https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=256923
--- Comment #2 from Michael Osipov <michael.osi...@siemens.com> --- (In reply to Kubilay Kocak from comment #1) While I understand the out of the box exprience, but since certctl(8) is there, there is very little need for ca_root_nss or I simply don't understand why it is still required. I expect every OpenSSL aware application to set default verification paths unless it is overridden by some means. I did a test run for our base ports with and without ca_root_nss on sphinx. I am from 120 packages down to 60 just because perl is out of the game. -- You are receiving this mail because: You are on the CC list for the bug. You are the assignee for the bug.