SwissSign request to add three G2 root CA certificates to Mozilla
This case is SwissSign AG’s request to have its G2 root CA certificates added to Mozilla’s root store. The request covered three roots: SwissSign Platinum CA - G2, SwissSign Gold CA - G2, and SwissSign Silver CA - G2. The thread focused on providing CA details, CP/CPS documents, audit information, and clarifying what certificate types each hierarchy issued, especially SSL server certificates and domain validation practices. Mozilla reviewers asked follow-up questions about the audit evidence, domain ownership verification, and the split of the Platinum CP/CPS into separate documents for the root and subordinate CAs. After public discussion, the request was approved, bug 407396 was opened to add the certificates to NSS, and this bug was later resolved FIXED.
- SwissSign G2 root CA inclusion request was opened for three new root certificates.
- Mozilla announced intent to approve inclusion of the three SwissSign root CAs after review.
- Mozilla approved the three SwissSign CA certificates and opened bug 407396 to add them to NSS.
- Bug 407396 was resolved FIXED, and this bug was closed FIXED as well.
- Hecker representative — Frank Hecker opened the bug and said SwissSign was another public CA based in Switzerland.
- Mozilla representative — Gerv asked for a contact email address because the SwissSign entry showed audit as TBD.
- Mozilla representative — Gerv requested additional CA details, certificate details, and operational information in plain text.
- SwissSign AG — Patrick Michel supplied direct download URLs, explained the move away from the older root, and described the planned certificate types.
- Mozilla representative — Gerv said the Gold and Silver roots looked suitable for inclusion but asked about the Platinum CP/CPS and a hierarchy diagram.
- Hecker representative — Frank Hecker said the Platinum subordinate procedures satisfied Mozilla requirements for email and code signing, but he still needed clarification on SSL domain verification.
- SwissSign AG — Melanie Raemy explained that Platinum would not issue SSL server certificates, confirmed Gold would include SSL, and said Silver did issue SSL certificates.
- Hecker representative — Frank Hecker posted his assessment and said he intended to approve inclusion of the three SwissSign root CAs after public discussion.
- SwissSign AG — Melanie Raemy provided a public URL to the audit confirmation letter from SwissSign.
- Hecker representative — Frank Hecker said the public comment period had ended and that, absent objection, he would officially approve inclusion the next day.
- Hecker representative — Frank Hecker approved the three SwissSign CA certificates for inclusion and opened bug 407396 for the NSS addition.
- Hecker representative — Frank Hecker resolved this bug FIXED after bug 407396 was resolved FIXED.