S-TRUST root inclusion request for authentication and encryption root
This case was an application by Deutscher Sparkassen Verlag GmbH (S-TRUST) to add root certificates to Mozilla’s trust store. The request initially covered multiple S-TRUST roots, including qualified roots and the S-TRUST Authentication and Encryption Root CA 2005:PN. Mozilla reviewers asked for CPS details, validation procedures, CRL/OCSP information, example certificates, and clarification about the yearly qualified roots. Over time, S-TRUST clarified that the rolling qualified roots were no longer being sought for Mozilla inclusion, and the request was narrowed to the authentication and encryption root. Mozilla then approved inclusion of S-TRUST Authentication and Encryption Root CA 2005:PN with email trust enabled, and the bug was handed off for NSS implementation and final closure.
- S-TRUST requested Mozilla CA Program admission for its root certificates.
- Mozilla collected detailed CA and certificate information for the S-TRUST roots.
- S-TRUST said it would add an email-address verification code to the certificate download process.
- Mozilla received example certificates and a completed information-gathering document.
- Mozilla recommended approval only for S-TRUST Authentication and Encryption Root CA 2005:PN.
- Mozilla approved inclusion of S-TRUST Authentication and Encryption Root CA 2005:PN in NSS with email trust enabled.
- Dsv-gruppe representative — S-TRUST opened the request and asked for Mozilla CA Program admission for its roots.
- Mozilla representative — Mozilla asked S-TRUST to provide a structured list of CA and certificate details for each root requested.
- Dsv-gruppe representative — S-TRUST provided CRL and OCSP values and said the correct MIME type was set for its CA certificates.
- Dsv-gruppe representative — S-TRUST said it would implement an email-address verification code before certificate issuance.
- Mozilla representative — Mozilla resolved the bug INCOMPLETE and asked S-TRUST to reopen it when updated CP/CPS documents were available.
- Hecker representative — Mozilla updated the pending list entry for S-TRUST and asked S-TRUST to verify the information.
- Dsv-gruppe representative — S-TRUST answered questions about subordinate CAs, cross-signing, example certificates, and the updated email verification procedure.
- Hecker representative — Mozilla started the one-week public discussion period for the request.
- Mozilla representative — Kathleen Wilson summarized the assessment and recommended approval only for S-TRUST Authentication and Encryption Root CA 2005:PN.
- Hecker representative — Mozilla approved the request to add S-TRUST Authentication and Encryption Root CA 2005:PN to NSS with email trust enabled.
- Mozilla representative — Kathleen Wilson filed bug 478573 against NSS for the actual changes.