<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="pending.xsl"?>

<certificates type="pending">
  <authority name="ACCV" url="http://www.pki.gva.es/"  status="complete">
    <summary>
      ACCV (Autoritat de Certificacio de la Comunitat Valenciana) is 
      a CA operated by the government of the Valencia region of Spain.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.ssiconsultores.com/">
        Seguridad y Sistemas de Informacion S.L.</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=571&amp;file=pdf">
        Informe de Auditoria Independiente</document>
    </audit>

    <certificate name="Root CA Generalitat Valenciana" status="complete">
      <summary>
      </summary>
      <data url="http://www.pki.gva.es/gestcert/rootca.crt"
            version="3"
            sha1="A0:73:E5:C5:BD:43:61:0D:86:4C:21:13:0A:85:58:57:CC:9C:EA:46"
            modulus="2048"
            from="2001-07-06"
            to="2021-07-01">
      </data>
      <crl url="http://www.pki.gva.es/gestcert/rootgva_der.crl">CRL</crl>
      <ocsp>http://ocsp.pki.gva.es/</ocsp>
      <type>DV, IV</type>
      <document url="http://www.accv.es/pdf-politicas/ACCV-CPS-V1.7-v.pdf">
        Declaracion de Practicas de Certificacion (CPS) de la ACCV, v1.7 in Spanish
      </document>
      <document url="http://www.pki.gva.es/legislacion_c.htm">
        Certification policies and practices for the different types of certs (Spanish)
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=274100</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="KISA" url="http://www.rootca.or.kr/" status="pending">
    <summary>Korea Information Security Agency (KISA) is the
      Electronic Signature Authorization Management Center for South
      Korea. The Korean Certification Authority Central (KCAC) of KISA
      issues certificates to six (6) intermediate CAs ("licensed CAs"
      or LCAs), which then issue end entity certificates to Korean
      citizens, businesses, and other organizations.</summary>
    <audit type="Government (WebTrust equivalent)">
      <auditor url="http://www.mic.go.kr/">Ministry of Information and Communication, Republic of Korea</auditor>
      <document url="http://eng.mic.go.kr/eng/user.tdf?a=common.HtmlApp&amp;c=1001&amp;page=resources/resources_f_01.html&amp;mc=E_04_06">Public statement by MIC re KISA/KCAC audit</document>
    </audit>

    <certificate name="CertRSA01" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root is apparently being phased out in favor of the KISA
        RootCA 1.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa.der"
            version="3"
            sha1="F5:C2:7C:F5:FF:F3:02:9A:CF:1A:1A:4B:EC:7E:E1:96:4C:77:D7:84"
            modulus="2048"
            from="2000-03-03"
            to="2010-03-03"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-2459.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure (Korean)</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 1" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root CA is replacing CertRSA01.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa-3280.der"
            version="3"
            sha1="02:72:68:29:3E:5F:5D:17:AA:A4:B3:C3:E6:36:1E:1F:92:57:5E:AA"
            modulus="2048"
            from="2005-08-24"
            to="2025-08-24"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-3280.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 3" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
LCAs (Licensed CAs), not directly to end entities.</summary>
      <data url="http://www.rootca.or.kr/certs/root-wrsa.der"
            version="3"
            sha1="5F:4E:1F:CF:31:B7:91:3B:85:0B:54:F6:E5:FF:50:1A:2B:6F:C6:CF"
            modulus="2048"
            from="2004-11-19"
            to="2014-11-19"/>
      <crl url="http://www.rootca.or.kr/certs/root-wrsa.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <comments></comments>
  </authority>

  <authority name="S-TRUST" url="https://www.s-trust.de/" status="complete">
    <summary>Deutscher Sparkassen Verlag GmbH is the world's largest
      smartcard provider and the central certification service
      provider for all German savings banks. This CA exists to enable
      up to 40 million German customers (end-users) to use their
      banking card as a certificate based signature, encryption and
      authentication device.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6701UE.pdf">
      ETSI TS 101.456 Certificate</document>
    </audit>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6702UE.pdf">
      ETSI TS 102.042 Certificate</document>
    </audit>
    <certificate name="S-TRUST Qualified Root CA 2008-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate1/ordner_crt_dateien/S-TRUSTQualifiedRootCA2008-00l_v3_509.crt"
            version="3"
            sha1="C9:2F:E6:50:DB:32:59:E0:CE:65:55:F3:8C:76:E0:B8:A8:FE:A3:CA"
            modulus="2048"
            from="2007-12-31"
            to="2012-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2008001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
    <certificate name="S-TRUST Qualified Root CA 2007-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/STRUSTQualifiedRootCA2007-001.crt"
            version="3"
            sha1="7A:3C:1B:60:2E:BD:A4:A1:E0:EB:AD:7A:BA:4F:D1:43:69:A9:39:FC"
            modulus="2048"
            from="2006-12-31"
            to="2011-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2007001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
    <certificate name="S-TRUST Qualified Root CA 2006-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/S-TRUST_Qualified_Root_CA_2006-001_PN.crt"
            version="3"
            sha1="7D:DC:76:1C:FD:AF:4C:E0:3A:B5:3A:DD:C9:FA:13:35:19:A3:DE:C9"
            modulus="2048"
            from="2005-12-31"
            to="2010-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2006001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
  </authority>

  <authority name="Austrian TCC" url="http://www.signatur.rtr.at/"      status="complete">
    <summary>The Telekom-Control Commission is the Austrian supervisory authority for electronic signatures. Its
responsibility includes supervision of all certification service providers
established in Austria. For every CA key used by an
Austrian certification service provider, the TKK issues a certificate to the
certification service provider. Based on these certificates, all certificates
issued by supervised Austrian certification service providers can be verified.
There are five subordinate CAs, each of which issues certificates for a different purpose.
</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.a-sit.at/">Secure Information Technology Center - Austria</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=204776">Conformity Assessment Statement</document>
    </audit>

    <certificate name="Telekom-Control-Kommission Top 1" status="complete">
      <summary>The TKK issues certificates to certification service providers who are
supervised according to the Austrian Electronic Signatures Act.
The corresponding private keys of certification service
providers are used for issuing certificates to end entities (signatories).</summary>
      <data url="http://www.signatur.rtr.at/currenttop.cer"
            version="3"
            sha1="91:49:29:EE:C7:A0:21:B5:DA:49:1A:35:A5:98:4C:2C:F2:5B:C7:55"
            modulus="2048"
            from="2005-09-13"
            to="2010-09-13"/>
      <crl url="http://www.signatur.rtr.at/current.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>

