Closed Bug 346614 Opened 19 years ago Closed 19 years ago

Austrian officially accredited Root CAs inclusion in Mozilla suite (add certificates)

Categories

(CA Program :: CA Certificate Root Program, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 318712

People

(Reporter: sec, Assigned: hecker)

Details

(Keywords: ecommerce)

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1 The Austria accredited Root Certificates should be included in the suite. These are the official CAs that are authorized by Austria Telecom Control Regulation Authority (RTR) to be used in/for officially signed documents & sites. There is a metaregistry at https://www.signatur.rtr.at/en/index.html, that, if included, chains down to the authorized CAs. The RTR is authorized by the signature law (SigG) to authorize CAs. There are currently 10 CAs: https://www.signatur.rtr.at/en/providers/providers.html Please include them. The RTR has a (german) text on the requirements, which, i assume, easily supercede these set by the MF: https://www.signatur.rtr.at/en/legal/sigg.html Reproducible: Always Steps to Reproduce: 1. go to a page that is authorized by austrian law to be a CA Actual Results: popup with unknown cert Expected Results: no popup
p.s.: add-on: the RTR is the telecom regulation company (don't know, limited?), but is controlled by the TKC (Telecom Control Commission), which is a government body - see http://www.rtr.at/web.nsf/englisch/Ueber+Uns_TKK?OpenDocument . to prove this further, see §15 SigG (Signature law) or Art. 1 § 115 TKG /telecommunitations law) for me not making RTR as authority up.
mozilla only has one list of trusted root CA certificates. That one list is used in all mozilla products. So requests for inclusion really can't be filed for specific mozilla products, but can be filed for all mozilla products together. All requests for inclusion in that CA cert list are filed against product "mozilla.org" component "CA Certificates". I confirm that this is a request for an addition to mozilla's cert list. I have no comment (at this time) on the merit of the CA(s).
Assignee: dveditz → hecker
Severity: normal → enhancement
Status: UNCONFIRMED → NEW
Component: Security → CA Certificates
Ever confirmed: true
Product: Mozilla Application Suite → mozilla.org
QA Contact: seamonkey
Version: unspecified → other
Keywords: ecommerce
btw: bug 252610 is chaining to the RTR, too. the signature law should clear out all questions about reliability and trustwirthyness, i think.
Accepting this bug. Note that I will have to consider each CA request individually, because there may be individual circumstances relevant to our decision. (For example, one or more of the CAs may not meet our requirement that inclusion of the CA be of benefit to typical Mozilla users.) I will likely file separate bugs for each of the CAs in the list.
Status: NEW → ASSIGNED
re. Note that I will have to consider each CA request individually, because there may be individual circumstances relevant to our decision. i propose checking the signature law to ease this process. i assume that the signature law is more restrictive than the mozilla ruleset. and as for benefit - if some are included and others arent, this is going to be political, as it would propably make the not included CAs complain about unfair or whatever..
The original Description says: > These are the official CAs that are authorized by Austria Telecom Control > Regulation Authority (RTR) to be used in/for officially signed documents & > sites. This indicates to me that the certificates are NOT used to sign or otherwise authenticate subscriber certificates owned by the general public. Instead, it appears that the root certificates are used to sign official government certificates. If that is true, this root certificate does not meet the policy requirements for inclusion in Mozilla products.
no, the certs are used for invoices and for the "citicen-card", basically all inter-company stuff - they are _not_ only for governmental correspondence.
Summary: Austrian officially accredited Root CAs inclusion in Mozilla suite → Austrian officially accredited Root CAs inclusion in Mozilla suite (add certificates)
any news? a yes or a no? i'd assume that the EC regulations for a national CA should suffice to be OK for MF, if even verisign is still in (afaik they have no governmental status) - for the end-user this is pretty annoying (well, for me personally, too, to explain why, but well..)
Reporter: Are these certificates self-issued root CA certificates? Or are they subordinate CA certificates, issued by another CA, such as TCK? Is this bug a duplicate of bug 318712, or vice versa?
QA Contact: ca-certificates
hi, yes, it is a duplicate i did query the database, but didn't find it. apparently the other bug rests for over a year, maybe i did only check the last 6 months, don't know...
Status: ASSIGNED → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
Product: mozilla.org → NSS
Product: NSS → CA Program
You need to log in before you can comment on or make changes to this bug.