← Atos cases
Bugzilla #711366 Ca Certificate Root Program Root Inclusion Opened By Ca Single Ca Owner Public Discussion

Atos root inclusion request for Atos TrustedRoot 2011

RESOLVED FIXED Atos
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a request by Atos to add the “Atos TrustedRoot 2011” root certificate to Mozilla’s trusted root store and enable the websites, email, and code signing trust bits. Atos opened the bug in December 2011 and provided application materials including CA information, CPS, subscriber agreement, and sample certificates. Mozilla conducted information verification, requested clarifications about RA roles, audits, code-signing authorization checks, and IDN handling, and later moved the request into public discussion. During the review, Atos provided additional audit documentation, updated CPS information, noted an OCSP service port change, and responded to Mozilla CA Communications and public discussion action items. After the first discussion round, Mozilla required Atos to complete a Baseline Requirements audit and attach the audit statement, which Atos later did. Mozilla then opened a second public discussion, published an assessment summary, and stated an intent to approve the request. Mozilla approved inclusion of the root on 2013-11-14 and filed NSS bug 938814 for the actual product changes. The Bugzilla case is resolved FIXED, and a later comment notes that bug 1329223 was marked as a duplicate of this bug.

Model: gpt-5.4 Generated: 2026-09-06 11:09 UTC Confidence: 0.98 41 comments
Chronology
  1. Atos opened a request to add the Atos Trustcenter root CA to Mozilla’s trusted root CA list.
  2. Atos reported that its website was available with the correct SSL certificate at https://pki.atos.net/TrustedRoot/.
  3. Mozilla added the request to the queue for public discussion.
  4. Mozilla opened the first public discussion for inclusion of the “Atos TrustedRoot 2011” root certificate with all three trust bits.
  5. Mozilla closed the first discussion round and required Atos to complete a Baseline Requirements audit and attach the audit statement.
  6. Atos stated that it had completed a Baseline Requirements audit and updated OCSP behavior for non-issued serial numbers.
  7. Mozilla opened the second public discussion period for the request.
  8. Mozilla approved inclusion of “Atos TrustedRoot 2011” for websites, email, and code signing and filed NSS bug 938814 for implementation.
  9. Bug 1329223 was marked as a duplicate of this bug.
Thread Activity
  1. Atos — Opened the bug requesting inclusion of the Atos root and attached CA information, noting the company name change from Atos Origin to Atos.
  2. Atos — Attached the Atos CPS.
  3. Atos — Attached the Atos Subscriber Agreement.
  4. Atos — Attached a client certificate sample.
  5. Atos — Attached a code-signing certificate sample.
  6. Atos — Said the website was now available with the correct SSL certificate.
  7. Mozilla representative — Said she planned to start information verification soon.
  8. Mozilla representative — Attached an initial CA information document and requested review of highlighted items needing clarification.
  9. Atos — Answered Mozilla’s questions about RA roles, annual audits, code-signing authorization checks, and planned IDN handling.
  10. Atos — Asked for the current status of the bug and whether more information was needed.
  11. Mozilla representative — Attached a completed CA information document.
  12. Mozilla representative — Said the request had been added to the queue for public discussion.
  13. Atos — Said he had attached the declaration of conformity from the annual ETSI audit.
  14. Atos — Attached the declaration of conformity document.
  15. Atos — Attached an updated CA information document.
  16. Atos — Reported that the OCSP service port had been changed from 2560 to 80 and that the update was reflected in the CA information document.
  17. Sealweb representative — Asked questions during public review about Atos’s email encryption key escrow and recovery service and subscriber identification for key recovery.
  18. Atos — Explained that only encryption keys are stored, that they are kept in an encrypted database, and that recovery uses a four-eyes process involving the key owner and a trust center employee.
  19. Sealweb representative — Acknowledged the answers and said the process appeared to use strong protection and dual control.
  20. Mozilla representative — Asked Atos to respond in the bug to action items from the January 10, 2013 CA Communication.
  21. Atos — Responded to the CA Communication, stating that Atos already complied with the proposed policy items, conformed to the Baseline Requirements for SSL issuance, had checked its certificate database, had stopped issuing SSL certificates for reserved IPs or internal names since 2013-01-01, and provided a test website URL.
  22. Atos — Asked whether there was a start date for the public discussion.
  23. Mozilla representative — Attached a completed information gathering document and asked Atos to confirm that the information was still current.
  24. Atos — Confirmed the information was still current and requested two small document changes, including adding a newly created client sub-CA.
  25. Mozilla representative — Attached an updated completed information gathering document.
  26. Mozilla representative — Opened the first public discussion period for inclusion of the root and enabling all three trust bits.
  27. Mozilla representative — Closed the first discussion round and set an action item requiring a Baseline Requirements audit and audit statement.
  28. Atos — Reported completion of the required actions, including a Baseline Requirements audit, updated CPS, a DQS statement, and an OCSP change so non-issued serial numbers no longer return “good.”
  29. Atos — Attached the ETSI audit document.
  30. Atos — Attached the DQS statement regarding public discussion impacts.
  31. Atos — Attached CPS version 1.6.
  32. Mozilla representative — Asked how to independently verify the ETSI certificate on the auditor’s website and where to find the new CPS version on the Atos website.
  33. Atos — Explained how to find the ETSI certificate on the DQS website and said CPS version 1.6 had been added to the Atos website.
  34. Atos — Said the English version of the ETSI certificate was now also available on the DQS website.
  35. Mozilla representative — Opened the second public discussion period for the request.
  36. Mozilla representative — Clarified the title of the new discussion thread.
  37. Mozilla representative — Posted Mozilla’s assessment summary and said she intended to approve inclusion of the root with all three trust bits.
  38. Mozilla representative — Approved the request on behalf of Mozilla for websites, email, and code signing.
  39. Mozilla representative — Said she had filed NSS bug 938814 for the actual changes.
  40. Mozilla representative — Attached a 2016 audit statement.
  41. Mozilla representative — Noted that bug 1329223 had been marked as a duplicate of this bug.
Participants
Atos Community commenter Sealweb representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1782092 RESOLVED Ca Certificate Root Program Root Inclusion Self Assessment Cp Cps Document Opened 2022-07-28 · Closed 2023-08-01 · 82% similar
Add Atos Roots
#1427262 RESOLVED Ca Certificate Root Program Root Inclusion Audit Document Self Assessment Opened 2017-12-28 · Closed 2022-11-14 · 80% similar
Add DarkMatter Root Certificates
#711366 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2011-12-16 · Closed 2022-11-14 · 76% similar
Add Atos Trustcenter CA cert to trusted root CA cert list
#1925173 RESOLVED Ca Certificate Root Program Root Inclusion Audit Document Self Assessment Opened 2024-10-17 · Closed 2026-06-15 · 71% similar
Add Cybertrust Japan SecureSign Root CA16
#1479040 RESOLVED Root Inclusion Ca Certificate Root Program Opened 2018-07-27 · Closed 2024-12-03 · 71% similar
CERTISIGN ROOT CERTIFICATE AUTHORITY REQUEST
#1454977 RESOLVED Root Inclusion Public Discussion Opened By Ca Opened 2018-04-18 · Closed 2023-07-12 · 71% similar
Add ACIN Global Trusted Sign root certificate
#662259 RESOLVED Root Inclusion Opened 2011-06-06 · Closed 2022-11-14 · 70% similar
SG Trust services Root certificate
#369519 RESOLVED Ca Certificate Root Program Root Inclusion Remediation Tracking Opened 2007-02-06 · Closed 2022-11-14 · 70% similar
Add Certipost E-Trust root certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action