Block new Kazakhstan root

Bug: 1502288
Change-Id: I9d77c138ba6a43015a9818c25d43f39ea5a70562
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/5031126
Reviewed-by: Chris Thompson <cthomp@chromium.org>
Commit-Queue: Emily Stark <estark@chromium.org>
Reviewed-by: David Benjamin <davidben@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1224774}
diff --git a/net/cert/cert_verify_proc_blocklist.inc b/net/cert/cert_verify_proc_blocklist.inc
index 29561f7c..f6a55da 100644
--- a/net/cert/cert_verify_proc_blocklist.inc
+++ b/net/cert/cert_verify_proc_blocklist.inc
@@ -387,6 +387,10 @@
         {0xa6, 0xac, 0xa1, 0xec, 0x98, 0x09, 0xcc, 0x5b, 0x48, 0x21, 0xff,
          0x9d, 0x29, 0xc5, 0xeb, 0xe6, 0x51, 0x96, 0x0b, 0x91, 0xb1, 0xf1,
          0x9c, 0xc8, 0x9b, 0x55, 0xef, 0x87, 0x81, 0x8a, 0x95, 0x09},
+        // c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem
+        {0x02, 0xa9, 0x5f, 0x43, 0x43, 0x10, 0x19, 0xe9, 0xdc, 0x22, 0x5f,
+         0x05, 0xf4, 0x19, 0x33, 0x01, 0x90, 0xde, 0xb4, 0xa3, 0xf1, 0x86,
+         0x9c, 0xaa, 0xc9, 0x84, 0x2b, 0x40, 0x3d, 0xcb, 0xee, 0x77},
 };
 
 // Hashes of SubjectPublicKeyInfos known to be used for interception by a
@@ -424,4 +428,8 @@
     {0xea, 0x12, 0x70, 0x5d, 0xe7, 0xc4, 0x8f, 0x6f, 0xcc, 0xe2, 0xcb, 0x8d,
      0xbc, 0x54, 0x2e, 0x0f, 0xc3, 0x8a, 0xc3, 0x8e, 0x08, 0x88, 0x0d, 0xd0,
      0x4a, 0x02, 0xef, 0x67, 0xc9, 0x3a, 0xe1, 0x35},
+    // c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem
+    {0x02, 0xa9, 0x5f, 0x43, 0x43, 0x10, 0x19, 0xe9, 0xdc, 0x22, 0x5f, 0x05,
+     0xf4, 0x19, 0x33, 0x01, 0x90, 0xde, 0xb4, 0xa3, 0xf1, 0x86, 0x9c, 0xaa,
+     0xc9, 0x84, 0x2b, 0x40, 0x3d, 0xcb, 0xee, 0x77},
 };
diff --git a/net/data/ssl/blocklist/README.md b/net/data/ssl/blocklist/README.md
index d335d26..28ec117 100644
--- a/net/data/ssl/blocklist/README.md
+++ b/net/data/ssl/blocklist/README.md
@@ -321,6 +321,7 @@
   * [06fd20629c143b9eab28d2799caefc5d23fde267d16c631e3f5b8b4bab3f68e6.pem](06fd20629c143b9eab28d2799caefc5d23fde267d16c631e3f5b8b4bab3f68e6.pem)
   * [0bd39de4793cdc117138f47708aa4d583acf67adb059a0d91f668d1803bf6489.pem](0bd39de4793cdc117138f47708aa4d583acf67adb059a0d91f668d1803bf6489.pem)
   * [c95c133b68319ee516b5f41e377f589878af1556567cc2834ef03b1d10830fd3.pem](c95c133b68319ee516b5f41e377f589878af1556567cc2834ef03b1d10830fd3.pem)
+  * [c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem](c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem)
 
 ### revoked.badssl.com
 
diff --git a/net/data/ssl/blocklist/c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem b/net/data/ssl/blocklist/c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem
new file mode 100644
index 0000000..25aa8b5
--- /dev/null
+++ b/net/data/ssl/blocklist/c530fadc9bfa265e63b755cc6ee04c2d70d60bb916ce2f331dc7359362571b25.pem
@@ -0,0 +1,128 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            45:1d:32:70:96:8c:19:99:7c:f2:e4:e3:b9:77:08:ef:e2:76:f3:18
+    Signature Algorithm: sha256WithRSAEncryption
+        Issuer: CN=Information Security Certification Authority, O=ISCA, C=KZ
+        Validity
+            Not Before: Feb 28 05:39:51 2020 GMT
+            Not After : Feb 28 05:39:51 2050 GMT
+        Subject: CN=Information Security Certification Authority, O=ISCA, C=KZ
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                RSA Public-Key: (4096 bit)
+                Modulus:
+                    00:c0:1b:5f:8a:71:6b:5c:b2:41:c6:b4:06:b3:0f:
+                    82:93:2f:20:3f:d1:59:9b:12:85:83:d6:2b:06:10:
+                    d5:b1:85:92:0c:0c:93:8a:6f:f6:44:8d:3a:aa:2a:
+                    85:1c:cc:de:c6:4b:8e:b6:0c:9e:73:36:a8:e0:2c:
+                    3e:30:08:0e:b2:28:7e:50:24:f2:02:41:99:84:98:
+                    f0:ba:45:dc:49:cb:5f:92:29:38:f6:33:8c:0d:f0:
+                    06:f0:2f:fe:25:4b:a0:f0:b5:3a:a5:d6:66:39:80:
+                    5f:f9:cb:15:48:0f:d2:79:d5:0d:4e:86:06:bf:3c:
+                    e2:89:02:48:0b:6a:3f:7a:31:0a:a0:cd:2a:c5:83:
+                    bc:70:36:d3:a7:80:d9:f9:6a:78:1f:f0:a5:27:10:
+                    6a:75:68:11:2a:54:ea:55:bd:af:d5:35:df:c9:ec:
+                    c2:0f:41:65:ee:6a:79:65:da:90:40:44:c3:87:e3:
+                    b0:8d:ca:69:80:5a:77:28:1e:e3:1f:9e:0e:d6:1d:
+                    14:42:f5:90:71:37:0e:24:ed:c3:06:c5:78:b8:c1:
+                    e3:fb:d7:16:85:2d:70:f7:f1:58:e7:fe:c1:6b:e0:
+                    ad:53:d9:1d:13:11:c8:b2:f4:02:4d:0f:e9:9c:28:
+                    91:20:f3:3c:bf:57:66:28:0a:31:29:ef:a0:18:cc:
+                    10:36:b8:07:a8:c0:71:82:76:d1:dd:a7:60:a9:28:
+                    0f:64:a1:49:cd:71:ee:b7:00:20:e4:8e:17:41:ff:
+                    60:18:92:2d:36:45:93:3f:ca:5d:aa:54:92:b1:cf:
+                    bf:9d:b5:27:18:ee:97:f1:d7:7a:36:60:e9:38:a4:
+                    e0:8d:05:a3:bc:4d:27:9e:5b:80:31:3e:b8:03:f7:
+                    4d:ed:08:1d:a9:7d:d8:42:56:80:f4:19:7c:d4:81:
+                    07:e1:6d:72:55:78:a3:eb:4b:0c:9a:a8:aa:27:1f:
+                    d3:22:86:85:9a:f5:f4:a3:aa:55:2e:1c:f6:94:dd:
+                    a4:f2:a8:f7:be:6b:94:b4:d6:83:f0:22:a0:bb:78:
+                    dc:75:22:51:72:4a:17:06:52:86:e8:ef:ed:ed:03:
+                    48:0f:ce:65:bd:d3:4d:cf:e9:e0:e0:03:91:e7:2e:
+                    91:f0:d3:75:e4:92:0d:c8:90:f9:a4:55:15:cc:d2:
+                    57:d6:40:16:8d:ac:26:0f:1d:f5:a9:b0:21:0f:1c:
+                    2b:7e:06:d7:3e:bb:ce:77:42:8c:1b:a2:c1:9b:22:
+                    1b:a9:f7:60:63:9e:a3:ce:01:5d:67:46:3d:fb:92:
+                    17:3a:26:ba:b3:ff:dd:39:90:26:0b:90:34:3b:22:
+                    f2:60:1e:bd:a9:f5:77:c6:77:59:54:38:67:ab:5c:
+                    99:4c:e3
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: critical
+                CA:TRUE
+            X509v3 Key Usage: critical
+                Certificate Sign, CRL Sign
+            X509v3 Subject Key Identifier: 
+                C5:1D:32:70:96:8C:19:99:7C:F2:E4:E3:B9:77:08:EF:E2:76:F3:18
+            X509v3 Authority Key Identifier: 
+                keyid:C5:1D:32:70:96:8C:19:99:7C:F2:E4:E3:B9:77:08:EF:E2:76:F3:18
+                DirName:/CN=Information Security Certification Authority/O=ISCA/C=KZ
+                serial:45:1D:32:70:96:8C:19:99:7C:F2:E4:E3:B9:77:08:EF:E2:76:F3:18
+
+    Signature Algorithm: sha256WithRSAEncryption
+         84:a7:5d:48:c2:14:39:76:0c:46:37:18:fc:88:c8:77:8b:a3:
+         0b:55:d6:09:c5:51:68:aa:f6:29:a4:27:3e:a2:da:06:55:6e:
+         d4:e0:b6:43:c7:03:04:b7:58:bf:03:e2:fd:95:15:82:3a:28:
+         88:30:16:74:db:e1:31:68:ec:dc:7d:4a:62:72:41:65:2e:5e:
+         17:6d:38:a8:3c:33:f5:d5:a2:6b:62:b2:04:fd:05:81:95:2f:
+         cd:ea:5f:7e:34:19:f4:3b:91:b5:10:26:6b:91:a3:62:fa:6c:
+         52:ac:8c:a6:27:d2:74:ec:ea:12:04:a6:e9:c1:01:b1:df:eb:
+         20:fc:19:1f:59:54:02:46:28:e0:6a:f4:26:23:d0:11:43:b5:
+         eb:63:ab:25:2e:d3:23:68:05:d5:c3:ec:1e:ae:cd:cf:ac:44:
+         75:6c:d4:0b:77:c5:a1:54:8e:70:08:87:51:c4:85:79:c6:b3:
+         a3:22:03:6e:3f:71:9b:3a:e5:d1:cd:a0:bb:81:d6:ca:8f:7c:
+         b3:88:57:48:3a:ed:a8:d7:3d:71:bb:f2:10:29:52:73:6f:90:
+         0e:8d:83:0e:f8:c8:15:fc:4c:79:8a:36:f0:83:a9:57:50:02:
+         b0:4c:0a:be:3e:d7:78:11:2c:f1:70:89:15:4e:42:c3:86:a8:
+         1f:de:b6:1d:d2:a1:aa:40:16:46:b2:57:7c:a0:a3:5a:61:d8:
+         b1:64:2f:54:23:24:1c:49:2e:54:58:f2:10:14:0d:18:31:fe:
+         5c:11:2e:5e:07:fa:1f:fe:37:01:c1:ea:39:01:c5:70:f4:10:
+         6a:4c:8e:d6:80:34:10:0a:7b:b2:e2:59:6e:fa:7b:c3:c0:05:
+         ca:e9:07:1c:1e:24:d9:d8:95:39:d1:81:dd:9d:ca:ff:82:bd:
+         6f:97:09:e4:bd:ee:85:b9:7a:5a:1a:c2:f1:aa:40:3c:a3:77:
+         04:27:27:04:ad:67:c1:20:d8:36:d6:8f:bc:8d:78:1a:ec:e1:
+         3f:95:53:b9:e0:9e:8c:b8:43:d1:17:78:5b:de:89:78:35:64:
+         2e:4c:2e:43:c0:99:71:f4:06:06:44:64:f5:eb:49:93:b7:ab:
