From MozillaWiki
Jump to: navigation, search

Mozilla's CA Certificate Program

Mozilla’s CA Certificate Program governs inclusion of root certificates in Network Security Services (NSS), a set of open source libraries designed to support cross-platform development of security-enabled client and server applications. The NSS root certificate store is not only used in Mozilla products such as the Firefox browser, but is also used by other companies in a variety of products.

Override Default Root Certificate Settings

Users of Mozilla products may override the default root certificate settings by either deleting the root certificate or by changing the trust bit settings of a root certificate.

Policy and Included CAs

  • Pending CAs Spreadsheet -- CAs who have applied for inclusion of their certificates in the Mozilla project Root CA store, and whose applications are pending. Also CAs who have applied to add trust bits or enable EV for certificates that are already included in Mozilla's Root CA store, and their applications are pending.

CA Communications

CA Community in Salesforce

Mozilla's CA Program has its own instance of Salesforce for managing the CA Program data. The Salesforce CA Community enables CAs to directly provide the data for all of the publicly disclosed and audited subordinate CAs chaining up to root certificates in Mozilla's program, and to also directly provide data about their revoked intermediate certificates. A Primary Point of Contact for each included CA will be given a Salesforce CA Communitylicense, so that each of the CAs in Mozilla's program can input, access, and update their intermediate certificate data directly in SalesForce.

Maintenance and Enforcement

How to Apply for Root Inclusion or Changes

  • Process Overview
  • How to Apply -- A guide for CAs wishing to include their certificate in Mozilla's Root CA store, and also a guide for CAs wishing to add trust bits or enable EV for a certificate that is already included in Mozilla's Root CA store.
  • Root Change Process -- How to request a change to a root certificate that is currently included in NSS. This includes the process for disabling or removing a root certificate from NSS.

Discussion forums

The following Mozilla public forums are relevant to CA evaluation and related issues. Note that each forum can be accessed either as a mailing list or a newsgroup (using an NNTP-newsreader or the Google Groups service).

  • Policy forum. This forum is used for discussions of Mozilla policies related to security in general and CAs in particular; among other things, it is the preferred forum for the public comment phase of CA evaluation.
  • Crypto forum. This forum is used for discussions of the NSS cryptographic library used in Firefox and other Mozilla-based products, as well as the PSM module that implements higher-level security protocols for Firefox, Note that this forum was previously used to discuss CA request, but such discussions should now be moved to the policy forum.
  • Security forum. This forum is used for discussions of Mozilla security issues in general. Crypto-related discussions should be moved to

Work in Progress


The following are templates created by Gerv Markham for use by the Mozilla representative(s) responsible for working on CA requests. Except as noted the templates are used in creating comments for the bug report associated with a CA request.


The following items are obsolete, and have been replaced by other links provided above.