      <document url="http://www.signatur.rtr.at/repository/tkk-cp-10-20020909-de.pdf">Certificate
      Policy</document>
      <document url="http://www.signatur.rtr.at/repository/tkk-cps-14-20060612-de.pdf">Certificate
      Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373174</authorisation>
        <technical></technical>
      </inclusion>
      <comments>CRL doesn't work in Firefox - bug 133191.</comments>
    </certificate>
  </authority>

  <authority name="VeriSign" url="http://www.verisign.com/" status="incomplete">
    <summary>VeriSign is a major commercial CA with worldwide
    operations and customer base.</summary>
    <audit type="WebTrust CA / WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=304&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>

    <certificate name="VeriSign Class 3 Public Primary Certificate Authority - G4" status="complete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. VeriSign is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=335538"
            version="3"
            sha1="22:D5:D8:Df:8F:02:31:D1:8D:F7:9D:B7:CF:8A:2D:64:C9:3F:6C:3A"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-4-11"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409235</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="VeriSign Universal Root Certification Authority" status="incomplete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=368998"
            version="3"
            sha1="36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484901</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="VeriSign Class 1 Public Primary Certification Authority" status="incomplete">
      <summary>
      This root CA (also known as PCA1-G1-SHA1) has Signature Algorithm SHA-1 With RSA Encryption. 
      This root will supersede the PCA1-G1 root that is already included in NSS, which has 
      Signature Algorithm MD2 With RSA Encryption.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375224"
            version="1"
            sha1="CE:6A:64:A3:09:E4:2F:BB:D9:85:1C:45:3E:64:09:EA:E8:7D:60:F1"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>DV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="VeriSign Class 2 Public Primary Certification Authority" status="incomplete">
      <summary>
      This root CA (also known as PCA2-G1-SHA1) has Signature Algorithm SHA-1 With RSA Encryption. 
      This root will supersede the PCA2-G1 root that is already included in NSS, which has 
      Signature Algorithm MD2 With RSA Encryption.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375223"
            version="1"
            sha1="57:F0:3D:CE:FB:45:69:4C:1C:25:E6:EE:A0:2C:43:D7:52:38:D3:C4"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>IV/OV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="VeriSign Class 3 Public Primary Certification Authority" status="incomplete">
      <summary>
      This root CA (also known as PCA3-G1-SHA1) has Signature Algorithm SHA-1 With RSA Encryption. 
      This root will supersede the PCA3-G1 root that is already included in NSS, which has 
      Signature Algorithm MD2 With RSA Encryption.
      The PCA3-G1 roots participate in the cross-signing scheme by which EV certs issued 
      under the VeriSign Class 3 Public Primary Certification Authority - G5 hierarchy may 
      chain up to existing VeriSign roots.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375222"
            version="1"
            sha1="A1:DB:63:93:91:6F:17:E4:18:55:09:40:04:15:C7:02:40:B0:AE:6B"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>OV, EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="A-Trust" url="https://www.a-trust.at/"               status="incomplete">
    <summary>a.trust is an accredited Trust Center in
  Austria issuing smartcard-based qualified certificates for Austrian citizens,
  to be used in eGovernment, etc.</summary>
    <!--
    <audit type="ETSI TS 101.456">
      <auditor url="http://signatur.rtr.at/en/index.html">Telekom Control Commission</auditor>
      <document url="http://www.signatur.rtr.at/en/providers/providers/atrust.html">A-Trust entry on TCC website</document>
    </audit>
    -->

    <certificate name="A-Trust-Qual-01" status="complete">
      <summary>The intermediate CAs below this CA issue only qualified smartCard-based certificates
      to a natural person after a face-to-face identification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-01a.crt"
            version="3"
            sha1="E6:19:D2:5B:38:0B:7B:13:FD:A3:3E:8A:58:CD:82:D8:A8:8E:05:15"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="A-Trust-Qual-02" status="complete">
      <summary>The intermediate CAs below this CA issue qualified smartCard-based certificates to a natural person after a face-to-face identification,
   smartCard-based certificates to a natural person after a face-to-face identification (eg.: email), and
   server certificates (eg. SSL) after domain-verification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-02a.crt"
            version="3"
            sha1="67:9A:4F:81:FC:70:5D:DE:C4:19:77:8D:D2:EB:D8:75:F4:C2:42:C6"
            modulus="2048"
            from="2004-12-02"
            to="2014-12-02"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-02">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
      <comment>Presumably the sub-CA for which they have given a CP/CPS is only signed by one of these four...</comment>
    </certificate>

    <certificate name="A-Trust-nQual-01" status="complete">
      <summary>The intermediate CAs below this CA issue smartCard-based certificates to a natural person after a face-to-face identification (eg.: email),
   software certificates (pKCS#12), and
   server certificates (eg. SSL) after domain-verification</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-01a.crt"
            version="3"
            sha1="51:A4:4C:28:F3:13:E3:F9:CB:5E:7C:0A:1E:0E:0D:D2:84:37:58:AE"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="A-Trust-nQual-03" status="complete">
      <summary>The intermediate CAs below this CA issue smartCard-based certificates to a natural person after a face-to-face identification (eg.: email),
   software certificates (pKCS#12), and
   server certificates (eg. SSL) after domain-verification</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-03.crt"
            version="3"
            sha1="D3:C0:63:F2:19:ED:07:3E:34:AD:5D:75:0B:32:76:29:FF:D5:9A:F2"
            modulus="2048"
            from="2005-08-17"
            to="2015-08-17"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-03">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="ARGE DATEN" url="http://www.a-cert.at/"              status="incomplete">
    <summary>ARGE DATEN, the Austrian Society for Data Protection is a non-profit
    non-governmental organisation. It is the Austrian market leader
in issuing certificates for eBilling. It operates subordinate CAs for eBilling,
SSL Server Certificates, SSL Client Certificates, and members of
governmental institutions.</summary>
<!--
    <audit type="Government">
      <auditor url="http://www.rtr.at/">Rundfunk und Telekom Regulierungs GmbH</auditor>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-globaltrust.html">GLOBALTRUST Audit</document>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-a-cert-advanced.html">A-CERT ADVANCED Audit</document>
      <document url="http://www.globaltrust.info/static/third-party-audits.pdf">List of Third Party Audits</document>
    </audit>
-->

    <certificate name="A-CERT ADVANCED" status="complete">
      <summary>This root certificate issues both end-user certificates and CA certificates.
      It is the current root certificate of ARGE DATEN.</summary>
      <data url="http://www.a-cert.at/static/a-cert-advanced.crt"
            version="3"
            sha1="29:64:B6:86:13:5B:5D:FD:DD:32:53:A8:9B:BC:24:D7:4B:08:C6:4D"
            modulus="2048"
            from="2004-10-23"
            to="2011-10-23"/>
      <crl url="http://www.a-cert.at/static/advanced.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.a-cert.at/static/a-cert-certificate-policy-english.pdf">A-CERT Certificate Policy v1.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="GLOBALTRUST" status="complete">
      <summary>This root certificate will not directly issue end-user certificates. It is used
      to issue the subordinate CA certificates which in turn issue the end-user
      certificates. This certificate is the
      successor to the A-CERT ADVANCED root certificate.</summary>
      <data url="http://www.globaltrust.info/static/globaltrust2006.crt"
            version="3"
            sha1="34:2C:D9:D3:06:2D:A4:8C:34:69:65:29:7F:08:1E:BC:2E:F6:8F:DC"
            modulus="4096"
            from="2006-08-07"
            to="2036-09-18"/>
      <crl url="http://www.globaltrust.info/static/globaltrust2006.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.globaltrust.eu/static/globaltrust-certificate-policy-english.pdf">GLOBALTRUST Certificate Policy v1.2</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Trustis" url="http://www.trustis.com/"               status="complete">
    <summary>Trustis is a commercial CA operating primarily in the UK and Europe.</summary>
    <audit type="WebTrust Equivalent">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.trustis.com/pki/fps/policy/T-TSC-AUDIT-KPMG%20FPS%20Audit%20Report.pdf">Audit
      Report and Management Assertions</document>
    </audit>
    <audit type="tScheme">
      <auditor url="http://www.tscheme.org/about/index.html">tScheme</auditor>
      <document url="http://www.tscheme.org/directory/trustis/index.html">tScheme Grant of Approval</document>
    </audit>

    <certificate name="Trustis FPS Root CA" status="complete">
      <summary></summary>
      <data url="http://www.trustis.com/roots/fps/certs/fpsroot.crt"
            version="3"
            sha1="3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04"
            modulus="2048"
            from="2003-12-23"
            to="2024-01-21"/>
      <crl url="http://www.trustis.com/pki/fps/crl/fpsder.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>IV</type>

      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-certificate-policy-v1.04.pdf">Trustis FPS Root CP v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-PDS-v1.04.pdf">PKI Disclosure Statement v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/Trustis-Certification-Practice-Statement V1.1.pdf">Trustis CPS v1.1</document>

