This is a unofficial working document maintained in connection with evaluating CA requests to have certificates pre-loaded into Firefox and related Mozilla-based software. This document reflects the personal knowledge and opinions of the author; it is not an official publication of the Mozilla Foundation. The document is also incomplete: in particular, it does not contain information on "legacy" CAs already pre-loaded into Mozilla-based software prior to Firefox 1.0.
Please post comments, questions, and corrections to the mozilla.dev.tech.crypto newsgroup or the corresponding dev-tech-crypto mailing list, or send them to the document author, Frank Hecker.
When distributing Mozilla and related software the Mozilla Foundation includes with such software a default set of X.509v3 certificates for various Certification Authorities (CAs). The certificates included by default are marked as being "trusted" for various purposes, so that Mozilla can use them automatically to verify certificates for SSL servers, S/MIME email users, etc., without having to ask Mozilla users for further permission or information.
The table below provides information about CAs whose certificates are included in Mozilla, including
Version 0.45, August 8, 2006. Marked GeoTrusti and Swisscom as approved.
Version 0.44, August 4, 2006. Updated information for Geotrust.
Version 0.43, July 6, 2006. Added entry for SwissSign.
Version 0.42, July 5, 2006. Added entry for Trustis.
Version 0.41, July 5, 2006. Modified entry for Swisscom (added previously). Approved Firmaprofesional. Updated bug numbers for GRCA and StartCom.
Version 0.40, June 28, 2006. Added entry for Wells Fargo.
Version 0.39, June 22, 2006. Added entries for Firmaprofesional and KISA.
Version 0.38, June 9, 2006. Marked GRCA as approved, added entry for DigiNotar.
Version 0.37, June 7, 2006. Edited entry for GRCA, added entry for new GeoTrust CAs.
Version 0.36, May 24, 2006. Marked Startcom as approved. Added internal links for all entries.
Version 0.35, May 1, 2006. Updated entry for StartCom.
Version 0.34, March 22, 2006. Added WebTrust info for Quo Vadis.
Version 0.33, February 18, 2006. Correct newsgroup and mailing list names.
Version 0.32, January 25, 2006. Updated information for StartCom.
Version 0.31, August 15, 2005. Added entries for Digicert Sdn. Bhd. (Malaysia) (not to be confused with DigiCert Inc.), G-CA (Thailand), StartCom (Israel). Updated entries for DSV/S-TRUST, GRCA.
Version 0.30, May 26, 2005. Added entry for CAcert.
Version 0.29, April 12, 2005. Changed trust bits for various UTN CAs to match what was actually set.
Version 0.28, March 23, 2005. Approved Go Daddy.
Version 0.27, March 22, 2005. Added entries for Go Daddy and Certipost E-Trust.
Version 0.26, February 2, 2005. Approved NetLock.
Version 0.25, January 28, 2005. Added links to NetLock audit report.
Version 0.24, January 25, 2005. Added entry for NetLock.
Version 0.23, December 21, 2004. Approved Camerfirma, added entry for T-Systems.
Version 0.22, December 15, 2004. Approved XRamp, changed entry for Camerfirma to change trust bits and add OCSP information and CRLs for subordinate CAs.
Version 0.21, December 10, 2004. Added entries for ACCV, Camerfirma, GRCA, and XRamp.
Version 0.20, November 29, 2004. Added entry for SecureNet Certificates.
Version 0.19, November 24, 2004. Approved USERTrust, fixed URL for its CPS.
Version 0.18, November 24, 2004. Approved TDC.
Version 0.17, October 27, 2004. Updated documents and data for TDC OCES.
Version 0.16, October 20, 2004. Added USERTrust. Corrected information for DFN-PCA.
Version 0.15, September 28, 2004. Updated information for SECOM Trust.net.
Version 0.14, September 24, 2004. Marked QuoVadis, SECOM Trust.net, Sonera, and Staat der Nederlanden as approved and added references to the appropriate bugs. Also added a CRL URL for Staat der Nederlanden.
Version 0.13, September 23, 2004. Updated Sonera Class 1 CA to mark as trusted only for identifiying S/MIME email users, and fixed HTML errors preventing validation as HTML 4.01 Strict.
Version 0.12, September 23, 2004. Marked Sonera Class 1 and 2 CAs as trusted for all purposes, fixed link for Sonera CRL.
Version 0.11, September 22, 2004. Added DFN-PCA, Sonera, and Staat der Nederlanden (The Netherlands).
Version 0.10, September 18, 2004. Really marked Comodo as approved, and added SECOM Trust.net.
Version 0.9, August 4, 2004. Marked Comodo as approved, and added Additional bugs for Comodo and ipsCA.
Version 0.8, July 16, 2004. Added CRLs for Comodo. Fixed odd/even marking of table rows.
Version 0.7, July 8, 2004. Added ESnet.
Version 0.6, July 3, 2004. Added Comodo Group.
Version 0.5, May 27, 2004. Marked ipsCA as approved.
Version 0.4, May 11, 2004. Added new entries for ipsCA and QuoVadis.
Version 0.3, May 9, 2004. Modified entry for Unizeto to add new bug, added new entries for TC TrustCenter and TDC, added status field.
Version 0.2, April 26, 2004. Added new columns for CRL, OCSP, and trust information, and changed format of table.
Version 0.1, April 16, 2004. Initial draft to test format.