Add SSL.com 2022 Client Root CA Certificates
SSL.com requested the addition of two 2022 Client Root CA certificates to NSS and the Mozilla root store. The roots were described as intended for S/MIME Server authentication, with the Email trust bit requested, and the request stated they would not be used for TLS issuance. SSL.com also stated it planned to migrate S/MIME issuance to subCAs chaining to these roots and referenced a CCADB case for inclusion. Mozilla asked SSL.com to provide end-user S/MIME certificates from these roots and to supply specific SPKI hashes. After public discussion, Mozilla recommended approving the request and Mozilla approved inclusion of the two specified email roots, with Mozilla noting it would file the NSS bug for the approved changes. The bug was resolved as FIXED.
- SSL.com submitted a request to include two 2022 Client Root CA certificates (Email trust) in NSS and the Mozilla root store.
- Mozilla requested end-user S/MIME certificates and related information from SSL.com for the proposed roots.
- Mozilla approved inclusion of the two SSL.com 2022 email roots and indicated it would file the NSS bug for the changes.
- The CA Program bug was resolved as FIXED.
- SSL.com — SSL.com requested addition of two 2022 Client Root CA certificates for S/MIME Server authentication with the Email trust bit enabled, stating they would not be used for TLS issuance and referencing a CCADB case and a self-assessment attachment URL.
- Mozilla representative — Mozilla asked SSL.com to attach end-user S/MIME certificates from these roots to the bug.
- Mozilla representative — Mozilla requested specific SPKIs for the proposed roots.
- SSL.com — SSL.com provided the requested SPKI hashes and verification commands.
- Mozilla representative — Mozilla noted public discussion began 3/21/2023 and was scheduled to end 5/2/2023, linking to a Google Groups thread.
- Mozilla representative — Mozilla recommended approving SSL.com's request and linked to a Mozilla dev-security-policy thread.
- Mozilla representative — On behalf of Mozilla, she approved SSL.com's request to include the SSL.com Client ECC Root CA 2022 (Email) and SSL.com Client RSA Root CA 2022 (Email) roots and stated she would file the NSS bug for the approved changes.
- Mozilla representative — She stated she filed bug #1839992 against NSS for the actual changes.