D-TRUST request to add D-TRUST Root Class 3 CA 2 2009 and D-TRUST Root Class 3 CA 2 EV 2009
D-TRUST opened this bug to request Mozilla inclusion of two new root certificates: "D-TRUST Root Class 3 CA 2 2009" and "D-TRUST Root Class 3 CA 2 EV 2009". The request also asked to turn on the Websites trust bit for both roots and enable EV for the EV root. Mozilla staff gathered information about D-TRUST’s CP/CPS, CRLs, OCSP, validation practices, and audits over several years, and D-TRUST provided updated documents and test sites. In the public discussion phase, Mozilla noted that questions remained for D-TRUST to answer, and later stated an intent to approve the request. Mozilla then approved the inclusion request and filed follow-up NSS and PSM bugs for the actual changes.
- D-TRUST requested inclusion of two new root certificates for Mozilla trust stores.
- Mozilla opened public discussion for the two D-TRUST root certificates.
- Mozilla approved inclusion of both roots, with EV enabled for the EV root.
- D-Trust — D-TRUST reported that Firefox users saw an unknown issuer error for https://ssl.d-trust.net and asked Mozilla to add the relevant roots.
- Mozilla representative — Mozilla accepted the bug for information gathering and verification and asked for more details on CP/CPS, CRL, OCSP, and problematic practices.
- D-Trust — D-TRUST said it had canceled the 5-year SSL option, that no RA could perform validation under these roots, and that it did not offer SSL certs for IP addresses or internal domain names.
- Mozilla representative — Mozilla opened the first public discussion period for the two root certificates and asked D-TRUST to respond to questions in the discussion thread.
- Mozilla representative — Mozilla summarized the assessment and stated an intent to approve the request for both roots, websites trust, and EV for the EV root.
- Mozilla representative — Mozilla approved the request and said it would file the NSS and PSM bugs for the approved changes.
- D-Trust — D-TRUST said it was not issuing SSL certificates with Reserved IP Addresses or Internal Server Names at that time, but reserved the right to do so under the BR expiry limitation.