CA: Difference between revisions

(→‎Policy: Added links Policies)
m (Minor)
 
(15 intermediate revisions by the same user not shown)
Line 12: Line 12:
=== MRSP ===
=== MRSP ===
'''Mozilla Root Store Policy'''
'''Mozilla Root Store Policy'''
* [https://www.mozilla.org/projects/security/certs/policy/ Root Store Policy] (current stable version: 3.0)
* [https://www.mozilla.org/projects/security/certs/policy/ Root Store Policy] (current stable version: 3.1)


* [[CA/Root_Store_Policy_Archive|Root Store Policy Archive]]
* [[CA/Root_Store_Policy_Archive|Root Store Policy Archive]]
** Blog Posts Regarding Policy Updates  ([https://blog.mozilla.org/security/2025/03/12/enhancing-ca-practices-key-updates-in-mozilla-root-store-policy-v3-0/ MRSP v.3.0], [https://blog.mozilla.org/security/2023/09/13/version-2-9-of-the-mozilla-root-store-policy/ MRSP v.2.9], [https://blog.mozilla.org/security/2022/05/23/upgrading-mrsp-to-v-2-8/ MRSP v.2.8], [https://blog.mozilla.org/security/2021/04/26/mrsp-v-2-7-1/ MRSP v.2.7.1], [https://blog.mozilla.org/security/2020/07/09/reducing-tls-certificate-lifespans-to-398-days/ 398-day validity periods], [https://blog.mozilla.org/security/2019/12/11/announcing-version-2-7-of-the-mozilla-root-store-policy/ MRSP v.2.7], [https://blog.mozilla.org/security/2018/07/02/root-store-policy-updated/ MRSP v.2.6], [https://blog.mozilla.org/security/2017/09/07/mozilla-releases-version-2-5-root-store-policy/ MRSP v.2.5], [https://blog.mozilla.org/security/2017/04/04/mozilla-releases-version-2-4-ca-certificate-policy/ MRSP v.2.4], [https://blog.mozilla.org/security/2013/07/31/announcing-version-2-2-of-mozillas-ca-certificate-policy/ MRSP v.2.2])
** Blog Posts Regarding Policy Updates  ([https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1 MRSP v.3.1], [https://blog.mozilla.org/security/2025/03/12/enhancing-ca-practices-key-updates-in-mozilla-root-store-policy-v3-0/ MRSP v.3.0], [https://blog.mozilla.org/security/2023/09/13/version-2-9-of-the-mozilla-root-store-policy/ MRSP v.2.9], [https://blog.mozilla.org/security/2022/05/23/upgrading-mrsp-to-v-2-8/ MRSP v.2.8], [https://blog.mozilla.org/security/2021/04/26/mrsp-v-2-7-1/ MRSP v.2.7.1], [https://blog.mozilla.org/security/2020/07/09/reducing-tls-certificate-lifespans-to-398-days/ 398-day validity periods], [https://blog.mozilla.org/security/2019/12/11/announcing-version-2-7-of-the-mozilla-root-store-policy/ MRSP v.2.7], [https://blog.mozilla.org/security/2018/07/02/root-store-policy-updated/ MRSP v.2.6], [https://blog.mozilla.org/security/2017/09/07/mozilla-releases-version-2-5-root-store-policy/ MRSP v.2.5], [https://blog.mozilla.org/security/2017/04/04/mozilla-releases-version-2-4-ca-certificate-policy/ MRSP v.2.4], [https://blog.mozilla.org/security/2013/07/31/announcing-version-2-2-of-mozillas-ca-certificate-policy/ MRSP v.2.2])


* [[CA/Communications | CA Communications]] and their responses. Such communications may also set policy in advance of it being included in the Root Store Policy.
* '''[[CA/Communications | CA Communications]]''', CA Surveys and CA operator responses. Such communications may also set policy in advance of it being included in the Root Store Policy.
** Blog Posts Regarding CA Communications ([https://blog.mozilla.org/security/2020/05/08/may-2020-ca-communication/ May 2020], [https://blog.mozilla.org/security/2020/01/13/january-2020-ca-communication/ Jan. 2020], [https://blog.mozilla.org/security/2018/09/17/september-2018-ca-communication/ Sept. 2018], [https://blog.mozilla.org/security/2017/11/16/november-2017-ca-communication/ Nov. 2017], [https://blog.mozilla.org/security/2016/03/29/march-2016-ca-communication/ Mar. 2016], [https://blog.mozilla.org/security/2015/05/12/may-2015-ca-communication/ May 2015])  
** Posts Regarding CA Communications ([https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/vwL-HwhElps/m/sYUZC3UHBwAJ June 2026], [https://blog.mozilla.org/security/2020/05/08/may-2020-ca-communication/ May 2020], [https://blog.mozilla.org/security/2020/01/13/january-2020-ca-communication/ Jan. 2020], [https://blog.mozilla.org/security/2018/09/17/september-2018-ca-communication/ Sept. 2018], [https://blog.mozilla.org/security/2017/11/16/november-2017-ca-communication/ Nov. 2017], [https://blog.mozilla.org/security/2016/03/29/march-2016-ca-communication/ Mar. 2016], [https://blog.mozilla.org/security/2015/05/12/may-2015-ca-communication/ May 2015])  


* [[CA/Updating_Root_Store_Policy|Process for updating the Root Store Policy]]
* [[CA/Updating_Root_Store_Policy|Process for updating the Root Store Policy]]
** [https://github.com/mozilla/pkipolicy/issues Root Store Policy Issue Tracker]
** [https://github.com/mozilla/pkipolicy/issues Root Store Policy Issue Tracker]
** [https://github.com/mozilla/pkipolicy/labels/3.1 Issues for next version (3.1) of Root Store Policy] (will become the next version)
** [https://github.com/mozilla/pkipolicy/labels/3.2 Issues for next version (3.2) of Root Store Policy] (will become the next version)


=== CCADB ===
=== CCADB ===
Line 35: Line 35:
== Lists of CAs and Certificates ==
== Lists of CAs and Certificates ==
* [https://www.ccadb.org/rootstores/usage#ccadb-data-usage-terms Data Usage Terms]
* [https://www.ccadb.org/rootstores/usage#ccadb-data-usage-terms Data Usage Terms]
* [[CA/Included_CAs|Included CAs]] (in the Root Program and in Firefox)
* [[CA/Included_CAs|Included CA Operators]] (in the Root Program and in Firefox)
* [[CA/Included_Certificates|Included CA Certificates]] (Roots)
* [[CA/Included_Certificates|Included CA Certificates]] (Roots)
* [[CA/Intermediate_Certificates|Intermediate Certificates]]
* [[CA/Intermediate_Certificates|Intermediate Certificates]]
Line 41: Line 41:
** [https://blog.mozilla.org/security/2020/11/13/preloading-intermediate-ca-certificates-into-firefox/ Preloading Intermediate CA Certificates into Firefox]
** [https://blog.mozilla.org/security/2020/11/13/preloading-intermediate-ca-certificates-into-firefox/ Preloading Intermediate CA Certificates into Firefox]
* [[CA/Removed_Certificates|Removed CA Certificates]]
* [[CA/Removed_Certificates|Removed CA Certificates]]
* [[NSS:Release_Versions|NSS Release Versions]] - shows in which version of Mozilla products each root certificate was first available
* [[NSS:Release_Versions#Root_Cert_Inclusions_into_Mozilla_Product_Releases|NSS Release Versions]] - shows in which version of Mozilla products each root certificate was first available
* [[CA/Additional_Trust_Changes| Additional Trust Policies ]] - describes trust policies enforced by PSM in Firefox and Thunderbird, but not represented in the NSS root store.
* [[CA/Additional_Trust_Changes| Additional Trust Policies ]] - describes trust policies enforced by PSM in Firefox and Thunderbird, but not represented in the NSS root store.


Line 48: Line 48:
Most information relating to the administration of our program is stored either in [https://bugzilla.mozilla.org/ Bugzilla] or in the [https://ccadb.org/ Common CA Database].
Most information relating to the administration of our program is stored either in [https://bugzilla.mozilla.org/ Bugzilla] or in the [https://ccadb.org/ Common CA Database].
* [[CA/Bug_Triage|Bugzilla Bug Triage Process]] - also lists whiteboard tags
* [[CA/Bug_Triage|Bugzilla Bug Triage Process]] - also lists whiteboard tags
* [[CA/Dashboard|Certificate Change Request Dashboard]] - tracks applications and trust changes through the process in Bugzilla
* [[CA/Dashboard|Certificate Change Request Dashboard]] - tracks inclusion requests and other trust changes in Bugzilla
* [[CA/Certificate_Change_Requests|Certificate Change Requests]] as tracked in the CCADB
* [[CA/Certificate_Change_Requests|Inclusion Requests]] as tracked in the CCADB
* [[CA/Incident_Dashboard|Incident and Compliance Dashboard]]
* [[CA/Incident_Dashboard|Incident and Compliance Dashboard]]
* [[CA/Maintenance_and_Enforcement#Issues_Lists|CA Issues Lists]]
* [[CA/Maintenance_and_Enforcement#Issues_Lists|CA Issues Lists]]
Line 83: Line 83:
* [[CA/Lessons_Learned| Lessons Learned]] - common compliance issues and proactive measures to prevent them
* [[CA/Lessons_Learned| Lessons Learned]] - common compliance issues and proactive measures to prevent them
* [[CA/Vulnerability_Disclosure|Disclosing a Vulnerability or Security Incident]]
* [[CA/Vulnerability_Disclosure|Disclosing a Vulnerability or Security Incident]]
=== Documentation ===
'''<span style="color:red;">New!</span>'''
* [[CA/CP-CPS_Guidance|CP/CPS Documentation Guidance]]
* [[CA/CPS-FAQs|CP/CPS Documentation FAQ]]
* [[CA/DCRs|Detailed Controls Reports Guidance]]
* [[CA/DCR-FAQs|Detailed Controls Reports FAQ]]


=== Root Inclusion ===
=== Root Inclusion ===
* [[CA/Root_Inclusion_Overview|Root Inclusion Overview]]
* [[CA/Prioritization|Prioritization Criteria for Processing Root Inclusion Requests]]  
* [[CA/Prioritization|Prioritization Criteria for Processing Root Inclusion Requests]]  
* [[CA/Application_Process|Application Process for Mozilla's Root Program]]
* [[CA/Application_Process|Application Process for Mozilla's Root Program]]
** [[CA/Information_Checklist|CA Information Checklist]]
* [[CA/Information_Checklist|CA Information Checklist]]
** [[CA/Quantifying_Value|Quantifying Value: Information Expected of New Applicants]]
* [[CA/Quantifying_Value|Quantifying Value: Information Expected of New Applicants]]
** [[CA/Compliance_Self-Assessment|Compliance Self Assessment]]
* [[CA/Root_Inclusion_Considerations|Root Inclusion Considerations]] -- Additional criteria to consider in adding or removing a root certificate
*** [[CA/CPS_Review|Previous reviews of CP/CPS documents]]
* [[CA/Compliance_Self-Assessment|Compliance Self Assessment]]
* [[CA/CPS_Review|Previous reviews of CP/CPS documents]]
* [[CA/Dashboard|Inclusion Requests - Bugzilla Dashboard]]


=== Subordinate CAs ===
* [[CA/Subordinate_CA_Checklist|Subordinate CA Information Checklist]]
* [[CA/Subordinate_CA_Checklist|Subordinate CA Information Checklist]]
* [[CA/External_Sub_CAs|Approval Process for Externally Operated Subordinate CAs]]  
* [[CA/External_Sub_CAs|Approval Process for Externally Operated Subordinate CAs]]
* [[CA/Root_Inclusion_Considerations|Root Inclusion Considerations]] -- This page is intended to be used as a tool for identifying when a CA Operator's root inclusion request should be denied, or when a CA's root certificate should be removed from Mozilla's root store.


=== Root Removal and Other Root Changes ===
=== Root Removal and Other Root Changes ===

Latest revision as of 16:02, 29 June 2026

Mozilla's CA Certificate Program

Mozilla’s CA Certificate Program governs inclusion of root certificates in Network Security Services (NSS), a set of open source libraries designed to support cross-platform development of security-enabled client and server applications. The NSS root certificate store is not only used in Mozilla products such as the Firefox browser, but is also used by other companies in a variety of products. The program is overseen by the module owner and peers of the CA Certificates Module; the policy itself is overseen by the module owner and peers of the CA Certificate Policy Module. Here are a few blog posts that describe the Mozilla CA Certificate Program in further detail:


Policy

MRSP

Mozilla Root Store Policy

CCADB

Common CA Database (CCADB)

Certificate Transparency

Lists of CAs and Certificates

Program Administration

Most information relating to the administration of our program is stored either in Bugzilla or in the Common CA Database.

crt.sh

Information for Auditors

Information for CAs

Compliance

Documentation

New!

Root Inclusion

Subordinate CAs

Root Removal and Other Root Changes

Revocation

How Firefox Works

Tools to Check Certificates

Certificate Linters

Information for the Public

Configuring Firefox


Discussion Forums

The following public forums are relevant to CA evaluation and related issues.

CCADB
MDSP
  • Mozilla's dev-security-policy (MDSP) mailing list is used for discussions of Mozilla policies related to security in general and CAs in particular, and for wider discussions about the WebPKI. If you are a regular participant in MDSP, then please add your name to the Policy Participants page.
Other MDSP Mail Archives
  • New MDSP Messages (since August 2021)

(HTML): https://www.mail-archive.com/dev-security-policy@mozilla.org/

(RSS): https://www.mail-archive.com/dev-security-policy@mozilla.org/maillist.xml

  • Old MDSP Messages (until April 2021)

(HTML): https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/

(RSS): https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/maillist.xml

Other Forums
  • Mozilla's dev-tech-crypto mailing list is used for discussions of the NSS cryptographic library used in Firefox and other Mozilla-based products, as well as the PSM module that implements higher-level security protocols for Firefox.
  • For other discussions of Mozilla security issues: