adding local CAs to the trusted SSL certificates for most of the system download capabilities, plugin-based PAM authentication rework for IPsec and the web proxy as well as third party fixes for hostapd / wpa_supplicant 2.8 and Suricata 4.1.4
The funny thing is ca-root-nss.crt is not for editing because it is the upstream root bundle, not the system root bundle. Case in point is the health audit:# pkg check -s ca_root_nssChecking ca_root_nss: 0%ca_root_nss-3.44.1: checksum mismatch for /usr/local/share/certs/ca-root-nss.crtChecking ca_root_nss: 100%Whatever tries to verify your SSL bounces it against the wrong file, but the feature is supposedly working as intended.Cheers,Franco