      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=324126</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Kamu SM" url="http://www.kamusm.gov.tr/" status="approved">
    <summary>Kamu Sertifikasyon Merkezi is the one government CA in Turkey
    that has authorization to issue certificates to
    government entities. They are also authorised to issue to commercial companies.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Information and Communications Technologies Authority (ICTA)</auditor>
      <document url="https://bug381974.bugzilla.mozilla.org/attachment.cgi?id=382453">ICTA statement of ETSI compliance</document>
    </audit>
    <certificate name="TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3" status="approved">
      <summary></summary>
      <data url="http://www.kamusm.gov.tr/BilgiDeposu/KOKSHS.v3.crt"
            version="3"
            sha1="1B:4B:39:61:26:27:6B:64:91:A2:68:6D:D7:02:43:21:2D:1F:1D:96"
            modulus="2048"
            from="2007-08-24"
            to="2017-08-21"/>
      <crl url="http://www.kamusm.gov.tr/BilgiDeposu/KOKSIL.v3.crl">CRL</crl>
      <ocsp>http://ocsp.kamusm.gov.tr</ocsp>
      <type>DV, IV</type>
      <document url="http://www.kamusm.gov.tr/BilgiDeposu/KSM_NES_SI/KSM_NES_SI.pdf">CP</document>
      <document url="http://www.kamusm.gov.tr/BilgiDeposu/KSM_NES_SUE/KSM_NES_SUE.pdf">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381974</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=499705</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Izenpe" url="http://www.izenpe.com/"    status="incomplete">
    <summary>Izenpe is owned by the government of the Basque country, Spain.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.bsi-global.com/">BSI Management Systems</auditor>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/acreditaciones/es_acredita/adjuntos/certificado_etsi.pdf">ETSI Certificate</document>
    </audit>
    <certificate name="Izenpe.com (Old Root)" status="incomplete">
      <summary>
        This is the original root, which is still needed. This root has four 
        internally-operated subordinate CAs. There are two sub-CAs for Qualified 
        certificates, one for Public Administration, and one for Citizens and Entities.  
        There are also two sub-CAs for non-Qualified certificates, one for Public 
        Administration and one for Citizens and Entities, which issue SSL Server, 
        Email, and Code Signing certs.
      </summary>
      <data url="https://servicios.izenpe.com/certificados/ca_raiz.crt"
            version="3"
            sha1="4A:3F:8D:6B:DC:0E:1E:CF:CD:72:E3:77:DE:F2:D7:FF:92:C1:9B:C7"
            modulus="2048"
            from="2006-01-31"
            to="2018-01-31"/>
      <crl url="http://crl.izenpe.com/cgi-bin/crl">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>OV</type>
      <document url="https://servicios.izenpe.com/jsp/descarga_ca/s27descarga_ca_c.jsp">CA Hierarchy</document>
      <document url="http://www.izenpe.com/cps">Links to CPS in Spanish, Basque, and English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/adjuntos/DPC%204.3%20ingles.pdf">CPS in English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/informacion_juridica.html">Declaration of Practices for each type of certificate (Spanish and Basque)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="Izenpe.com (New Root, SHA-1)" status="incomplete">
      <summary>
       This is the new root, signed with SHA1. 
       This root has five internally-operated subordinate CAs. 
       One sub-CA issues EV SSL certs. Two of the sub-CAs are for Qualified certificates, 
       one for Public Administration, and one for Citizens and Entities.  There are also 
       two sub-CAs for non-Qualified certificates, one for Public Administration and one 
       for Citizens and Entities, which issue SSL Server, Email, and Code Signing certs.</summary>
      <data url="https://servicios.izenpe.com/certificados/RAIZ2007_CERTIFICATE_AND_CRL_SIGNING_SHA1_PEM.cer"
            version="3"
            sha1="30:77:9E:93:15:02:2E:94:85:6A:3F:F8:BC:F8:15:B0:82:F9:AE:FD"
            modulus="4096"
            from="2007-12-13"
            to="2037-12-13"/>
      <crl url="http://crl.izenpe.com/cgi-bin/arl2">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>OV, EV (Policy OID 1.3.6.1.4.1.14777.6.1.1)</type>
      <document url="https://servicios.izenpe.com/jsp/descarga_ca/s27descarga_ca_c.jsp">CA Hierarchy</document>
      <document url="http://www.izenpe.com/cps">Links to CPS in Spanish, Basque, and English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/adjuntos/DPC%204.3%20ingles.pdf">CPS in English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/informacion_juridica.html">Declaration of Practices for each type of certificate (Spanish and Basque)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="Izenpe.com (New Root, SHA-256)" status="incomplete">
      <summary>
       This is the new root, signed with SHA-256. 
       This root has five internally-operated subordinate CAs. 
       One sub-CA issues EV SSL certs. Two of the sub-CAs are for Qualified certificates, 
       one for Public Administration, and one for Citizens and Entities.  There are also 
       two sub-CAs for non-Qualified certificates, one for Public Administration and one 
       for Citizens and Entities, which issue SSL Server, Email, and Code Signing certs.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=301667"
            version="3"
            sha1="2F:78:3D:25:52:18:A7:4A:65:39:71:B5:2C:A2:9C:45:15:6F:E9:19"
            modulus="4096"
            from="2007-12-13"
            to="2037-12-13"/>
      <crl url="http://crl.izenpe.com/cgi-bin/arl2">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>OV, EV (Policy OID 1.3.6.1.4.1.14777.6.1.1)</type>
      <document url="https://servicios.izenpe.com/jsp/descarga_ca/s27descarga_ca_c.jsp">CA Hierarchy</document>
      <document url="http://www.izenpe.com/cps">Links to CPS in Spanish, Basque, and English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/adjuntos/DPC%204.3%20ingles.pdf">CPS in English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/informacion_juridica.html">Declaration of Practices for each type of certificate (Spanish and Basque)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TC TrustCenter" url="http://www.trustcenter.de/"     
             status="complete">
    <summary>
    TC TrustCenter GmbH  is a commercial company based in Germany, 
    with customers in all major regions of the world. TC TrustCenter 
    offers a variety of products and services including SSL Server 
    certificates and Email certificates.
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT Germany</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6707UE_s.pdf">ETSI TS 102.042 LCP Certificate</document>
    </audit>
    <certificate name="TC TrustCenter Class 1 CA" status="complete">
      <summary>
      This root has four internally-operated subordinate CAs which issue 
      certificates for email and SSL client authentication. 
      This root also has an externally-operated sub-CA which is used to issue
      certificates to company internal email users. 
      There are many customers who are using certificates chained to this 
      root for secure email with Thunderbird.
      </summary>
      <data url="http://www.trustcenter.de/certservices/cacerts/tcclass1-2011.der"
            version="3"
            sha1="72:0F:C1:5D:DC:27:D4:56:D0:98:FA:BF:3C:DD:78:D3:1E:F5:A8:DA"
            modulus="1024"
            from="1998-03-09"
            to="2011-01-01"/>
      <crl url="http://www.trustcenter.de/crl/v2/tcclass1.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass1.trustcenter.de/</ocsp>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
      <comments>This root will not be approved for inclusion.</comments>
    </certificate>
    <certificate name="TC TrustCenter Class 4 CA II" status="incomplete">
      <summary>This EV Root is being used to issue all types of certificates, 
      e.g. Email Security,SSL-Client-Authentication, SSL-Server, CodeSigning.
      </summary>
      <data url="http://www.trustcenter.de/media/class_4_ii.der"
            version="3"
            sha1="A6:9A:91:FD:05:7F:13:6A:42:63:0B:B1:76:0D:2D:51:12:0C:16:50"
            modulus="2048"
            from="2006-03-23"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_4_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass4-ii.trustcenter.de</ocsp>
      <type>EV (policy OID 1.2.276.0.44.1.1.1.4)</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
       <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=436467</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="TC TrustCenter Universal CA II" status="incomplete">
      <summary>This Root is being used to issue all types of certificates, 
      e.g. Email Security, SSL-Client-Authentication, SSL-Server, CodeSigning.
      </summary>
      <data url="http://www.trustcenter.de/media/Universal_CA-II.der"
            version="3"
            sha1="8C:C4:30:7B:C6:07:55:E7:B2:2D:D9:F7:FE:A2:45:93:6C:7C:F2:88"
            modulus="4096"
            from="2006-03-22"
            to="2030-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_universal_root_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcuniversal-ii.trustcenter.de</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
      <comments>This root was postponed. A new bug will need to be created when ready to submit an inclusion request for this root.</comments>
    </certificate>
  </authority>

  <authority name="QuoVadis" url="http://www.quovadis.bm/" status="pending">
    <summary>QuoVadis is a commercial CA, based in Bermuda and
    operating globally.  QuoVadis is a Qualified Certification
    Services Provider in Switzerland.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst &amp; Young
      (Technology and Security Risk Services)</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=612&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document
      url="http://www.seco.admin.ch/sas/00229/00251/00254/index.html?lang=en">Swiss
      Accreditation Service statement</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/">Ernst &amp; Young</auditor>
      <document
      url="https://bugzilla.mozilla.org/attachment.cgi?id=288529">CA-supplied
      auditor's letter re WebTrust EV audit</document>
    </audit>

    <certificate name="QuoVadis Root CA 2" status="complete">
      <summary>This root will be used for SSL/device certificates,
      including standard "organisation validated" certificates as well
      as EV certificates. The associated EV policy OID is
      1.3.6.1.4.1.8024.0.2.100.1.2.</summary>
      <data url="http://www.quovadis.bm/public/qvrca2.crt"
            version="3"
            sha1="CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7"
            modulus="4096"
            from="2006-11-24"
            to="2031-11-24"
            ev-oid="1.3.6.1.4.1.8024.0.2.100.1.2"/>
      <crl url="http://crl.quovadisglobal.com/qvrca2.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV, EV</type>
      <document url="https://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.8.pdf">QuoVadis
      Root CA2 CP/CPS v1.8</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403665</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418701</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list (per bug 365281). The present request is to
      enable this CA certificate for EV.</comments>
    </certificate>

  </authority>

<!--
  <authority name="" url="" status="incomplete">
    <summary></summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url=""
            version=""
            sha1=""
            modulus=""
            from=""
            to=""/>
      <crl url="">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url=""></document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation></authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
-->

<!--
  <authority name="Visa" url="http://www.visaca.com/"                   status="incomplete">
    <summary>Certificates used with this root will be used with various Visa
websites associated with Visa products and services. Our main website is
visa.com.</summary>
    <audit type="">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.pem"
            version="3"
            sha1=""
            modulus="2048"
            from="2005-06-27"
            to="2025-06-29"/>
      <crl url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.crl">CRL</crl>
      <ocsp><!- - none - -></ocsp>
      <type>DV, IV</type>

      <document url=""></document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380067</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Certificate is served with the wrong content-type</comments>
  </authority>

  <authority name="ANCERT" url="http://www.ancert.com/"                 status="incomplete">
    <summary>ANCERT is the Notary Agency of Certification in Spain. It issues
    electronic recognized certificates to persons, companies, public corporations
    and others according to the requirements of the current Spanish regulations.</summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="Ancert Notarial" status="incomplete">
      <summary></summary>
      <data url="http://www.ancert.com/?do=productos.getDocuments&amp;group=certificados_notariales&amp;option=personal&amp;id=163"
            version="3"
            sha1="C0:9A:B0:C8:AD:71:14:71:4E:D5:E2:1A:5A:27:6A:DC:D5:E7:EF:CB"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTNOT.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="Ancert General Council of Notaries" status="incomplete">
      <summary></summary>
      <data url="http://www.notariado.org/n_tecno/feren/archivos/ANCERTCGN.crt"
            version="3"
            sha1="11:C5:B5:F7:55:52:B0:11:66:9C:2E:97:17:DE:6D:9B:FF:5F:A8:10"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTCGN.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Cert 1 is a BIN file</comments>
  </authority>

-->

  <authority name="DigiCert" url="http://www.digicert.com/" status="pending">
    <summary>DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert
provides digital certification and identity assurance services internationally
to a variety of sectors including business, education, and government.</summary>
    <audit type="WebTrust">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=558&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://www.digicert.com/ev-final-webtrust-report.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="DigiCert High Assurance EV Root CA" status="complete">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt"
            version="3"
            sha1="5F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25"
            modulus="2048"
            from="2006-11-10"
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV (policy OID 2.16.840.1.114412.2.1)</type>
      <document url="http://www.digicert.com/DigiCert_CPS.pdf">DigiCert Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.6</document>
      <document url="http://www.digicert.com/DigiCert_EV-CPS.pdf">DigiCert Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403644</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=416827</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list. The present request is to enable this CA
      certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="Comodo" url="http://www.comodo.com/" status="incomplete">
    <summary>Comodo CA Ltd is a commercial CA based in the UK and
      serving customers worldwide. Comodo has eleven root CA certs
      already included in Mozilla, all of which it would like upgraded
      for EV use, and one additional EV root requested for
      inclusion. There are altogether 124 subordinate CAs signed by
      the root CAs listed below.  Some of them exist to differentiate
      between different Comodo brands or products and some are used to
      re-brand products for its partners. In each case Comodo retains
      the private key for the subordinate CA within its
      infrastructure.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=636&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.comodo.com/repository/ev_audit_report_and_management_assertions.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="AddTrust Class 1 CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustClass1CARoot.crt"
            version="3"
            sha1="CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustClass1CARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and code signing.</comments>
    </certificate>

    <certificate name="AddTrust External CA Root" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustExternalCARoot.crt"
            version="3"
            sha1="02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustExternalCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="AddTrust Public CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustPublicCARoot.crt"
            version="3"
            sha1="2A:B6:28:48:5E:78:FB:F3:AD:9E:79:10:DD:6B:DF:99:72:2C:96:E5"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustPublicCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and to enable all trust bits if not already
        enabled.</comments>
    </certificate>

    <certificate name="AddTrust Qualified CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustQualifiedCARoot.crt"
            version="3"
            sha1="4D:23:78:EC:91:95:39:B5:00:7F:75:8F:03:3B:21:1E:C5:4D:8B:CF"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustQualifiedCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="UTN - DATACorp SGC" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-DATACorpSGC.crt"
            version="3"
            sha1="58:11:9F:0E:12:82:87:EA:50:FD:D9:87:45:6F:4F:78:DC:FA:D6:D4"
            modulus="2048"
            from="1999-06-24"
            to="2019-06-24"/>
      <crl url="http://crl.comodoca.com/UTN-DATACorpSGC.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, code signing, and email.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Client Authentication and Email" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crt"
            version="3"
            sha1="B1:72:B1:A5:6D:95:F9:1F:E5:02:87:E1:4D:37:EA:6A:44:63:76:8A"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Hardware" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Hardware.crt"
            version="3"
            sha1="04:83:ED:33:99:AC:36:08:05:87:22:ED:BC:5E:46:00:E3:BE:F9:D7"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Hardware.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Object" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Object.crt"
            version="3"
            sha1="E1:2D:FB:4B:41:D7:D9:C3:2B:30:51:4B:AC:1D:81:D8:38:5E:2D:46"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Object.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, SSL, and email.</comments>
    </certificate>

    <certificate name="AAA Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AAACertificateServices.crt"
            version="3"
            sha1="D1:EB:23:A4:6D:17:D6:8F:D9:25:64:C2:F1:F1:60:17:64:D8:E3:49"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/AAACertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/November_2007_CPS_Amendment.pdf">November 2007 Addendum to the Comodo Certification Practice Statement v.3.0 (31 October 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_Intel_Pro.pdf">August 2007 Intel Pro SSL Addendum to the Comodo Certification Practice Statement v.3.0 (17 August 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_of_Version_3_UCC.pdf">March 2007 Unified Communications Addendum to the Comodo Certification Practice Statement v.3.0 (1 March 2007)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Secure Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/SecureCertificateServices.crt"
            version="3"
            sha1="4A:65:D5:F4:1D:EF:39:B8:B8:90:4A:4A:D3:64:81:33:CF:C7:A1:D1"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/SecureCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Trusted Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/TrustedCertificateServices.crt"
            version="3"
            sha1="E1:9F:E3:0E:8B:84:60:9E:80:9B:17:0D:72:A8:C5:BA:6E:14:09:BD"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/TrustedCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="Cisco" url="http://www.cisco.com/" status="incomplete">
    <summary>Cisco is a leading provider of networking equipment to
      consumers and businesses worldwide.
    </summary>

    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/">PricewaterhouseCoopers</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=728">Audit Report and Management Assertions</document>
    </audit>

    <certificate name="Cisco Root CA 2048" status="incomplete">

      <summary>This is an off-line root CA that issues CA certificates
        to one or more Cisco-controlled subordinate CAs (including the
        Cisco Manufacturing Sub-CA). The subordinate CAs in turn issue
        end entity certificates, e.g., for use in Cisco network
        equipment with embedded web servers and web-based
        administrative interfaces.
      </summary>
      <data url="http://www.cisco.com/security/pki/certs/crca2048.cer"
            version="3"
            sha1="DE:99:0C:ED:99:E0:43:1F:60:ED:C3:93:7E:7C:D5:BF:0E:D9:E5:FA"
            modulus="2048"
            from="2004-05-14"
            to="2029-05-14"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV</type>
      <document url="http://www.cisco.com/security/pki/policies/Certification_Practice_Statement_-_Cisco_Root_CA_2048_v1.1.doc">Cisco Root CA 2048
Certification Practice Statement, Version 1.1</document>
      <document url="http://www.cisco.com/security/pki/policies/Certificate_Policy_-_Cisco_Root_CA_2048_v1.0.doc">Cisco Root CA 2048 Certificate Policy, Version 1.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=416842</authorisation>
        <technical></technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Verizon / Cybertrust" url="http://www.verizonbusiness.com/us/products/security/identity/"                   status="complete">
    <summary>
      Verizon Business Security Solutions Powered by Cybertrust
      operates a commercial certificate authority service for
      businesses and governments internationally.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=799&amp;file=pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cybertrust.omniroot.com/repository/WT_EV_2008_SealFile.pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="GTE CyberTrust Global Root" status="complete">
      <summary>
        The request is to enable EV for this GTE CyberTrust Global Root 
        certificate, which is already included in NSS. This is presently
        Cybertrust's mainstream root, issuing their standard
        validation SSL server certificates, user authentication and
        secure email certificates, and code signing certificates. This
        root has existing subordinate CAs that are operated both
        internally and by third-parties. The sub-CAs are required to
        follow the CPS and to have regular audits. This CA will be
        superseded by the Baltimore CybertTrust Root.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=323777"
            version="1"
            sha1="97:81:79:50:d8:1c:96:70:cc:34:d8:09:cf:79:44:31:36:7e:f4:74"
            modulus="1024"
            from="1998-08-12"
            to="2018-08-13">
      </data>
      <crl url="http://www.public-trust.com/cgi-bin/CRL/2018/cdp.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV, EV (policy OID 1.3.6.1.4.1.6334.1.100.1)</type>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CP_v_2_3_cl.pdf"> Cybertrust CA Certificate Policy
      </document>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CPS_v_5_4.pdf"> Certification Practice Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=430694</authorisation>
        <technical></technical>
      </inclusion>
    <comments>During the public discussion it was decided that this root should not be enabled for EV. Therefore, the bug has been closed as won't fix.</comments>
    </certificate>
    <certificate name="Baltimore CyberTrust Root" status="pending">
      <summary>
        The request is to enable EV and add the Code Signing trust bit
        for the Baltimore CyberTrust Root certificate, which is already included 
        in NSS. This root will supersede Cybertrust's current
        mainstream root, GTE CyberTrust Global Root. When that
        happens, this root will have subordinate CAs that are operated
        both internally and by third-parties. The sub-CAs are required
        to follow the CPS and to have regular audits.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=323781"
            version="3"
            sha1="d4:de:20:d0:5e:66:fc:53:fe:1a:50:88:2c:78:db:28:52:ca:e4:74"
            modulus="2048"
            from="2000-05-12"
            to="2025-05-12">
      </data>
      <crl url="http://www.public-trust.com/cgi-bin/CRL/202501/cdp.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV, EV (policy OID 1.3.6.1.4.1.6334.1.100.1)</type>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CP_v_2_3_cl.pdf"> Cybertrust CA Certificate Policy
      </document>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CPS_v_5_4.pdf"> Certification Practice Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=430698</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="SSC" url="http://www.ssc.lt"  status="pending">
    <summary>
      SSC, Skaitmeninio Sertifkavimo Centras, is the Lithuanian Government accredited commercial CA issuing certificates to Government institutions, public services, businesses and citizens.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.ivpk.lt/main_en.php?cat=10&amp;gr=4">Information Society Development Committee Under The Government Of The Republic Of Lithuania
      </auditor>
      <document url= "http://www.ssc.lt/files/SSC%20CA%20Application%20to%20Trusted%20Root%20CA%20program.pdf">Statement of Compliance with ETSI TS 101.456</document>
      <document url= "http://epp.ivpk.lt/en/providers/">Lithuanian Government Qualified Certificate Service Provider</document>
    </audit>
    <certificate name="SSC Root CA A" status="complete">
      <summary>
        Root CA with four internally operated subordinate CAs: Class 1, Class 2, Qualified Class 3, and Qualified Class 3 VS.
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_a.crt"
            version="3"
            sha1="5a:5a:4d:af:78:61:26:7c:4b:1f:1e:67:58:6b:ae:6e:d4:fe:b9:3f"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-28">
      </data>
      <crl url="http://crl.ssc.lt/root-a/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="SSC Root CA B" status="complete">
      <summary>
        This Root CA is a special purpose CA that has no subordinate CAs. 
        Root B is used for single-root certificates (SSL, Code Signing, 
        OCSP, time stamping). 
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_b.crt"
            version="3"
            sha1="3e:84:d3:bc:c5:44:c0:f6:fa:19:43:5c:85:1f:3f:2f:cb:a8:e8:14"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-25">
      </data>
      <crl url="http://crl.ssc.lt/root-b/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="SSC Root CA C" status="complete">
      <summary>
        Root C serves as a backup CA for Roots A and B. Just in case either 
        of those two roots become unusable and become revoked. According to 
        the government project that SSC is involved in, Root C will have to 
        be tested in a specific project where they must demonstrate availability 
        of its CRL and OCSP services. The project will accept Root C only if it 
        is a FireFox built-in object. If Root A does get revoked and Root C gets 
        put into service, then Root C will have four internally operated subordinate 
        CAs: Class 1, Class 2, Qualified Class 3, and Qualified Class 3 VS.
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_c.crt"
            version="3"
            sha1="23:e8:33:23:3e:7d:0c:c9:2b:7c:42:79:ac:19:c2:f4:74:d6:04:ca"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-22">
      </data>
      <crl url="http://crl.ssc.lt/root-c/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Certicamara S.A." url="http://www.certicamara.com"  status="complete">
    <summary>
      Sociedad Cameral de Certificación Digital - Certicámara S.A. is a 
      commercial CA primarily serving Colombia and Andean Region
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.com">Deloitte and Touche
      </auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=750&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Certificado Empresarial Clase-A" status="incomplete">
      <summary>
        This is the orginal root which expires in 2011. Certicámara 
        requests that this root also be added to the NSS database 
        because they have a significant number of customers that use it, 
        and their certificates expire in 2010. End entity certificates 
        have been issued directly from this root, rather than using an 
        offline root and issuing certs through a subordinate CA. 
      </summary>
      <data url="http://www.certicamara.com/certicamara.crt"
            version="3"
            sha1="8b:1a:11:06:b8:e2:6b:23:29:80:fd:65:2e:61:81:37:64:41:fd:11"
            modulus="2048"
            from="2001-05-23"
            to="2011-05-23">
      </data>
      <crl url="http://www.certicamara.com/certicamara.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.certicamara.com/certificate_hierarchy_diagram.jpg">Certificate Hierarchy
      </document> 
      <document url="http://www.certicamara.com/templates/cc/images/dpc/DPC_Julio_de_2008.pdf">Certificate Policy
      </document>
      <document url="http://www.certicamara.com/index.php?option=com_content&amp;task=category&amp;sectionid=22">Declaration of Practices
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=401262</authorisation>
        <technical></technical>
      </inclusion>
      <comments>This root will not be approved for inclusion.</comments>
    </certificate>
  </authority>

