Closed Bug 555860 Opened 10 years ago Closed 10 years ago

Enable Certplus Class 2 Primary CA for EV in PSM


(Core :: Security: PSM, enhancement)

Not set



Tracking Status
status1.9.2 --- .7-fixed
status1.9.1 --- .11-fixed


(Reporter: kwilson, Assigned: KaiE)




(1 file)

Per bug 497917 the request from Keynectis/Certplus has been approved to enable its Certplus “Class 2 Primary CA” root certificate for EV use. Please make the corresponding changes to PSM.

The relevant information is as follows:

Friendly name: Certplus Class 2 Primary CA

SHA1 Fingerprint: 

EV policy OID: 

Test URL:
Erwann, Please confirm that the above information is correct.
I double checked the SHA1 fingerprint, and the EV Policy OID. Everything mentioned above is correct.
BTW, thank you for your implication.
Thanks for confirming that the data in this bug is correct.

Root inclusions/updates are usually grouped and done as a batch when there is either a large enough set of changes or about every 3 months.

At some point in the next 3 months a test build will be provided and this bug will be updated to request that you test it. Since you are cc'd on this bug, you will get notification via email when that happens.
Attached patch Patch v1Splinter Review
Using this patch I get the expected green EV indicator.
Attachment #437711 - Flags: review?(rrelyea)
Kathleen, I wonder if we could simplify the verification procedure (this time only), given that no NSS update is necessary.

My proposal is:
- I've already tested that it appears to work
- we get the code review
- we add the code to the experimental Firefox nightly builds
- the CA representatives verify correctness using an 
  Firefox 3.7 nightly developer build
- if correct, we could proceed (if desired) to add it to stable branches

Kathleen, would you be OK with this simplified procedure?

Erwann Abalea, would you be OK to perform the test using an "alpha quality" version of Firefox?
For you and my reference, I'm talking about the nightly builds that are updated each night at this location:

(your root is NOT yet enabled in those builds, we'll update the bug if the proposal is accepted and once the code has been added)
I'm OK to test such an "alpha quality" version of Firefox.
Kai, That sounds like a good plan.  Thanks!
Attachment #437711 - Flags: review?(honzab.moz)
Comment on attachment 437711 [details] [diff] [review]
Patch v1

Works for me.

>diff --git a/security/manager/ssl/src/nsIdentityChecking.cpp b/security/manager/ssl/src/nsIdentityChecking.cpp
>+    //    CN=Class 2 Primary CA,O=Certplus,C=FR

Maybe just adjust to one space after // to be consistent with the rest of the file.

Attachment #437711 - Flags: review?(honzab.moz) → review+
Comment on attachment 437711 [details] [diff] [review]
Patch v1

r+ rrelyea
Attachment #437711 - Flags: review?(rrelyea) → review+
Checked in

Erwann: Please wait until tomorrow, then go to the address from comment 6, and grab a alpha quality build with a timestamp of May 04.
Thanks in advance for testing.
Please let us know if it works right for you.
Closed: 10 years ago
Resolution: --- → FIXED
Sorry I couldn't check yesterday, too busy.
I just downloaded and tested the May 05 version, for Linux i686, that's right for me, I get the green bar.

Thanks, Kai.
Comment on attachment 437711 [details] [diff] [review]
Patch v1

requesting EV approval for stable firefox branches
Attachment #437711 - Flags: approval1.9.2.5?
Attachment #437711 - Flags: approval1.9.1.11?
Attachment #437711 - Flags: approval1.9.2.6+
Attachment #437711 - Flags: approval1.9.2.5?
Attachment #437711 - Flags: approval1.9.1.11?
Attachment #437711 - Flags: approval1.9.1.11+
Comment on attachment 437711 [details] [diff] [review]
Patch v1

Approved for and, a=dveditz for release-drivers
You need to log in before you can comment on or make changes to this bug.