Closed
Bug 346614
Opened 19 years ago
Closed 19 years ago
Austrian officially accredited Root CAs inclusion in Mozilla suite (add certificates)
Categories
(CA Program :: CA Certificate Root Program, task)
CA Program
CA Certificate Root Program
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 318712
People
(Reporter: sec, Assigned: hecker)
Details
(Keywords: ecommerce)
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1
The Austria accredited Root Certificates should be included in the suite.
These are the official CAs that are authorized by Austria Telecom Control Regulation Authority (RTR) to be used in/for officially signed documents & sites.
There is a metaregistry at https://www.signatur.rtr.at/en/index.html, that, if included, chains down to the authorized CAs.
The RTR is authorized by the signature law (SigG) to authorize CAs.
There are currently 10 CAs:
https://www.signatur.rtr.at/en/providers/providers.html
Please include them. The RTR has a (german) text on the requirements, which, i assume, easily supercede these set by the MF:
https://www.signatur.rtr.at/en/legal/sigg.html
Reproducible: Always
Steps to Reproduce:
1. go to a page that is authorized by austrian law to be a CA
Actual Results:
popup with unknown cert
Expected Results:
no popup
p.s.: add-on: the RTR is the telecom regulation company (don't know, limited?), but is controlled by the TKC (Telecom Control Commission), which is a government body - see http://www.rtr.at/web.nsf/englisch/Ueber+Uns_TKK?OpenDocument .
to prove this further, see §15 SigG (Signature law) or Art. 1 § 115 TKG /telecommunitations law) for me not making RTR as authority up.
Comment 2•19 years ago
|
||
mozilla only has one list of trusted root CA certificates.
That one list is used in all mozilla products.
So requests for inclusion really can't be filed for specific mozilla products,
but can be filed for all mozilla products together.
All requests for inclusion in that CA cert list are filed against product
"mozilla.org" component "CA Certificates".
I confirm that this is a request for an addition to mozilla's cert list.
I have no comment (at this time) on the merit of the CA(s).
Assignee: dveditz → hecker
Severity: normal → enhancement
Status: UNCONFIRMED → NEW
Component: Security → CA Certificates
Ever confirmed: true
Product: Mozilla Application Suite → mozilla.org
QA Contact: seamonkey
Version: unspecified → other
btw: bug 252610 is chaining to the RTR, too.
the signature law should clear out all questions about reliability and trustwirthyness, i think.
| Assignee | ||
Comment 4•19 years ago
|
||
Accepting this bug. Note that I will have to consider each CA request individually, because there may be individual circumstances relevant to our decision. (For example, one or more of the CAs may not meet our requirement that inclusion of the CA be of benefit to typical Mozilla users.) I will likely file separate bugs for each of the CAs in the list.
Status: NEW → ASSIGNED
re. Note that I will have to consider each CA request
individually, because there may be individual circumstances relevant to our
decision.
i propose checking the signature law to ease this process. i assume that the signature law is more restrictive than the mozilla ruleset. and as for benefit - if some are included and others arent, this is going to be political, as it would propably make the not included CAs complain about unfair or whatever..
Comment 6•19 years ago
|
||
The original Description says:
> These are the official CAs that are authorized by Austria Telecom Control
> Regulation Authority (RTR) to be used in/for officially signed documents &
> sites.
This indicates to me that the certificates are NOT used to sign or otherwise authenticate subscriber certificates owned by the general public. Instead, it appears that the root certificates are used to sign official government certificates. If that is true, this root certificate does not meet the policy requirements for inclusion in Mozilla products.
no, the certs are used for invoices and for the "citicen-card", basically all inter-company stuff - they are _not_ only for governmental correspondence.
Updated•19 years ago
|
Summary: Austrian officially accredited Root CAs inclusion in Mozilla suite → Austrian officially accredited Root CAs inclusion in Mozilla suite (add certificates)
any news? a yes or a no?
i'd assume that the EC regulations for a national CA should suffice to be OK for MF, if even verisign is still in (afaik they have no governmental status) - for the end-user this is pretty annoying (well, for me personally, too, to explain why, but well..)
Comment 9•19 years ago
|
||
Reporter:
Are these certificates self-issued root CA certificates?
Or are they subordinate CA certificates, issued by another CA, such as TCK?
Is this bug a duplicate of bug 318712, or vice versa?
Updated•19 years ago
|
QA Contact: ca-certificates
| Reporter | ||
Comment 10•19 years ago
|
||
hi,
yes, it is a duplicate
i did query the database, but didn't find it.
apparently the other bug rests for over a year, maybe i did only check the last 6 months, don't know...
Status: ASSIGNED → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
Updated•9 years ago
|
Product: mozilla.org → NSS
Updated•3 years ago
|
Product: NSS → CA Program
You need to log in
before you can comment on or make changes to this bug.
Description
•