CA:Root Certificate Requests: Difference between revisions
Jump to navigation
Jump to search
(First draft of How-To guide for CAs) |
m (formatting fixes) |
||
Line 5: | Line 5: | ||
# If you don't already have an account with [https://bugzilla.mozilla.org Mozilla's bug and enhancement request tracking system bugzilla.mozilla.org], then [https://bugzilla.mozilla.org/createaccount.cgi register for an account]. | # If you don't already have an account with [https://bugzilla.mozilla.org Mozilla's bug and enhancement request tracking system bugzilla.mozilla.org], then [https://bugzilla.mozilla.org/createaccount.cgi register for an account]. | ||
# [https://bugzilla.mozilla.org/enter_bug.cgi?product=mozilla.org&component=CA%20Certificates Submit an Enhancement request bug] in the bug tracking system, requesting that your CA's root certs be added to Mozilla products. | # [https://bugzilla.mozilla.org/enter_bug.cgi?product=mozilla.org&component=CA%20Certificates Submit an Enhancement request bug] in the bug tracking system, requesting that your CA's root certs be added to Mozilla products. | ||
:The form for the Enhancement request should be filled out with these values: | |||
The form for the Enhancement request should be filled out with these values: | |||
<pre> | <pre> | ||
Reporter: (your account email address) | Reporter: (your account email address) | ||
Line 18: | Line 17: | ||
Description: (see below) | Description: (see below) | ||
</pre> | </pre> | ||
:In the Description box, copy and past the boilerplate shown below, and then fill it in with your CA's details. There is one section below requesting information about the CA itself, and one section that should be repeated for each of the Root CA certificates that you wish to have included in Mozilla products. Feel free to expand any answer area as needed. | |||
In the Description box, copy and past the boilerplate shown below, and then fill it in with your CA's details. There is one section below requesting | |||
information about the CA itself, and one section that should be repeated for each of the Root CA certificates that you wish to have included in Mozilla products. Feel free to expand any answer area as needed. | |||
<pre> | <pre> | ||
CA Details | CA Details | ||
Line 31: | Line 27: | ||
CA Summary: | CA Summary: | ||
[ A one Paragraph Summary of your CA, | [ A one Paragraph Summary of your CA, ] | ||
[ including the following: | [ including the following: ] | ||
[ - General nature (e.g., commercial, government, | [ - General nature (e.g., commercial, government, ] | ||
[ academic/research, nonprofit) | [ academic/research, nonprofit) ] | ||
[ - Primary geographical area(s) served | [ - Primary geographical area(s) served ] | ||
[ - Number and type of subordinate CAs | [ - Number and type of subordinate CAs ] | ||
Audit Type (WebTrust, ETSI etc.): [ ] | Audit Type (WebTrust, ETSI etc.): [ ] | ||
Line 56: | Line 52: | ||
include root certificates in the store, not intermediates.) | include root certificates in the store, not intermediates.) | ||
Certificate Name: [ a short name, 60 characters max, no ':' | Certificate Name: [ a short name, 60 characters max, no ':' ] | ||
Summary Paragraph: | Summary Paragraph: | ||
[ including the following: | [ including the following: ] | ||
[ - End entity certificate issuance policy, | [ - End entity certificate issuance policy, ] | ||
[ i.e. what you plan to do with the root | [ i.e. what you plan to do with the root ] | ||
Root certificate download URL (on CA website): | Root certificate download URL (on CA website): | ||
Line 68: | Line 64: | ||
Certificate SHA1 Fingerprint (in hexadecimal): | Certificate SHA1 Fingerprint (in hexadecimal): | ||
[ XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX ] | |||
Key size (for RSA, modulus length) in bits: [ ] | Key size (for RSA, modulus length) in bits: [ ] | ||
Line 98: | Line 94: | ||
[https:// ] | [https:// ] | ||
</pre> | </pre> | ||
# Submit your enhancement request and note the bug number. | # Submit your enhancement request and note the bug number. | ||
# Watch your email mailbox for email from bugzilla-daemon@mozilla.org containing additional requests for information. | # Watch your email mailbox for email from bugzilla-daemon@mozilla.org containing additional requests for information. |
Revision as of 09:40, 6 March 2008
If you are an official representative of a Certificate Authority and you wish to apply to have your CA's root certificate(s) included in Mozilla products, you should do these steps:
- Read through Mozilla CA certificate policy to determine if your CA is eligible and to learn all the requirements for the certificate to be included in Mozilla products
- If you don't already have an account with Mozilla's bug and enhancement request tracking system bugzilla.mozilla.org, then register for an account.
- Submit an Enhancement request bug in the bug tracking system, requesting that your CA's root certs be added to Mozilla products.
- The form for the Enhancement request should be filled out with these values:
Reporter: (your account email address) Product: mozilla.org Version: Other Component: CA Certificates Severity: Enhancement Platform: ALL OS: ALL Summary: Add (your CA name) Root Certificate Description: (see below)
- In the Description box, copy and past the boilerplate shown below, and then fill it in with your CA's details. There is one section below requesting information about the CA itself, and one section that should be repeated for each of the Root CA certificates that you wish to have included in Mozilla products. Feel free to expand any answer area as needed.
CA Details ---------- CA Name: [ ] Website URL: [http:// ] CA Summary: [ A one Paragraph Summary of your CA, ] [ including the following: ] [ - General nature (e.g., commercial, government, ] [ academic/research, nonprofit) ] [ - Primary geographical area(s) served ] [ - Number and type of subordinate CAs ] Audit Type (WebTrust, ETSI etc.): [ ] Auditor: [ ] Auditor Website URL: [http:// ] Audit Document URL(s): [http:// ] [http:// ] URL of certificate hierarchy diagram (if available): [http:// ] Certificate Details ------------------- (To be completed once for each root certificate; note that we only include root certificates in the store, not intermediates.) Certificate Name: [ a short name, 60 characters max, no ':' ] Summary Paragraph: [ including the following: ] [ - End entity certificate issuance policy, ] [ i.e. what you plan to do with the root ] Root certificate download URL (on CA website): [http:// ] [alternatively, paste a copy of the certificate in "PEM" format ] Certificate SHA1 Fingerprint (in hexadecimal): [ XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX ] Key size (for RSA, modulus length) in bits: [ ] Valid From (YYYY-MM-DD): [ ] Valid To (YYYY-MM-DD): [ ] CRL HTTP URL (if any): [http:// ] CRL issuing frequency for subordinate CA certificates: [ days ] CRL issuing frequency for subordinate EE certificates: [ days ] OCSP responder URL (if any): [http:// ] Class: [domain-validated, identity/organizationally-validated or EV ] Certificate Policy URL: [http:// ] CPS URL: [http:// ] Requested Trust Indicators: [ email and/or SSL and/or code signing ] URL of a sample website using a certificate chained to this root (if applying for SSL): [https:// ]
- Submit your enhancement request and note the bug number.
- Watch your email mailbox for email from bugzilla-daemon@mozilla.org containing additional requests for information.