  <authority name="GeoTrust" url="http://www.geotrust.com/" status="complete">
    <summary>GeoTrust is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=650&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="GeoTrust Primary Certificate Authority - G2" status="complete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. GeoTrust is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
        </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=294057"
            version="3"
            sha1="8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-11-04"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.1.1.pdf">GeoTrust Certification Practice Statement, Version 1.1.1</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409236</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="GeoTrust Primary Certification Authority - G3" status="incomplete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. 
        </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=368997"
            version="3"
            sha1="03:9E:ED:B8:0B:E7:A0:3C:69:53:89:3B:20:D2:D9:32:3A:4C:2A:FD"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.1.1.pdf">GeoTrust Certification Practice Statement, Version 1.1.1</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484899</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="thawte" url="http://www.thawte.com/" status="complete">
    <summary>thawte is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=527&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="thawte Primary Root CA - G2" status="complete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. thawte is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=335551"
            version="3"
            sha1="AA:DB:BC:22:23:8F:C4:01:A1:27:BB:38:DD:F4:1D:DB:08:9E:F0:12"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-11-04"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.thawte.com/guides/pdf/Thawte_CPS_3_7.1.pdf">thawte Certification Practice Statement, Version 3.7.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409237</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="thawte Primary Root CA - G3" status="incomplete">
      <summary>
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. 
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=369000"
            version="3"
            sha1="F1:8B:53:8D:1B:E9:03:B6:A6:F0:56:43:5B:17:15:89:CA:F3:6B:F2"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.thawte.com/guides/pdf/Thawte_CPS_3_7.1.pdf">thawte Certification Practice Statement, Version 3.7.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484903</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="ICP-Brasil" url="https://www.icpbrasil.gov.br/" status="incomplete">
    <summary>
       ICP Brasil (Infra-Estrutura de Chaves Públicas Brasileira) 
       is Brazil's National PKI created by the law Medida 
       Provisória nº 2.200-2 / 2001.
       ICP Certificates are used in all secure Brazilian government 
       sites, other Brazilian sites and by financial institutions. 
       ICP-Brazil has the only (V0 and V1) chain operated by the ITI.
    </summary>
    <audit type="Internal">
      <auditor url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp">ICP-Brasil Management Committee</auditor>
      <document
      url="http://acraiz.icpbrasil.gov.br/resolucoes/Resolucao%2049.pdf">Audit Committee Aproval</document>
    </audit>
    <certificate name="Autoridade Certificadora Raiz Brasileira" status="incomplete">
      <summary>
        Root cert used to secure Brazilian government and financial sites.
        This root has 8 subordinate CAs that are externally operated. 
      </summary>
      <data url="http://acraiz.icpbrasil.gov.br/CertificadoACRaiz.crt"
            version="3"
            sha1="8E:FD:CA:BC:93:E6:1E:92:5D:4D:1D:ED:18:1A:43:20:A4:67:A1:39"
            modulus="2048"
            from="2001-11-30"
            to="2011-11-30"/>
      <crl url="http://acraiz.icpbrasil.gov.br/LCRacraiz.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>Unkown</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342297">Subordinate CA Hierarchy</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342298">Audit Hierarchy</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/EstruturaIcp">Companies operating the subordinate CAs</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-04_-_v_2.0.pdf">ICP-Brasil Certificate Practices</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-01_-_v_3.0.pdf">AC-Raiz Certificate Practices</document>
      <document url=""></document>
      <document url=""></document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=438825</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="Autoridade Certificadora Raiz Brasileira v1" status="incomplete">
      <summary>
        This is the next version of the Autoridade Certificadora 
        Raiz Brasileira root, which is used to secure Brazilian 
        government and financial sites.
      </summary>
      <data url="http://acraiz.icpbrasil.gov.br/ICP-Brasil.crt"
            version="3"
            sha1="70:5D:2B:45:65:C7:04:7A:54:06:94:A7:9A:F7:AB:B8:42:BD:C1:61"
            modulus="2048"
            from="2008-07-29"
            to="2021-07-29"/>
      <crl url="http://acraiz.icpbrasil.gov.br/LCRacraizv1.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>Unkown</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342297">Subordinate CA Hierarchy</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342298">Audit Hierarchy</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/EstruturaIcp">Companies operating the subordinate CAs</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-04_-_v_2.0.pdf">ICP-Brasil Certificate Practices</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-01_-_v_3.0.pdf">AC-Raiz Certificate Practices</document>
      <document url=""></document>
      <document url=""></document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=438825</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="E-TUGRA" url="http://www.etugra.com.tr/" status="pending">
    <summary>
    E-TUGRA is the EBG Informatics Technologies and Services Corporation. 
    E-TUGRA is a privately held CA operating in Ankara, Turkey, with customers 
    from all geographic areas within Turkey. E-TUGRA has been certified as one 
    of the four authorized CAs that issues qualified certificates as well as 
    SSL and other types of certificates to public in Turkey.  
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Information and Communications Technologies Authority (ICTA)</auditor>
      <document url="http://www.e-tugra.com.tr/Portals/3/E-Tugra_audit_09.pdf">ICTA statement of ETSI compliance</document>
    </audit>
    <certificate name="EBG Elektronik Sertifika Hizmet Sağlayıcısı" status="pending">
      <summary>
      From this root CA E-TUGRA has issued two internally-operated subordinate 
      CAs. The Qualified Certificate (QC) subordinate CA issues certificates 
      for Digital Signing and Non-Repudiation (document and email signing). 
      The Non Qualified Certificate (NQC) subordinate CA (EBG Web Sunucu 
      Sertifika Hizmet Sağlayıcısı) issues certificates for SSL, email 
      encryption, and code signing.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=380381"
            version="3"
            sha1="8c:96:ba:eb:dd:2b:07:07:48:ee:30:32:66:a0:f3:98:6e:7c:ae:58"
            modulus="4096"
            from="2006-08-17"
            to="2016-08-14"/>
      <crl url="http://crl.e-tugra.com.tr/e-tugra_ksm.crl">CRL</crl>
      <ocsp>http://ocsp.e-tugra.com/status/</ocsp>
      <type>OV</type>
      <document url="http://www.e-tugra.com.tr/Portals/3/Templates/NQC_CpCps.pdf">Non Qualified (NQC) CP/CPS in English</document>
      <document url="http://www.e-tugra.com.tr/Portals/3/Templates/QC_CpCps.pdf">Qualified (QC) CP/CPS in English</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=443653</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Camerfirma" url="http://www.camerfirma.com" status="complete">
    <summary>
    AC Camerfirma S.A. is a commercial CA issuing certificates for companies 
    primarily in Spain. Camerfirma is the digital certification authority for 
    Chambers of Commerce in Spain.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=874">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Chambers of Commerce Root - 2008" status="complete">
      <summary>
       This CA has four internally-operated subordinate CAs that issue certificates 
       for Spanish companies and representatives. Chambers of Commerce act as RAs 
       for end user registration.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=339325"
            version="3"
            sha1="78:6a:74:ac:76:ab:14:7f:9c:6a:30:50:ba:9e:a8:7e:fe:9a:ce:3c"
            modulus="4096"
            from="2008-08-01"
            to="2038-07-31"/>
      <crl url="http://crl.camerfirma.com/root_chambers_2008.crl">CRL</crl>
      <ocsp>http://ocsp.camerfirma.com</ocsp>
      <type>OV</type>
      <document url="https://www.camerfirma.com/mod_web/usuarios/pdf/CPS_3.1.1.pdf">Certificate Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406968</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Global Chambersign Root - 2008" status="complete">
      <summary>
       This CA has internally-operated subordinate CAs that issue certificates for 
       general use globally. Other companies act as RAs for end user registration.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=339324"
            version="3"
            sha1="4a:bd:ee:ec:95:0d:35:9c:89:ae:c7:52:a1:2c:5b:29:f6:d6:aa:0c"
            modulus="4096"
            from="2008-08-01"
            to="2038-07-31"/>
      <crl url="http://crl.camerfirma.com/root_chambersign_2008.crl">CRL</crl>
      <ocsp>http://ocsp.camerfirma.com</ocsp>
      <type>OV</type>
      <document url="https://www.camerfirma.com/mod_web/usuarios/pdf/CPS_3.1.1.pdf">Certificate Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406968</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Hongkong Post" url="http://www.hongkongpost.gov.hk/index.html" status="approved">
    <summary>
     Hongkong Post is a government agency and is a recognized CA under 
     the law of Hong Kong Special Administrative Region (HKSAR) of China, 
     and has been issuing digital certificates under the e_Cert brand name 
     to individuals and organizations of HKSAR since January 2000. 
     Hongkong Post CA operations have been outsourced to E-Mice Solutions. 
     This is documented in the CPS and the Management Assertions. 
     The WebTrust audit covers both Hongkong Post and E-Mice CA operations.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/">PricewaterhouseCoopers</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=125">Audit Report and Management Assertions</document>
    </audit>
    <certificate name="Hongkong Post Root CA 1" status="approved">
      <summary>
       This root has only one direct subordinate, Hongkong Post e-Cert CA 1, 
       which is the signer key and is used to issue different types of recognized 
       e-Certs to individuals and organizations.  
      </summary>
      <data url="http://www.hongkongpost.gov.hk/product/download/root/img/smartid_rt.cacert"
            version="3"
            sha1="D6:DA:A8:20:8D:09:D2:15:4D:24:B5:2F:CB:34:6E:B2:58:B2:8A:58"
            modulus="2048"
            from="2003-05-15"
            to="2023-05-15"/>
      <crl url="http://crl1.hongkongpost.gov.hk/crl/eCertCA1CRL1.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.hongkongpost.gov.hk/product/cps/ecert/img/cps_en23.pdf">Certificate Practice Statement for e-Certs</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=408949</authorisation>
      </inclusion>
      <comments>File NSS bug after the CRL issues have all been resolved.</comments>
    </certificate>
  </authority>

