Closed Bug 896546 Opened 11 years ago Closed 11 years ago

Remove Wells Fargo Root Certificate Authority root cert from NSS

Categories

(NSS :: CA Certificates Code, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED
3.15.4

People

(Reporter: kwilson, Unassigned)

References

Details

This bug requests that the following root certificate be removed from the NSS root certificate store.

Wells Fargo has been transitioning away from this old hierarchy (to the WellsSecure hierarchy) and has indicated that this root no longer needs to be included in NSS.

Issuer:
CN = Wells Fargo Root Certificate Authority
OU = Wells Fargo Certification Authority
O = Wells Fargo
C = US

SHA1 Fingerprint: 93:E6:AB:22:03:03:B5:23:28:DC:DA:56:9E:BA:E4:D1:D1:CC:FB:65
Jason, Please confirm that the data in this bug is correct.
This information is correct, thank you.
Depends on: 911960
Please proceed with testing.

Important reminder:
At this phase, we change the NSS root CA list, which covers domain validation.

At this time, please test that your root has been correctly included and 
that trust flags are set correctly, and that connections to your test site work
with basic domain validation status.

If you have requested EV (extended validation), this is NOT yet enabled,
it will be done at a later time, in a separate bug.

The test build is available at
  http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-cdb68506e138/

Please download a binary for your preferred operating system, you probably want one of the following files:
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-e82a03006a30/try-linux/firefox-26.0a1.en-US.linux-i686.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-e82a03006a30/try-linux64/firefox-26.0a1.en-US.linux-x86_64.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-e82a03006a30/try-macosx64/firefox-26.0a1.en-US.mac.dmg
http://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/kaie@kuix.de-e82a03006a30/try-win32/firefox-26.0a1.en-US.win32.zip

(Only if the above link fails, you may use this backup location:
  https://kuix.de/mozilla/tryserver-roots-20130903/ )

Can a CA representative please verify the trust settings for correctness?

FYI: https://wiki.mozilla.org/CA:How_to_apply#Testing_Inclusion

(See also the initial comments in this bug.
 You should ensure that you're using a fresh profile,
 to make sure you really see the trust bits provided by this build,
 not trust settings that you had set manually in an application profile.
 To learn how to use a separate profile for testing, refer to
 http://support.mozilla.org/en-US/kb/profile-manager-create-and-remove-firefox-profiles
 or http://kb.mozillazine.org/Creating_a_new_Firefox_profile_on_Windows )
I have installed the test build and confirm that the "Wells Fargo Root Certificate Authority" root certificate has been removed, and that the "WellsSecure Public Root Certificate Authority" root certificate is still included with the websites trust bit set.

Jason, Do you also want to check this test build?
You can follow the instructions for testing here: 
https://wiki.mozilla.org/CA:How_to_apply#Testing_Inclusion
Verified, looks good. Thank you
done as part of bug 911960
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Target Milestone: --- → 3.15.4
You need to log in before you can comment on or make changes to this bug.