Closed Bug 1988913 Opened 7 months ago Closed 7 months ago

Add OISTE Root CA Certificates to NSS

Categories

(NSS :: CA Certificates Code, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: bwilson, Assigned: djackson)

References

Details

Attachments

(5 files)

568 bytes, application/x-x509-ca-cert
Details
1.38 KB, application/x-x509-ca-cert
Details
569 bytes, application/x-x509-ca-cert
Details
1.38 KB, application/x-x509-ca-cert
Details
48 bytes, text/x-phabricator-request
Details | Review

This bug requests inclusion in the NSS root store of the following root certificates owned by OISTE:

Root Certificate 1 of 4
Friendly Name: OISTE Client Root ECC G1
Cert Location: http://public.wisekey.com/crt/ocreccg1.cer
SHA-1 Fingerprint: C02B13F91D7756ED6C9283F186DF2AD51E6EF2BC
SHA-256 Fingerprint: D9A32485A8CCA85539CEF12FFFFF711378A17851D73DA2732AB4302D763BD62B
Trust Flag: Email

Root Certificate 2 of 4
Friendly Name: OISTE Client Root RSA G1
Cert Location: http://public.wisekey.com/crt/ocrrsag1.cer
SHA-1 Fingerprint: BDA81320E0BF97EDA28E9E185FF2D5FEE52B13D5
SHA-256 Fingerprint: D02A0F994A868C66395F2E7A880DF509BD0C29C96DE16015A0FD501EDA4F96A9
Trust Flag: Email

Root Certificate 3 of 4
Friendly Name: OISTE Server Root ECC G1
Cert Location: http://public.wisekey.com/crt/osreccg1.cer
SHA-1 Fingerprint: 3BF68B09AE2A927BBAE38D3F1195D9E6440C45E2
SHA-256 Fingerprint: EEC997C0C30F216F7E3B8B307D2BAE42412D753FC8219DAFD1520B2572850F49
Trust Flag: Websites
Test URL: https://eccg1validssl.hightrusted.com/

Root Certificate 4 of 4
Friendly Name: OISTE Server Root RSA G1
Cert Location: http://public.wisekey.com/crt/osrrsag1.cer
SHA-1 Fingerprint: F700342594886831E434873F70FE86B3869FF06E
SHA-256 Fingerprint: 9AE36232A5189FFDDB353DFD26520C015395D22777DAC59DB57B98C089A651E6
Trust Flag: Websites
Test URL: https://rsag1validssl.hightrusted.com/

OISTE's inclusion application has been assessed in accordance with the Mozilla project guidelines, and the certificates approved for inclusion in bug #1936279.

The next steps are as follows:

  1. A representative of the CA must confirm that all the data in this bug is correct, and that the correct certificates have been attached.
  2. A Mozilla representative creates a patch with the new certificates.
  3. The Mozilla representative requests that another Mozilla representative review the patch.
  4. The Mozilla representative adds (commits) the patch to NSS, then closes this bug as RESOLVED FIXED.
  5. At some time after that, various Mozilla products will move to using a version of NSS which contains the certificate. This process is mostly under the control of the release drivers for those products.

Pedro,
Please see Step #1 above.
Thanks,
Ben

Blocks: 1936279
Flags: needinfo?(pfuentes)
Attached file ocreccg1.cer
Attached file ocrrsag1.cer
Attached file osreccg1.cer
Attached file osrrsag1.cer
Blocks: 1988916

Hello Ben,
this seems all OK to me.
Thanks!
Pedro

Flags: needinfo?(pfuentes)
Assignee: nobody → djackson
Status: NEW → ASSIGNED
Blocks: 1988290
No longer blocks: 1936279, 1988916
Depends on: 1936279, 1988916

Pushed by djackson@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/0f59abe809d6
Add OISTE roots. r=nss-reviewers,nkulatova

Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Resolution: --- → FIXED
Pushed by djackson@mozilla.com: https://hg.mozilla.org/projects/nss/rev/3a2d6a6f7443 Add OISTE roots. r=nss-reviewers,nkulatova
Blocks: 1936279, 1988916
No longer depends on: 1936279, 1988916
Regressions: 2003189
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: