Closed Bug 1781510 Opened 2 years ago Closed 3 months ago

Add D-Trust SBR Root CAs 1 & 2 2022

Categories

(CA Program :: CA Certificate Root Program, task, P1)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: bwilson, Assigned: bwilson)

References

Details

(Whiteboard: [ca-approved] - in NSS 3.98, Firefox 124)

Attachments

(8 files)

Status: NEW → ASSIGNED
Priority: -- → P1
Whiteboard: [ca-initial]

Dear Ben,
Please find the root CA certificates, the audit attestations and the PKI hierarchy overviews.
In future, the “D-Trust SBR Root CA 1 2022” root CA (ECC) and the “D-Trust SBR Root CA 2 2022” root CA (RSA) are to replace the existing “D-TRUST Root CA 3 2013” root CA.
We are currently carrying out the self-assessment for both root CAs. We will submit the result after completion.
Thanks,
Enrico

Product: NSS → CA Program
Whiteboard: [ca-initial] → [ca-verifying]

Could you please attach an end-entity SMIME certificate issued under each of these roots to this bug? Also, can you upload information about your key generation, too?
Thanks, Ben

Flags: needinfo?(enrico.entschew)

Please find here the links of the audit attestations of the key generation:
https://www.tuvit.de/fileadmin/Content/TUV_IT/zertifikate/de/AA2022081901_D-TRUST_SBR_Root_CA_1_2022_V1.0.pdf
https://www.tuvit.de/fileadmin/Content/TUV_IT/zertifikate/de/AA2022081902_D-TRUST_SBR_Root_CA_2_2022_V1.0.pdf

The end-entity S/MIME certificates issued under each of these roots will be published here as soon as it is available.
Thanks, Enrico

Flags: needinfo?(enrico.entschew)

Thanks, Enrico. That information has been updated in the CCADB. How do you propose that we handle the Self Assessment for these S/MIME Root CAs, since you completed a self assessment within the last few years- e.g. https://bugzilla.mozilla.org/attachment.cgi?id=9246613 ? We have a new form, but it mainly is geared toward SSL/TLS and the Baseline Requirements. It appears that my questions regarding the email trust bit were asked and answered in that attachment you provided in Bugzilla #1679258. We look forward to receiving your S/MIME certificates.

Flags: needinfo?(enrico.entschew)
Whiteboard: [ca-verifying] → [ca-ready-for-discussion 2023-03-24]

How soon do you think it will be until you can upload your sample S/MIME certificates here?
Thanks,
Ben

Dear Ben,
After checking with the product management, we will provide the certificates by the end of May at the latest.
Thanks,
Enrico

Flags: needinfo?(enrico.entschew)

Here is the test certificate from the S/MIME root CA "D-Trust SBR Root CA 2 2022". You can also download the certificate here: https://www.d-trust.net/internet/files/RollOverSmime_RSA.cer

Here is the test certificate from the S/MIME root CA "D-Trust SBR Root CA 1 2022". You can also download the certificate here: https://www.d-trust.net/internet/files/RollOverSmime_EC.cer

Whiteboard: [ca-ready-for-discussion 2023-03-24] → [ca-in-discussion]

Public discussion commenced on 2023-11-03 (https://groups.google.com/a/ccadb.org/g/public/c/EPVczE_6oCc/m/s90nO9-EBAAJ) and concluded on 2023-12-15 (https://groups.google.com/a/ccadb.org/g/public/c/EPVczE_6oCc/m/jsZ0CsgdAAAJ). Today I sent notice to the Mozilla Dev-Security-Policy list that I am recommending approval of D-Trust's request. https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/vjX1-3zQ7ds/m/mSnRpjgOAAAJ. This starts a 7-day "last call" which will run through December 26, 2023.

Whiteboard: [ca-in-discussion] → [ca-pending-approval] 2023-12-19

As per Comment #16, and on behalf of Mozilla, this request from D-Trust to include the following root certificates is Approved:

** D-Trust SBR Root CA 1 2022 (Email)
** D-Trust SBR Root CA 2 2022 (Email)

I will file the NSS bug for the approved changes.

Flags: needinfo?(bwilson)
Flags: needinfo?(bwilson)
Whiteboard: [ca-pending-approval] 2023-12-19 → [ca-approved] - pending NSS code changes
Depends on: 1873095

Bug # 1873095 has been created to add these CA certificates to NSS.

Whiteboard: [ca-approved] - pending NSS code changes → [ca-approved] - in NSS 3.98, Firefox 124

These two roots are in Firefox Nightly 124.0a1 (2024-02-01).

Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: