entrust.net CA shows up as Verified by: "Trusted Secure Certificate Authority"
The bug was filed because the user believed the CA display name shown in Firefox (“Verified by: "Trusted Secure Certificate Authority"”) was misleading or insufficiently informative. The reporter argued that the CA name string did not clearly identify the responsible organization and that users would need to view certificates directly to get more information. Mozilla staff and other participants explained that the string “Trusted Secure Certificate Authority” comes from the issuer’s certificate fields (CN/O) and that PSM/NSS displays the issuing CA name rather than a Mozilla-applied “friendly name.” Participants noted that the issue may relate to the intermediate CA’s naming practices and suggested checking the CA’s CPS and/or discouraging such naming conventions. Frank Hecker concluded that this is not actually a Mozilla bug and closed the bug as INVALID, while indicating that the policy angle would be tracked by adding the practice to a list of “problematic practices.”
- A bug was opened alleging that Firefox displays a misleading CA name (“Verified by: Trusted Secure Certificate Authority”) for an entrust.net-related CA.
- Mozilla staff closed the bug as INVALID and noted a policy-tracking action for problematic CA naming practices.
- Jengr representative — Reported that Firefox shows “Verified by: "Trusted Secure Certificate Authority"” and argued the name is vague/misleading and should display the validating corporation.
- Johnath representative — Suggested that changing a “friendly name” would be an NSS-level change and that the question is a CA Certificates policy issue.
- Bolyard representative — Disagreed that this is a Mozilla “friendly name” issue, stating the displayed string is the issuer’s certificate name (CN/O).
- Startcom representative — Said the intermediate CA’s naming should be checked against its CPS and that such naming conventions should be discouraged and added to Mozilla CA Policy.
- Johnath representative — Acknowledged the issue is likely with enTrust rather than Mozilla and asked whether to close or track the policy question.
- Startcom representative — Proposed an alternative of always showing the root CA as the issuer, noting it would be a PSM issue.
- Jengr representative — Added a note about MD5 collision policy context and reiterated concern about the generic root certificate name.
- Hecker representative — Closed the bug as INVALID because it is not a Mozilla bug, and said he would add the practice to a list of “problematic practices” while rejecting showing the root CA as issuer.