Closed Bug 1679256 Opened 4 years ago Closed 2 years ago

Root inclusion request for D-TRUST BR Root CA 1 2020

Categories

(CA Program :: CA Certificate Root Program, task, P1)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: enrico.entschew, Assigned: bwilson)

References

Details

(Whiteboard: [ca-approved] - in Firefox 100, NSS 3.77)

Attachments

(4 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36 Edg/87.0.664.41

Steps to reproduce:

This is a request for a root inclusion.
http://www.d-trust.net/cgi-bin/D-TRUST_BR_Root_CA_1_2020.crt
CN=D-TRUST BR Root CA 1 2020
O=D-Trust GmbH

(Planned rollover for D-TRUST Root Class 3 CA 2 2009)

Key Ceremony Attestation for D-TRUST BR Root CA 1 2020

Assignee: kwilson → bwilson
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Type: enhancement → task
Whiteboard: [ca-initial]

According to the CCADB we need:

Priority: -- → P1
Whiteboard: [ca-initial] → [ca-verifying]

Do you have three test websites with certificates that chain up to this root - a valid certificate, an expired certificate, and a revoked certificate? Thanks.

Flags: needinfo?(enrico.entschew)

Hallo Ben, please find the requested information here:

Overview of the test websites of D-TRUST BR Root CA 1 2020
Valid: https://certdemo-ov-valid.tls.d-trust.net/
Revoked: https://certdemo-ov-revoked.tls.d-trust.net/
Expired: https://certdemo-ov-expired.tls.d-trust.net/

Furthermore, I submit the CA hierarchy including the Sub CAs in the pdf.

The results of the self assessment will follow after the updated CP, CPS and TSPS are published.

Flags: needinfo?(enrico.entschew)

Please find here the CA hierarchy including Root CA and Sub CAs.

Flags: needinfo?(bwilson)

Awaiting BR Self Assessment, and then this request can be moved to CP/CPS review.

Please find attached the BR self assessment of the D-TRUST BR Root CA 1 2020.

Flags: needinfo?(bwilson)
Whiteboard: [ca-verifying] → [ca-cps-review] BW 2021-08-06

CP-CPS review can be found in 4th column of attachment in Bug #1679258 - https://bugzilla.mozilla.org/attachment.cgi?id=9243128

Whiteboard: [ca-cps-review] BW 2021-08-06 → [ca-cps-review] BW 2021-09-27

CP-CPS Review highlights are posted here: https://bugzilla.mozilla.org/show_bug.cgi?id=1679258#c9

Information to the updated policy documents and revised BR self assessment can be found here: https://bugzilla.mozilla.org/show_bug.cgi?id=1679258#c10 and https://bugzilla.mozilla.org/show_bug.cgi?id=1679258#c11

Whiteboard: [ca-cps-review] BW 2021-09-27 → [ca-ready-for-discussion 2021-10-20]

Public discussion started today with a scheduled close of 28-Jan-2022: https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/0Ljc_EkPsiQ/m/9XLIROdXBAAJ

Whiteboard: [ca-ready-for-discussion 2021-10-20] → [ca-in-discussion] 2022-01-06

Public discussion closed without comment and with my recommendation that we include this root CA certificate in NSS with the websites trust bit enabled. See https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/0Ljc_EkPsiQ/m/34f608EgAgAJ

Flags: needinfo?(kwilson)
Whiteboard: [ca-in-discussion] 2022-01-06 → [ca-pending-approval] 2022-01-31

As per Comment #12, and on behalf of Mozilla I approve this request from D-TRUST to include the following root certificate:

** D-TRUST BR Root CA 1 2020 (Websites)

I will file the NSS bug for the approved changes.

Flags: needinfo?(kwilson)
Whiteboard: [ca-pending-approval] 2022-01-31 → [ca-approved] - pending NSS code changes
Depends on: 1754890

I have filed bug #1754890 against NSS for the actual changes.

Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Whiteboard: [ca-approved] - pending NSS code changes → [ca-approved] - in Firefox 100, NSS 3.77
Product: NSS → CA Program
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: