Deutsche Telekom Security GmbH root inclusion request for Deutsche Telekom Root CA 2
This case is a request to include the Deutsche Telekom Root CA 2 certificate in Mozilla products. It was opened by Lothar Eickholt of T-Systems/Deutsche Telekom and initially asked for root embedding in Firefox and other Mozilla software. Mozilla requested the missing CA information, including certificate URLs, CPS/CP documents, CRL details, audit information, and clarification about subordinate CAs and issuance practices. The CA provided the requested materials, confirmed the information was correct, and the request moved through Mozilla’s pending and public discussion stages. The thread also records that Mozilla asked for an auditor statement on the auditor’s own website, and that T-Systems later said it had obtained a WebTrust certification in addition to ETSI. The bug was eventually assigned to Kathleen Wilson for further information gathering and then for the discussion phase, but the thread does not record a final inclusion decision here.
- T-Systems opened a request to add Deutsche Telekom Root CA 2 for Mozilla products.
- Mozilla placed the request on the pending CA root certificate request list.
- Mozilla began collecting additional information about subordinate CAs, verification practices, and website usage.
- Mozilla opened the public discussion period for the request.
- Mozilla marked the info-gathering phase complete and returned the request for discussion.
- T-systems representative — Opened the bug and said the request was for root embedding in Mozilla software.
- Mozilla representative — Asked for the missing CRL URL, CRL frequency, and confirmation of the requested certificate capabilities.
- Mozilla representative — Said the request had been placed on the pending root certificate request list and asked T-Systems to confirm the information.
- T-systems representative — Confirmed that the CA information was correct.
- Mozilla representative — Asked T-Systems to have the ETSI certificate posted on the auditor’s own website.
- Mozilla representative — Opened an info-gathering document and asked about subordinate CAs, domain verification, email-certificate practices, and a website using the root.
- Mozilla representative — Said the info-gathering phase was complete and reassigned the request back for discussion.
- Hecker representative — Opened a one-week public discussion period and linked the mozilla.dev.tech.crypto forum.
- T-systems representative — Pointed readers to Mozilla’s schedule page and the DFN status page for progress updates.
- Hecker representative — Formally assigned the bug to Kathleen Wilson because she was actively working on it.