b1956dffc8dbf97a67d3c62a97ae46 100644 --- a/README.md +++ b/README.md @@ -3,12 +3,15 @@ Anti China Certifications. ### 版本 -Last updated on **2014-09-07** +Last updated on **2014-09-08** ### 使用方法 * Windows(System) - * Base 版本**以管ç†å‘˜èº«ä»½è¿è¡Œ** AntiChinaCerts(Base).bat - * Extended 版本**以管ç†å‘˜èº«ä»½è¿è¡Œ** AntiChinaCerts(Extended).bat + * Base 版本 **以管ç†å‘˜èº«ä»½è¿è¡Œ** AntiChinaCerts_Base.bat + * Extended 版本 **以管ç†å‘˜èº«ä»½è¿è¡Œ** AntiChinaCerts_Extended.bat +* Windows(Firefox) + * `工具` - `选项` - `高级` - `è¯ä¹¦` - `查看è¯ä¹¦` + * 点击需è¦ç¦ç”¨çš„è¯ä¹¦ï¼Œç›´æŽ¥ç‚¹å‡» `åˆ é™¤æˆ–ä¸ä¿¡ä»»` 按钮å³å¯ * Android * `设置` - `安全` - `å—信任的å‡æ®(显示å—信任的CAè¯ä¹¦)` * 点击需è¦ç¦ç”¨çš„è¯ä¹¦å¹¶ä¸‹æ‹‰åˆ°æœ€ä¸‹é¢ï¼Œç‚¹å‡» `ç¦ç”¨` å³å¯ @@ -18,22 +21,33 @@ Last updated on **2014-09-07** * 本工具作用是先将列表ä¸çš„CAæ ¹è¯ä¹¦åˆ 掉,然åŽå†å°†è¿™äº›è¯ä¹¦æ·»åŠ 到CRLè¯ä¹¦åŠé”€åˆ—表ä¸ï¼ŒCRLè¯ä¹¦åŠé”€åˆ—表ä¸çš„è¯ä¹¦æ‰ä¼šè¢«å½»åº•ç¦ç”¨ * Extended 版本为 Base ç‰ˆæœ¬æ‰©å±•ï¼Œæ·»åŠ å¦å¤–å‡ ä¸ªCAæ ¹è¯ä¹¦ * 使用å‰å¯ä½¿ç”¨ Microsoft_Fixit_20135.diagcab(Win7以åŠä¹‹åŽ) 或者 Microsoft_Fixit_51014.msi(Vista以åŠä¹‹å‰) é‡ç½®è¯ä¹¦åˆ—表,**ä¸è¿‡å¤§å¤šæ•°æƒ…况下并ä¸éœ€è¦** - * ä½¿ç”¨å‰ **强烈建议以管ç†å‘˜èº«ä»½è¿è¡Œè‡ªå¸¦çš„RootSUPD** 更新系统的è¯ä¹¦åˆ—表 + * ä½¿ç”¨å‰ **强烈建议以管ç†å‘˜èº«ä»½è¿è¡Œè‡ªå¸¦çš„ RootSUPD** 更新系统的è¯ä¹¦åˆ—表 +* Windows(Firefox) + * 最新 32 版本自带有 CNNIC ROOT ä»¥åŠ China Internet Network Information Center EV Certificates Root * Android * 最新 4.4.4 系统自带有 CNNIC ROOT ä»¥åŠ China Internet Network Information Center EV Certificates Root - * 其它并ä¸éšç³»ç»Ÿé™„带 ### æ³¨æ„ * Windows(System) - * **å°†CAæ ¹è¯ä¹¦ç›´æŽ¥åˆ 掉是没有任何作用的,下次访问使用该è¯ä¹¦çš„网站时系统åˆä¼šé‡æ–°è‡ªåŠ¨è”ç½‘æ·»åŠ ï¼** - * **å› ä¸ºæ¯ä¸ªç”¨æˆ·ä½¿ç”¨çš„è¯ä¹¦åˆ—表都是独立的,所以需è¦æ‰€æœ‰ç”¨æˆ·éƒ½è¿è¡Œä¸€æ¬¡æ‰èƒ½å½»åº•ç¦ç”¨è¿™äº›è¯ä¹¦ï¼** - * è¿è¡Œæ—¶å¦‚æžœé‡åˆ° `Error: Can not find a certificate matching the hash value` ä¸éœ€è¦åœ¨æ„,åªè¦åŽé¢ `CertMgr Succeeded` è¿è¡ŒæˆåŠŸå°±è¡Œï¼Œå¦‚æžœæ示错误请检查是å¦æ˜¯ä»¥ç®¡ç†å‘˜æƒé™è¿è¡Œã€‚或者è”系作者 + * **å°†CAæ ¹è¯ä¹¦ç›´æŽ¥åˆ 除没有任何作用,下次访问使用该è¯ä¹¦çš„网站时系统åˆä¼šé‡æ–°è‡ªåŠ¨è”ç½‘æ·»åŠ ** + * **由于æ¯ä¸ªç”¨æˆ·ä½¿ç”¨ç‹¬ç«‹çš„è¯ä¹¦åˆ—表,所以需è¦æ‰€æœ‰ç”¨æˆ·éƒ½è¿è¡Œä¸€æ¬¡æœ¬å·¥å…·æ‰èƒ½å½»åº•ç¦ç”¨** + * è¿è¡Œæ—¶å¦‚æžœé‡åˆ° `Error: Can not find a certificate matching the hash value` ä¸éœ€è¦åœ¨æ„,åªè¦åŽé¢ `CertMgr Succeeded` è¿è¡ŒæˆåŠŸå°±è¡Œï¼Œå¦‚æžœæ示错误请检查是å¦æ˜¯ä»¥ç®¡ç†å‘˜æƒé™è¿è¡Œæˆ–è”系作者寻求帮助 + * è¿è¡Œå®Œæ¯•å»ºè®®æ¸…空所有æµè§ˆå™¨æ•°æ®ä»¥åŠç³»ç»ŸSSLç¼“å˜ +* Windows(Firefox) + * 在 Firefox é‡Œå¯¹è‡ªå¸¦æ ¹è¯ä¹¦æ‰§è¡Œ `åˆ é™¤æˆ–ä¸ä¿¡ä»»` æ“作就相当于是ç¦ç”¨å…¶æ‰€æœ‰ç›®çš„,并ä¸ä¼šå°†æ ¹è¯ä¹¦æœ¬èº«åˆ 除 * Android * Android 上由于没有æ供比较方便的方法编辑CRL列表,所以è¯ä¹¦å¹¶ä¸èƒ½è¢«å®Œå…¨ç¦ç”¨ï¼ŒAppså¯ä»¥é€šè¿‡å¿½ç•¥è¯ä¹¦é”™è¯¯ç»§ç»ä½¿ç”¨ * Android 系统没有自带的CAæ ¹è¯ä¹¦é»˜è®¤ä¸ºä¸ä¿¡ä»»çŠ¶æ€ï¼Œæ‰€ä»¥ä¸éœ€è¦æ‰‹åŠ¨æ·»åŠ åˆ°ç³»ç»Ÿä¸ + * æ“作完毕建议清空所有æµè§ˆå™¨æ•°æ®å’Œç³»ç»Ÿç¼“å˜ï¼Œå¹¶é‡å¯ç½‘络连接 ### 涉åŠçš„CAæ ¹è¯ä¹¦ * Base 版本 + * Fake GitHub.Com(2013-01-25) + * SHA-1 指纹 ‎27A29C3A8B3261770E8B59448557DC9E9339E68C + * æ¤ä¼ªé€ è¯ä¹¦è¢«ç”¨äºŽ 2013-01-25 大规模ä¸é—´äººæ”»å‡» GitHub 网站 + * Fake Google.Com(2014-07-24) + * SHA-1 指纹 ‎F6BEADB9BC02E0A152D71C318739CDECFC1C085D + * æ¤ä¼ªé€ è¯ä¹¦è¢«ç”¨äºŽ 2014-09-01 大规模ä¸é—´äººæ”»å‡» Google 网站 * CNNIC ROOT * SHA-1 指纹 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F * 所属机构为 [China Internet Network Information Center/CNNIC/ä¸å›½äº’è”网络信æ¯ä¸å¿ƒ](http://www.cnnic.net.cn) @@ -42,9 +56,9 @@ Last updated on **2014-09-07** * SHA-1 指纹 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E * 所属机构为 [China Internet Network Information Center/CNNIC/ä¸å›½äº’è”网络信æ¯ä¸å¿ƒ](http://www.cnnic.net.cn) * [测试网å€](https://evdemo.cnnic.cn) -* Extended 版本 +* Extended 版本扩展 * ROOTCA - * SHA-1 指纹 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E + * SHA-1 指纹 ‎DBB84423C928ABE889D0E368FC3191D151DDB1AB * 所属机构为 [Office of the State Commercial Cryptography Administration/OSCCA/国家商用密ç 管ç†åŠžå…¬å®¤](http://www.oscca.gov.cn) * 测试:打开 Certs ç›®å½•ä¸ CFCA_CS_SM2_OCA11 è¯ä¹¦ï¼Œè¯¥è¯ä¹¦ç”± ROOTCA 交å‰ç¾ç½²è®¤è¯ * CFCA GT CA @@ -65,7 +79,7 @@ Last updated on **2014-09-07** * UCA EV Root * SHA-1 指纹 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E * 所属机构为 [Shanghai Electronic Certificate Authority Center/SHECA/上海市数å—è¯ä¹¦è®¤è¯ä¸å¿ƒ](http://www.sheca.com) -* 观察ä¸çš„CAæ ¹è¯ä¹¦ï¼ˆ**这些è¯ä¹¦æ²¡æœ‰è¢«å·¥å…·ç¦ç”¨**) +* 观察ä¸ï¼ˆ**å¹¶æ— è¢«æœ¬å·¥å…·ç¦ç”¨**) * SRCA * 本è¯ä¹¦ç”±å…¶è‡ªè¡Œé¢å‘,没有ç»è¿‡ä»»ä½•ç¬¦åˆå›½é™…æ ‡å‡†çš„å›½é™…äº‹åŠ¡æ‰€è¿›è¡Œå®¡è®¡ * SHA-1 指纹 ‎AE3F2E66D48FC6BD1DF131E89D768D505DF14302 diff --git a/Windows/System/AntiChinaCerts(Base).bat b/Windows/System/AntiChinaCerts(Base).bat deleted file mode 100644 index 473a11d2fe8ddeabbd3e33deeba1a852ffb3d2e9..0000000000000000000000000000000000000000 --- a/Windows/System/AntiChinaCerts(Base).bat +++ /dev/null @@ -1,34 +0,0 @@ -:: AntiChinaCerts Base batch -:: Anti China Certifications. -:: -:: Author: Chengr28 -:: - -@echo off - -:: Permission check -if "%PROCESSOR_ARCHITECTURE%" == "AMD64" (set SystemPath = %SystemRoot%\SysWOW64) else (set SystemPath = %SystemRoot%\system32) -rd "%SystemPath%\test_permissions" > nul 2 > nul -md "%SystemPath%\test_permissions" 2 > nul || (echo Require Administrator Permission. && pause > nul && Exit) -rd "%SystemPath%\test_permissions" > nul 2 > nul -cls - -:: Delete certifications(Base) -cd /d %~dp0/Certs -:: CNNIC ROOT -certmgr /del /c /sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F /s Root -:: China Internet Network Information Center EV Certificates Root -certmgr /del /c /sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E /s Root - -@echo. - -:: Add certifications to CRL. -:: Base -certmgr /add /c CNNIC_ROOT.cer /s Disallowed -certmgr /add /c China_Internet_Network_Information_Center_EV_Certificates_Root.cer /s Disallowed - -:: Print to screen. -@echo. -@echo Done. Please confirm the messages on screen. -@echo. -@pause diff --git a/Windows/System/AntiChinaCerts(Extended).bat b/Windows/System/AntiChinaCerts(Extended).bat deleted file mode 100644 index 88ebc88e30ed8470050a522108a64195c70c59db..0000000000000000000000000000000000000000 --- a/Windows/System/AntiChinaCerts(Extended).bat +++ /dev/null @@ -1,54 +0,0 @@ -:: AntiChinaCerts Extended batch -:: Anti China Certifications. -:: -:: Author: Chengr28 -:: - -@echo off - -:: Permission check -if "%PROCESSOR_ARCHITECTURE%" == "AMD64" (set SystemPath = %SystemRoot%\SysWOW64) else (set SystemPath = %SystemRoot%\system32) -rd "%SystemPath%\test_permissions" > nul 2 > nul -md "%SystemPath%\test_permissions" 2 > nul || (echo Require Administrator Permission. && pause > nul && Exit) -rd "%SystemPath%\test_permissions" > nul 2 > nul -cls - -:: Delete certifications(Base) -cd /d %~dp0/Certs -:: CNNIC ROOT -certmgr /del /c /sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F /s Root -:: China Internet Network Information Center EV Certificates Root -certmgr /del /c /sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E /s Root -:: Delete certs(Extended) -:: ROOTCA -certmgr /del /c /sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB /s Root -:: CFCA GT CA -certmgr /del /c /sha1 EABDA240440ABBD694930A01D09764C6C2D77966 /s Root -:: CFCA EV ROOT -certmgr /del /c /sha1 E2B8294B5584AB6B58C290466CAC3FB8398F8483 /s Root -:: UCA Global Root -certmgr /del /c /sha1 0B972C9EA6E7CC58D93B20BF71EC412E7209FABF /s Root -:: UCA Root -certmgr /del /c /sha1 8250BED5A214433A66377CBC10EF83F669DA3A67 /s Root -:: UCA EV Root -certmgr /del /c /sha1 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E /s Root - -@echo. - -:: Add certifications to CRL. -:: Base -certmgr /add /c CNNIC_ROOT.cer /s Disallowed -certmgr /add /c China_Internet_Network_Information_Center_EV_Certificates_Root.cer /s Disallowed -:: Extended -certmgr /add /c ROOTCA.cer /s Disallowed -certmgr /add /c CFCA_GT_CA.cer /s Disallowed -certmgr /add /c CFCA_EV_ROOT.cer /s Disallowed -certmgr /add /c UCA_Global_Root.cer /s Disallowed -certmgr /add /c UCA_Root.cer /s Disallowed -certmgr /add /c UCA_EV_Root.cer /s Disallowed - -:: Print to screen. -@echo. -@echo Done. Please confirm the messages on screen. -@echo. -@pause diff --git a/Windows/System/AntiChinaCerts_Base.bat b/Windows/System/AntiChinaCerts_Base.bat new file mode 100644 index 0000000000000000000000000000000000000000..8bdda02646182a2b8f1ef7502b03b1008ba32fa1 --- /dev/null +++ b/Windows/System/AntiChinaCerts_Base.bat @@ -0,0 +1,77 @@ +:: AntiChinaCerts Base batch +:: Anti China Certifications. +:: +:: Author: Chengr28 +:: + +@echo off + +:: Permission check +if "%PROCESSOR_ARCHITECTURE%" == "AMD64" (set SystemPath = %SystemRoot%\SysWOW64) else (set SystemPath = %SystemRoot%\system32) +::rd "%SystemPath%\Test_Permissions" > nul 2 > nul +::md "%SystemPath%\Test_Permissions" 2 > nul || (echo Require Administrator Permission. && pause > nul && Exit) +::rd "%SystemPath%\Test_Permissions" > nul 2 > nul +del /f /q %SystemPath%\TestPermission.log +echo "Permission check." >> %SystemPath%\TestPermission.log +if not exist %SystemPath%\TestPermission.log (echo Require Administrator Permission. && pause > nul && Exit) +del /f /q %SystemPath%\TestPermission.log + +cls +cd /d %~dp0\Certs + +:: Architecture check +if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" (goto X86) else goto X64 + +:X86 +:: Delete certifications(Base) +:: Fake GitHub.Com(2013-01-25) +CertMgr_x86 -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root +CertMgr_x86 -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot +:: Fake Google.Com(2014-07-24) +CertMgr_x86 -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine Root +CertMgr_x86 -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine AuthRoot +:: CNNIC ROOT +CertMgr_x86 -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine Root +CertMgr_x86 -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine AuthRoot +:: China Internet Network Information Center EV Certificates Root +CertMgr_x86 -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine Root +CertMgr_x86 -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine AuthRoot + +@echo. + +:: Add certifications to CRL(Base) +CertMgr_x86 -add -c FakeGitHubCom_2013_01.cer -s Disallowed +CertMgr_x86 -add -c FakeGoogleCom_2014_07.cer -s Disallowed +CertMgr_x86 -add -c CNNIC_ROOT.cer -s Disallowed +CertMgr_x86 -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.cer -s Disallowed +goto Exit + +:X64 +:: Delete certifications(Base) +:: Fake GitHub.Com(2013-01-25) +CertMgr -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root +CertMgr -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot +:: Fake Google.Com(2014-07-24) +CertMgr -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine Root +CertMgr -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine AuthRoot +:: CNNIC ROOT +CertMgr -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine Root +CertMgr -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine AuthRoot +:: China Internet Network Information Center EV Certificates Root +CertMgr -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine Root +CertMgr -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine AuthRoot + +@echo. + +:: Add certifications to CRL(Base) +CertMgr -add -c FakeGitHubCom_2013_01.cer -s Disallowed +CertMgr -add -c FakeGoogleCom_2014_07.cer -s Disallowed +CertMgr -add -c CNNIC_ROOT.cer -s Disallowed +CertMgr -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.cer -s Disallowed + +:Exit +:: Print to screen. +@echo. +@echo Done. Please confirm the messages on screen. +@echo. +@pause diff --git a/Windows/System/AntiChinaCerts_Extended.bat b/Windows/System/AntiChinaCerts_Extended.bat new file mode 100644 index 0000000000000000000000000000000000000000..35dc94071e9f099257424b21fec57da49ebc7ed4 --- /dev/null +++ b/Windows/System/AntiChinaCerts_Extended.bat @@ -0,0 +1,129 @@ +:: AntiChinaCerts Extended batch +:: Anti China Certifications. +:: +:: Author: Chengr28 +:: + +@echo off + +:: Permission check +if "%PROCESSOR_ARCHITECTURE%" == "AMD64" (set SystemPath = %SystemRoot%\SysWOW64) else (set SystemPath = %SystemRoot%\system32) +::rd "%SystemPath%\Test_Permissions" > nul 2 > nul +::md "%SystemPath%\Test_Permissions" 2 > nul || (echo Require Administrator Permission. && pause > nul && Exit) +::rd "%SystemPath%\Test_Permissions" > nul 2 > nul +del /f /q %SystemPath%\TestPermission.log +echo "Permission check." >> %SystemPath%\TestPermission.log +if not exist %SystemPath%\TestPermission.log (echo Require Administrator Permission. && pause > nul && Exit) +del /f /q %SystemPath%\TestPermission.log + +cls +cd /d %~dp0\Certs + +:: Architecture check +if "%PROCESSOR_ARCHITECTURE%%PROCESSOR_ARCHITEW6432%" == "x86" (goto X86) else goto X64 + +:X86 +:: Delete certifications(Base) +:: Fake GitHub.Com(2013-01-25) +CertMgr_x86 -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root +CertMgr_x86 -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot +:: Fake Google.Com(2014-07-24) +CertMgr_x86 -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine Root +CertMgr_x86 -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine AuthRoot +:: CNNIC ROOT +CertMgr_x86 -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine Root +CertMgr_x86 -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine AuthRoot +:: China Internet Network Information Center EV Certificates Root +CertMgr_x86 -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine Root +CertMgr_x86 -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine AuthRoot +:: Delete certifications(Extended) +:: ROOTCA +CertMgr_x86 -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine Root +CertMgr_x86 -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine AuthRoot +:: CFCA GT CA +CertMgr_x86 -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine Root +CertMgr_x86 -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine AuthRoot +:: CFCA EV ROOT +CertMgr_x86 -del -c -sha1 E2B8294B5584AB6B58C290466CAC3FB8398F8483 -s -r localMachine Root +CertMgr_x86 -del -c -sha1 E2B8294B5584AB6B58C290466CAC3FB8398F8483 -s -r localMachine AuthRoot +:: UCA Global Root +CertMgr_x86 -del -c -sha1 0B972C9EA6E7CC58D93B20BF71EC412E7209FABF -s -r localMachine Root +CertMgr_x86 -del -c -sha1 0B972C9EA6E7CC58D93B20BF71EC412E7209FABF -s -r localMachine AuthRoot +:: UCA Root +CertMgr_x86 -del -c -sha1 8250BED5A214433A66377CBC10EF83F669DA3A67 -s -r localMachine Root +CertMgr_x86 -del -c -sha1 8250BED5A214433A66377CBC10EF83F669DA3A67 -s -r localMachine AuthRoot +:: UCA EV Root +CertMgr_x86 -del -c -sha1 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E -s -r localMachine Root +CertMgr_x86 -del -c -sha1 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E -s -r localMachine AuthRoot + +@echo. + +:: Add certifications to CRL(Base) +CertMgr_x86 -add -c FakeGitHubCom_2013_01.cer -s Disallowed +CertMgr_x86 -add -c FakeGoogleCom_2014_07.cer -s Disallowed +CertMgr_x86 -add -c CNNIC_ROOT.cer -s Disallowed +CertMgr_x86 -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.cer -s Disallowed +:: Add certifications to CRL(Extended) +CertMgr_x86 -add -c ROOTCA.cer -s Disallowed +CertMgr_x86 -add -c CFCA_GT_CA.cer -s Disallowed +CertMgr_x86 -add -c CFCA_EV_ROOT.cer -s Disallowed +CertMgr_x86 -add -c UCA_Global_Root.cer -s Disallowed +CertMgr_x86 -add -c UCA_Root.cer -s Disallowed +CertMgr_x86 -add -c UCA_EV_Root.cer -s Disallowed +goto Exit + +:X64 +:: Delete certifications(Base) +:: Fake GitHub.Com(2013-01-25) +CertMgr -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine Root +CertMgr -del -c -sha1 27A29C3A8B3261770E8B59448557DC9E9339E68C -s -r localMachine AuthRoot +:: Fake Google.Com(2014-07-24) +CertMgr -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine Root +CertMgr -del -c -sha1 F6BEADB9BC02E0A152D71C318739CDECFC1C085D -s -r localMachine AuthRoot +:: CNNIC ROOT +CertMgr -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine Root +CertMgr -del -c -sha1 8BAF4C9B1DF02A92F7DA128EB91BACF498604B6F -s -r localMachine AuthRoot +:: China Internet Network Information Center EV Certificates Root +CertMgr -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine Root +CertMgr -del -c -sha1 4F99AA93FB2BD13726A1994ACE7FF005F2935D1E -s -r localMachine AuthRoot +:: Delete certifications(Extended) +:: ROOTCA +CertMgr -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine Root +CertMgr -del -c -sha1 DBB84423C928ABE889D0E368FC3191D151DDB1AB -s -r localMachine AuthRoot +:: CFCA GT CA +CertMgr -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine Root +CertMgr -del -c -sha1 EABDA240440ABBD694930A01D09764C6C2D77966 -s -r localMachine AuthRoot +:: CFCA EV ROOT +CertMgr -del -c -sha1 E2B8294B5584AB6B58C290466CAC3FB8398F8483 -s -r localMachine Root +CertMgr -del -c -sha1 E2B8294B5584AB6B58C290466CAC3FB8398F8483 -s -r localMachine AuthRoot +:: UCA Global Root +CertMgr -del -c -sha1 0B972C9EA6E7CC58D93B20BF71EC412E7209FABF -s -r localMachine Root +CertMgr -del -c -sha1 0B972C9EA6E7CC58D93B20BF71EC412E7209FABF -s -r localMachine AuthRoot +:: UCA Root +CertMgr -del -c -sha1 8250BED5A214433A66377CBC10EF83F669DA3A67 -s -r localMachine Root +CertMgr -del -c -sha1 8250BED5A214433A66377CBC10EF83F669DA3A67 -s -r localMachine AuthRoot +:: UCA EV Root +CertMgr -del -c -sha1 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E -s -r localMachine Root +CertMgr -del -c -sha1 B9C9F58B3BBEF575E2B58328770E7B0076C40B5E -s -r localMachine AuthRoot + +@echo. + +:: Add certifications to CRL(Base) +CertMgr -add -c FakeGitHubCom_2013_01.cer -s Disallowed +CertMgr -add -c FakeGoogleCom_2014_07.cer -s Disallowed +CertMgr -add -c CNNIC_ROOT.cer -s Disallowed +CertMgr -add -c China_Internet_Network_Information_Center_EV_Certificates_Root.cer -s Disallowed +:: Add certifications to CRL(Extended) +CertMgr -add -c ROOTCA.cer -s Disallowed +CertMgr -add -c CFCA_GT_CA.cer -s Disallowed +CertMgr -add -c CFCA_EV_ROOT.cer -s Disallowed +CertMgr -add -c UCA_Global_Root.cer -s Disallowed +CertMgr -add -c UCA_Root.cer -s Disallowed +CertMgr -add -c UCA_EV_Root.cer -s Disallowed + +:Exit +:: Print to screen. +@echo. +@echo Done. Please confirm the messages on screen. +@echo. +@pause diff --git a/Windows/System/Certs/CertMgr.exe b/Windows/System/Certs/CertMgr.exe index 911654e3c151ec341b4a2fed5959a3570109a1dc..0c19be670c7cb3f134cb837c8e03406894e2ee2e 100644 Binary files a/Windows/System/Certs/CertMgr.exe and b/Windows/System/Certs/CertMgr.exe differ diff --git a/Windows/System/Certs/CertMgr_x86.exe b/Windows/System/Certs/CertMgr_x86.exe new file mode 100644 index 0000000000000000000000000000000000000000..911654e3c151ec341b4a2fed5959a3570109a1dc Binary files /dev/null and b/Windows/System/Certs/CertMgr_x86.exe differ diff --git a/Windows/System/Certs/Certification_Authority_Of_WoSign.cer b/Windows/System/Certs/Certification_Authority_Of_WoSign.cer new file mode 100644 index 0000000000000000000000000000000000000000..1a1e3e613f8dce68bf04a66fcfe38cb362cc924e Binary files /dev/null and b/Windows/System/Certs/Certification_Authority_Of_WoSign.cer differ diff --git a/Windows/System/Certs/Certification_Authority_Of_WoSign.crt b/Windows/System/Certs/Certification_Authority_Of_WoSign.crt deleted file mode 100644 index e3abaaa758ccdebac27a00285acbd4ca5ec08bf2..0000000000000000000000000000000000000000 --- a/Windows/System/Certs/Certification_Authority_Of_WoSign.crt +++ /dev/null @@ -1,32 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFdjCCA16gAwIBAgIQXmjWEXGUY1BWAGjzPsnFkTANBgkqhkiG9w0BAQUFADBV -MQswCQYDVQQGEwJDTjEaMBgGA1UEChMRV29TaWduIENBIExpbWl0ZWQxKjAoBgNV -BAMTIUNlcnRpZmljYXRpb24gQXV0aG9yaXR5IG9mIFdvU2lnbjAeFw0wOTA4MDgw -MTAwMDFaFw0zOTA4MDgwMTAwMDFaMFUxCzAJBgNVBAYTAkNOMRowGAYDVQQKExFX -b1NpZ24gQ0EgTGltaXRlZDEqMCgGA1UEAxMhQ2VydGlmaWNhdGlvbiBBdXRob3Jp -dHkgb2YgV29TaWduMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvcqN -rLiRFVaXe2tcesLea9mhsMMQI/qnobLMMfo+2aYpbxY94Gv4uEBf2zmoAHqLoE1U -fcIiePyOCbiohdfMlZdLdNiefvAA5A6JrkkoRBoQmTIPJYhTpA2zDxIIFgsDcScc -f+Hb0v1naMQFXQoOXXDX2JegvFNBmpGN9J42Znp+VsGQX+axaCA2pIwkLCxHC1l2 -ZjC1vt7tj/id07sBMOby8w7gLJKA84X5KIq0VC6a7fd2/BVoFutKbOsuEo/Uz/4M -x1wdC34FMr5esAkqQtXJTpCzWQ27en7N1QhatH/YHGkR+ScPewavVIMYe+HdVHpR -aG53/Ma/UkpmRqGyZxq7o093oL5d//xWC0Nyd5DKnvnyOfUNqfTq1+ezEC8wQjch -zDBwyYaYD8xYTYO7feUapTeNtqwylwA6Y3EkHp43xP901DfA4v6IRmAR3Qg/UDar -uHqklWJqbrDKaiFaafPz+x1wOZXzp26mgYmhiMU7ccqjUu6Du/2gd/Tkb+dC221K -mYo0SLwX3OSACCK28jHAPwQ+658geda4BmRkAjHXqc1S+4RFaQkAKtxVi8QGRkvA -Sh0JWzko/amrzgD5LkhLJuYwTKVYyrREgk/nkR4zw7CT/xH8gdLKH3Ep3XZPkiWv -HYG3Dy+MwwbMLyejSuQOmbp8HkUff6oZRZb9/D0CAwEAAaNCMEAwDgYDVR0PAQH/ -BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFOFmzw7R8bNLtwYgFP6H -EtX2/vs+MA0GCSqGSIb3DQEBBQUAA4ICAQCoy3JAsnbBfnv8rWTjMnvMPLZdRtP1 -LOJwXcgu2AZ9mNELIaCJWSQBnfmvCX0KI4I01fx8cpm5o9dU9OpScA7F9dY74ToJ -MuYhOZO9sxXqT2r09Ys/L3yNWC7F4TmgPsc9SnOeQHrAK2GpZ8nzJLmzbVUsWh2e -JXLOC62qx1ViC777Y7NhRCOjy+EaDveaBk3e1CNOIZZbOVtXHS9dCF4Jef98l7VN -g64N1uajeeAz0JmWAjCnPv/So0M/BVoG6kQC2nz4SNAzqfkHx5Xh9T71XXG68pWp -dIhhWeO/yloTunK0jF02h+mmxTwTv97QRCbut+wucPrXnbes5cVAWubXbHssw1ab -R80LzvobtCHXt2a49CUwi1wNuepnsvRtrtWhnk/Yn+knArAdBtaP4/tIEp9/EaEQ -PkxROpaw0RPxx9gmrjrKkcRpnd8BKWRRb2jaFOwIQZeQjdCygPLPwj2/kWjFgGce -xGATVdVhmVd8upUPYUk6ynW8yQqTP2cOEvIo4jEbwFcW3wh8GcF+Dx+FHgo2fFt+ -J7x6v+Db9NpSvd4MVHAxkUOVyLzwPt0JfjBkUO1/AaQzZ01oT74V77D2AhGiGxMl -OtzCWfHjXEa7ZywCRuoeSKbmW9m1vFGikpbbqsY3Iqb+zCB0oy2pLmvLwIIRIbWT -ee5Ehr7XHuQe+w== ------END CERTIFICATE----- diff --git a/Windows/System/Certs/FakeGitHubCom_2013_01.cer b/Windows/System/Certs/FakeGitHubCom_2013_01.cer new file mode 100644 index 0000000000000000000000000000000000000000..dec381fb9a6f0cdc52ca4fcfa81755c2577371cd Binary files /dev/null and b/Windows/System/Certs/FakeGitHubCom_2013_01.cer differ diff --git a/Windows/System/Certs/FakeGoogleCom_2014_07.cer b/Windows/System/Certs/FakeGoogleCom_2014_07.cer new file mode 100644 index 0000000000000000000000000000000000000000..6ed201f3147a4f259e435c28382b11980787643f Binary files /dev/null and b/Windows/System/Certs/FakeGoogleCom_2014_07.cer differ