Closed Bug 1021054 Opened 8 years ago Closed 8 years ago

Add QuoVadis G3 root certificates to NSS

Categories

(NSS :: CA Certificates Code, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED
3.16.3

People

(Reporter: kwilson, Unassigned)

References

Details

Attachments

(3 files)

1.91 KB, application/x-x509-ca-cert
Details
1.91 KB, application/x-x509-ca-cert
Details
1.91 KB, application/x-x509-ca-cert
Details
This bug requests inclusion in the NSS root certificate store of the following 3 certificates, owned by QuoVadis.

Friendly name: QuoVadis Root CA 1 G3
Certificate location: http://trust.quovadisglobal.com/qvrca1g3.crt
SHA1 Fingerprint: 1B:8E:EA:57:96:29:1A:C9:39:EA:B8:0A:81:1A:73:73:C0:93:79:67
Trust flags: Websites, Email, Code Signing
Test URL: https://qvica1g3-v.quovadisglobal.com/

Friendly name: QuoVadis Root CA 2 G3
Certificate location: http://trust.quovadisglobal.com/qvrca2g3.crt
SHA1 Fingerprint: 09:3C:61:F3:8B:8B:DC:7D:55:DF:75:38:02:05:00:E1:25:F5:C8:36
Trust flags: Websites, Code Signing
Test URL: https://evsslicag3-v.quovadisglobal.com/

Friendly name: QuoVadis Root CA 3 G3
Certificate location: http://trust.quovadisglobal.com/qvrca3g3.crt
SHA1 Fingerprint: 48:12:BD:92:3C:A8:C4:39:06:E7:30:6D:27:96:E6:A4:CF:22:2E:7D
Trust flags: Websites, Email, Code Signing
Test URL: https://qvica3g3-v.quovadisglobal.com/

This CA has been assessed in accordance with the Mozilla project guidelines, and the certificates approved for inclusion in bug #926541.

The next steps are as follows:

1) A representative of the CA must confirm that all the data in this bug is correct, and that the correct certificates have been attached.

2) A Mozilla representative creates a patch with the new certificates, and provides a special test version of Firefox.

3) A representative of the CA uses the test version of Firefox to confirm (by adding a comment in this bug) that the certificates have been correctly imported and that websites work correctly.

4) The Mozilla representative requests that another Mozilla representative review the patch.

5) The Mozilla representative adds (commits) the patch to NSS, then closes this bug as RESOLVED FIXED.

6) At some time after that, various Mozilla products will move to using a version of NSS which contains the certificates. This process is mostly under the control of the release drivers for those products.
Attached file QuoVadisRootCA1G3.crt
Attached file QuoVadisRootCA2G3.crt
Attached file QuoVadisRootCA3G3.crt
Stephen, Please see step #1 above.
Blocks: 1021106
QuoVadis confirms that the data in this bug is correct, and that the correct certificates have been attached.  Regards, Stephen
Blocks: 1021967
No longer blocks: 1021967
Depends on: 1021967
A Test Build with these changes has been created as part of Bug #1021967.
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-394c2eeb9793/

Please test, as described here:
https://wiki.mozilla.org/CA:How_to_apply#Testing_Inclusion
I have tested SSL certificates issued by all three G3 roots using the nightly.  All provide the padlock.
However, the test EV SSL certificate issued under Root CA2 G3 does not show EV indicators.
The EV OID for Root CA2 G3 is 1.3.6.1.4.1.8024.0.2.100.1.2

Test EV certificate:  https://evsslicag3-v.quovadisglobal.com/
Other test certificates: http://www.quovadisglobal.com/en-GB/QVRepository/TestCertificates.aspx
(In reply to Stephen Davidson from comment #7)
> I have tested SSL certificates issued by all three G3 roots using the
> nightly.  All provide the padlock.

Thanks for testing.

> However, the test EV SSL certificate issued under Root CA2 G3 does not show
> EV indicators.

EV treatment (Bug #1021106) requires a different code change, and can only be done after the root has been included.
Aha, understood.  Thank you!
fixed as part of bug 1021967
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
Target Milestone: --- → 3.16.3
You need to log in before you can comment on or make changes to this bug.