Atos TrustedRoot 2011 root inclusion request and public discussion
Atos requested that Mozilla add the Atos TrustedRoot Root CA certificate to the trusted root CA list and enable all three trust bits. The request included CA information, CPS, subscriber agreement, and supporting certificates, and Mozilla began information verification and public discussion. During the review, Atos provided clarifications about its CA hierarchy, annual audits, OCSP configuration, and subscriber validation practices, and later supplied updated CPS and audit documents. Mozilla opened a first and then a second public discussion period, and after the assessment Mozilla approved inclusion of the "Atos TrustedRoot 2011" root certificate for websites, email, and code signing. The bug was then resolved with the related NSS implementation tracked in bug 938814.
- Atos requested inclusion of the Atos TrustedRoot Root CA certificate in Mozilla’s trusted root CA list.
- Mozilla opened the first public discussion period for the Atos TrustedRoot 2011 root certificate.
- Mozilla opened the second public discussion period for the Atos TrustedRoot 2011 root certificate.
- Mozilla approved inclusion of the Atos TrustedRoot 2011 root certificate and all three trust bits.
- Atos — Atos asked Mozilla to add the Atos Trustcenter Root CA to the trusted root CA list and provided initial documentation and contact details.
- Atos — Atos answered questions about external RAs, annual audits, subscriber authorization for code signing, and IDN handling.
- Mozilla representative — Mozilla attached a completed CA information document and said the request had been added to the queue for public discussion.
- Atos — Atos responded to Mozilla’s CA Communication with statements about multi-factor authentication, CA hierarchy, Baseline Requirements compliance, and certificate database checks.
- Mozilla representative — Mozilla opened the first public discussion period for the Atos TrustedRoot 2011 root certificate.
- Mozilla representative — Mozilla closed the first discussion round and asked Atos to complete a Baseline Requirements audit and attach the audit statement.
- Atos — Atos said it had completed the Baseline Requirements audit, updated OCSP behavior, and attached the audit statement, CPS, and related documents.
- Atos — Atos said the ETSI certificate was available on the DQS website and that CPS version 1.6 had been added to the Atos website.
- Mozilla representative — Mozilla opened the second public discussion period for the request and corrected the discussion thread title.
- Mozilla representative — Mozilla posted its assessment summary and said it intended to approve the request.
- Mozilla representative — Mozilla approved inclusion of the Atos TrustedRoot 2011 root certificate and said it would file the NSS bug for the approved changes.
- Mozilla representative — Mozilla filed bug 938814 against NSS for the actual changes.