Request to add Swisscom root CA certificate
This case is a request to add the Swisscom root CA certificate to Mozilla’s default trust store. The request was initiated after Swisscom, a CA in Switzerland, asked to have its root certificate included. The Mozilla CA Program reviewer (Frank Hecker) added Swisscom information to the CA certificate list and reviewed Swisscom’s accreditation and documentation, including that Swisscom completed independent audit using ETSI TS 101 456 criteria under Swiss government auspices (KPMG). The reviewer stated they were not aware of technical issues with Swisscom or its subordinate CAs and noted details about Swisscom’s certificate types, subscriber verification approach, and revocation information (CRLs and OCSP in test stage). After additional follow-up and questions being answered, the reviewer formally approved inclusion of Swisscom’s root CA certificate in NSS for Firefox and other Mozilla-based products. The bug was later marked resolved/fixed, with a note that Bug 347880 (for the actual cert addition to NSS) was resolved/fixed as well.
- Mozilla CA Program reviewer received and began processing a request to add the Swisscom root CA certificate.
- Reviewer reviewed additional Swisscom documentation and policy details relevant to Mozilla’s CA policy.
- Reviewer formally approved Swisscom’s root CA certificate for inclusion in NSS.
- Bug was marked resolved/fixed after the related NSS inclusion bug was resolved/fixed.
- Hecker representative — Hecker said he received a request from Swisscom Solutions to add a root CA certificate, added Swisscom info to the CA certificate list, and noted Swisscom’s successful accreditation based on ETSI TS 101 456.
- Hecker representative — Hecker provided more detail on Swisscom’s certificate types (Diamant, Saphir, Rubin), issuance/identity verification requirements, and that separate CP documents were planned.
- Hecker representative — Hecker stated he was not aware of technical issues, described Swisscom’s relevance to Mozilla users, subscriber verification requirements, and that Swisscom met minimum subscriber verification and passed an independent ETSI TS 101 456 audit (KPMG under Swiss Accreditation Service).
- Hecker representative — Hecker fixed the URL reference to Swisscom’s entry on his CA certificate list page.
- Hecker representative — Hecker added CRL and OCSP details from a Swisscom email, including CRL production frequency and an OCSP distribution point URL for later go-live.
- Hecker representative — Hecker apologized for the delay, said questions were answered and Swisscom appeared compliant, and formally approved inclusion of the Swisscom root CA certificate in NSS.
- Bolyard representative — Nelson noted Bug 347880 (for NSS cert inclusion) was resolved/fixed and marked this bug resolved/fixed as well.