Atos root inclusion request for Atos TrustedRoot 2011
This case is a request by Atos to add the “Atos TrustedRoot 2011” root certificate to Mozilla’s trusted root store and enable the websites, email, and code signing trust bits. Atos opened the bug in December 2011 and provided application materials including CA information, CPS, subscriber agreement, and sample certificates. Mozilla conducted information verification, requested clarifications about RA roles, audits, code-signing authorization checks, and IDN handling, and later moved the request into public discussion. During the review, Atos provided additional audit documentation, updated CPS information, noted an OCSP service port change, and responded to Mozilla CA Communications and public discussion action items. After the first discussion round, Mozilla required Atos to complete a Baseline Requirements audit and attach the audit statement, which Atos later did. Mozilla then opened a second public discussion, published an assessment summary, and stated an intent to approve the request. Mozilla approved inclusion of the root on 2013-11-14 and filed NSS bug 938814 for the actual product changes. The Bugzilla case is resolved FIXED, and a later comment notes that bug 1329223 was marked as a duplicate of this bug.
- Atos opened a request to add the Atos Trustcenter root CA to Mozilla’s trusted root CA list.
- Atos reported that its website was available with the correct SSL certificate at https://pki.atos.net/TrustedRoot/.
- Mozilla added the request to the queue for public discussion.
- Mozilla opened the first public discussion for inclusion of the “Atos TrustedRoot 2011” root certificate with all three trust bits.
- Mozilla closed the first discussion round and required Atos to complete a Baseline Requirements audit and attach the audit statement.
- Atos stated that it had completed a Baseline Requirements audit and updated OCSP behavior for non-issued serial numbers.
- Mozilla opened the second public discussion period for the request.
- Mozilla approved inclusion of “Atos TrustedRoot 2011” for websites, email, and code signing and filed NSS bug 938814 for implementation.
- Bug 1329223 was marked as a duplicate of this bug.
- Atos — Opened the bug requesting inclusion of the Atos root and attached CA information, noting the company name change from Atos Origin to Atos.
- Atos — Attached the Atos CPS.
- Atos — Attached the Atos Subscriber Agreement.
- Atos — Attached a client certificate sample.
- Atos — Attached a code-signing certificate sample.
- Atos — Said the website was now available with the correct SSL certificate.
- Mozilla representative — Said she planned to start information verification soon.
- Mozilla representative — Attached an initial CA information document and requested review of highlighted items needing clarification.
- Atos — Answered Mozilla’s questions about RA roles, annual audits, code-signing authorization checks, and planned IDN handling.
- Atos — Asked for the current status of the bug and whether more information was needed.
- Mozilla representative — Attached a completed CA information document.
- Mozilla representative — Said the request had been added to the queue for public discussion.
- Atos — Said he had attached the declaration of conformity from the annual ETSI audit.
- Atos — Attached the declaration of conformity document.
- Atos — Attached an updated CA information document.
- Atos — Reported that the OCSP service port had been changed from 2560 to 80 and that the update was reflected in the CA information document.
- Sealweb representative — Asked questions during public review about Atos’s email encryption key escrow and recovery service and subscriber identification for key recovery.
- Atos — Explained that only encryption keys are stored, that they are kept in an encrypted database, and that recovery uses a four-eyes process involving the key owner and a trust center employee.
- Sealweb representative — Acknowledged the answers and said the process appeared to use strong protection and dual control.
- Mozilla representative — Asked Atos to respond in the bug to action items from the January 10, 2013 CA Communication.
- Atos — Responded to the CA Communication, stating that Atos already complied with the proposed policy items, conformed to the Baseline Requirements for SSL issuance, had checked its certificate database, had stopped issuing SSL certificates for reserved IPs or internal names since 2013-01-01, and provided a test website URL.
- Atos — Asked whether there was a start date for the public discussion.
- Mozilla representative — Attached a completed information gathering document and asked Atos to confirm that the information was still current.
- Atos — Confirmed the information was still current and requested two small document changes, including adding a newly created client sub-CA.
- Mozilla representative — Attached an updated completed information gathering document.
- Mozilla representative — Opened the first public discussion period for inclusion of the root and enabling all three trust bits.
- Mozilla representative — Closed the first discussion round and set an action item requiring a Baseline Requirements audit and audit statement.
- Atos — Reported completion of the required actions, including a Baseline Requirements audit, updated CPS, a DQS statement, and an OCSP change so non-issued serial numbers no longer return “good.”
- Atos — Attached the ETSI audit document.
- Atos — Attached the DQS statement regarding public discussion impacts.
- Atos — Attached CPS version 1.6.
- Mozilla representative — Asked how to independently verify the ETSI certificate on the auditor’s website and where to find the new CPS version on the Atos website.
- Atos — Explained how to find the ETSI certificate on the DQS website and said CPS version 1.6 had been added to the Atos website.
- Atos — Said the English version of the ETSI certificate was now also available on the DQS website.
- Mozilla representative — Opened the second public discussion period for the request.
- Mozilla representative — Clarified the title of the new discussion thread.
- Mozilla representative — Posted Mozilla’s assessment summary and said she intended to approve inclusion of the root with all three trust bits.
- Mozilla representative — Approved the request on behalf of Mozilla for websites, email, and code signing.
- Mozilla representative — Said she had filed NSS bug 938814 for the actual changes.
- Mozilla representative — Attached a 2016 audit statement.
- Mozilla representative — Noted that bug 1329223 had been marked as a duplicate of this bug.