+         c4:66:aa:f8:de:39:40:8f:cc:69:31:a9:d8:8e:65:59:bf:1d:
+         57:36:fc:c2:7c:65:da:d6:d2:63:95:a6:c5:0c:a5:cd:71:57:
+         8f:d9:f8:a5:35:0f:ba:12:28:fd:c1:f1:b5:66:83:48:36:5f:
+         2b:a5:c6:32:f2:19:b6:63:92:a6:9d:9c:3e:44:18:4e:a4:02:
+         35:d0:0e:b9:70:17:26:30:6b:40:24:b7:61:1c:f9:41:d0:78:
+         fb:f6:29:a2:a4:a9:16:60
+-----BEGIN CERTIFICATE-----
+MIIGDTCCA/WgAwIBAgIURR0ycJaMGZl88uTjuXcI7+J28xgwDQYJKoZIhvcNAQEL
+BQAwUzE1MDMGA1UEAxMsSW5mb3JtYXRpb24gU2VjdXJpdHkgQ2VydGlmaWNhdGlv
+biBBdXRob3JpdHkxDTALBgNVBAoTBElTQ0ExCzAJBgNVBAYTAktaMCAXDTIwMDIy
+ODA1Mzk1MVoYDzIwNTAwMjI4MDUzOTUxWjBTMTUwMwYDVQQDEyxJbmZvcm1hdGlv
+biBTZWN1cml0eSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTENMAsGA1UEChMESVND
+QTELMAkGA1UEBhMCS1owggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDA
+G1+KcWtcskHGtAazD4KTLyA/0VmbEoWD1isGENWxhZIMDJOKb/ZEjTqqKoUczN7G
+S462DJ5zNqjgLD4wCA6yKH5QJPICQZmEmPC6RdxJy1+SKTj2M4wN8AbwL/4lS6Dw
+tTql1mY5gF/5yxVID9J51Q1Ohga/POKJAkgLaj96MQqgzSrFg7xwNtOngNn5angf
+8KUnEGp1aBEqVOpVva/VNd/J7MIPQWXuanll2pBARMOH47CNymmAWncoHuMfng7W
+HRRC9ZBxNw4k7cMGxXi4weP71xaFLXD38Vjn/sFr4K1T2R0TEciy9AJND+mcKJEg
+8zy/V2YoCjEp76AYzBA2uAeowHGCdtHdp2CpKA9koUnNce63ACDkjhdB/2AYki02
+RZM/yl2qVJKxz7+dtScY7pfx13o2YOk4pOCNBaO8TSeeW4AxPrgD903tCB2pfdhC
+VoD0GXzUgQfhbXJVeKPrSwyaqKonH9MihoWa9fSjqlUuHPaU3aTyqPe+a5S01oPw
+IqC7eNx1IlFyShcGUobo7+3tA0gPzmW9003P6eDgA5HnLpHw03Xkkg3IkPmkVRXM
+0lfWQBaNrCYPHfWpsCEPHCt+Btc+u853QowbosGbIhup92BjnqPOAV1nRj37khc6
+Jrqz/905kCYLkDQ7IvJgHr2p9XfGd1lUOGerXJlM4wIDAQABo4HWMIHTMA8GA1Ud
+EwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBTFHTJwlowZmXzy
+5OO5dwjv4nbzGDCBkAYDVR0jBIGIMIGFgBTFHTJwlowZmXzy5OO5dwjv4nbzGKFX
+pFUwUzE1MDMGA1UEAxMsSW5mb3JtYXRpb24gU2VjdXJpdHkgQ2VydGlmaWNhdGlv
+biBBdXRob3JpdHkxDTALBgNVBAoTBElTQ0ExCzAJBgNVBAYTAktaghRFHTJwlowZ
+mXzy5OO5dwjv4nbzGDANBgkqhkiG9w0BAQsFAAOCAgEAhKddSMIUOXYMRjcY/IjI
+d4ujC1XWCcVRaKr2KaQnPqLaBlVu1OC2Q8cDBLdYvwPi/ZUVgjooiDAWdNvhMWjs
+3H1KYnJBZS5eF204qDwz9dWia2KyBP0FgZUvzepffjQZ9DuRtRAma5GjYvpsUqyM
+pifSdOzqEgSm6cEBsd/rIPwZH1lUAkYo4Gr0JiPQEUO162OrJS7TI2gF1cPsHq7N
+z6xEdWzUC3fFoVSOcAiHUcSFecazoyIDbj9xmzrl0c2gu4HWyo98s4hXSDrtqNc9
+cbvyEClSc2+QDo2DDvjIFfxMeYo28IOpV1ACsEwKvj7XeBEs8XCJFU5Cw4aoH962
+HdKhqkAWRrJXfKCjWmHYsWQvVCMkHEkuVFjyEBQNGDH+XBEuXgf6H/43AcHqOQHF
+cPQQakyO1oA0EAp7suJZbvp7w8AFyukHHB4k2diVOdGB3Z3K/4K9b5cJ5L3uhbl6
+WhrC8apAPKN3BCcnBK1nwSDYNtaPvI14GuzhP5VTueCejLhD0Rd4W96JeDVkLkwu
+Q8CZcfQGBkRk9etJk7erxGaq+N45QI/MaTGp2I5lWb8dVzb8wnxl2tbSY5WmxQyl
+zXFXj9n4pTUPuhIo/cHxtWaDSDZfK6XGMvIZtmOSpp2cPkQYTqQCNdAOuXAXJjBr
+QCS3YRz5QdB4+/YpoqSpFmA=
+-----END CERTIFICATE-----