FNMT root inclusion request for SSL trust in Firefox
This case was opened by a third party who reported that Firefox did not trust certificates issued by FNMT for Spanish government sites. The reporter asked Mozilla to recognize FNMT as an SSL certificate authority so sites such as https://www.nic.es/ would load without the untrusted issuer error. Mozilla staff replied that inclusion requests must come from representatives of the CA itself, and the bug was first resolved as incomplete. The bug was later reopened when an FNMT representative asked how to proceed with root inclusion. Mozilla then pointed FNMT to the root CA inclusion guidance and the bug was ultimately closed as a duplicate of bug 435736, which was said to contain the full information.
- A user reported that Firefox did not trust FNMT-issued SSL certificates for Spanish government sites.
- An FNMT representative asked how to include the FNMT root certificate in Firefox.
- The bug was closed as a duplicate of bug 435736.
- Community commenter — Reported that https://www.nic.es/ showed a sec_error_untrusted_issuer and asked Mozilla to recognize FNMT SSL certificates.
- Bolyard representative — Said Mozilla only accepts CA inclusion requests from representatives of the CA itself, not third parties.
- Mozilla representative — Resolved the bug as incomplete and said it could be used as evidence of Mozilla's policy.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Stated that she belonged to FNMT and was trying to follow the steps to include FNMT's root certificate in Firefox.
- Community commenter — Reopened the bug because Cristina was from FNMT and was asking for the inclusion steps.
- Bolyard representative — Pointed FNMT to a wiki page describing how to apply for root CA certificate inclusion in Mozilla products.
- Community commenter — Said Cristina had opened bug 435736 with all the information and asked to close this bug.
- Johnath representative — Closed the bug as a duplicate of bug 435736.