This is a draft document for public discussion. It reflects the personal opinions of the author, and does not necessarily represent the views of mozilla.org staff and the Mozilla Foundation.
Please post comments and questions to the netscape.public.mozilla.crypto newsgroup or the corresponding mozilla-crypto mailing list, or send them to the document author, Frank Hecker.
This section attempts to explain the rationales behind the specific CA certificate policy adopted by the Mozilla Foundation, and also attempts to address various questions about why Mozilla treats CA certificates in the way it does; it is primarily intended for people who have some level of knowledge about CAs, Public Key Infrastructures, and computer security issues in general.