Request to add the French Government IGC/A CA root certificate to Mozilla
This case is a request to add the French Government IGC/A root certificate, operated by DCSSI, to Mozilla. The request began with a letter from the French Government asking Mozilla to include the root certificates, and the thread then gathered information about the CA’s policies, hierarchy, validation practices, and audit status. DCSSI provided details on CRL/ARL handling, subordinate CA structure, subscriber verification for email, SSL, and code signing, and links to the relevant French policy documents. Mozilla also asked for evidence of an acceptable audit and clarification of the CA’s practices, including whether private companies could operate subordinate CAs. After public discussion, Mozilla approved the request to add the IGC/A root certificate to NSS with email, SSL, and code-signing trust bits enabled, and the bug was then handed back for the final NSS tracking steps.
- French Government requested inclusion of the DCSSI root certificates in Mozilla.
- DCSSI reported CRL/ARL implementation and provided policy details for the IGC/A hierarchy.
- Mozilla approved adding the IGC/A root certificate to NSS with email, SSL, and code-signing trust bits.
- Mozilla representative — Opened the case after receiving a letter from the French Government requesting inclusion of the French Government CA root certificates.
- Mozilla representative — Asked DCSSI for the missing application details needed to continue the review.
- Free representative — Provided CA details, explained the hierarchy, and said the CA did not operate OCSP and had no CRLDP in the root certificates.
- Mozilla representative — Asked for clarification on email verification, audit requirements, and whether the summary of the root’s structure was correct.
- Free representative — Clarified that private companies were not signed as sub-CAs, explained email verification through the registration file, and said the CA was audited to WebTrust criteria.
- Free representative — Pointed Kathleen to the SSL validation text showing that the domain name in the certificate must belong to the represented entity.
- Mozilla representative — Summarized the assessment, including validation, audit, hierarchy, and CRL schedule, and recommended approval.
- Hecker representative — Approved the request to add the IGC/A root certificate to NSS with email, SSL, and code-signing trust bits enabled.
- Mozilla representative — Filed bug 477147 against NSS for the actual changes.