  <authority name="Sertifitseerimiskeskus AS" url="http://www.sk.ee" status="pending">
    <summary>
    SK (Certification Centre, legal name AS Sertifitseerimiskeskus) is a 
    commercial CA, covering the Baltic region (Estonia, Lithuania, Latvia). 
    SK is Estonia's primary certification authority, providing certificates 
    for authentication and digital signing to Estonian ID Cards. Established in 
    2001, SK has the backing of Estonian and Nordic financial and telecom sector. 
    SK’s customers include the Estonian court system and notaries, Central Bank 
    and commercial banks, and enforcement organisations (e.g. Police).
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ee/">KPMG Estonia</auditor>
      <document url="http://www.sk.ee/file.php?id=457">Audit Report</document>
    </audit>
    <certificate name="Juur-SK" status="pending">
      <summary>
       This root issues three types of internally operated subordinate CAs. 
       The first type of subordinate CA is used to issue electronic ID cards 
       which contain certificates for digital signature and for digital 
       identification. 
       The second type of subordinate CA is used to issue internal ID cards 
       of the Republic of Estonia. 
       The third type of subordinate CA is used to issue device and SSL certificates.
      </summary>
      <data url="http://www.sk.ee/files/JUUR-SK.der"
            version="3"
            sha1="40:9D:4B:D9:17:B5:5C:27:B6:9B:64:CB:98:22:44:0D:CD:09:B8:89"
            modulus="2048"
            from="2001-08-30"
            to="2016-08-26"/>
      <crl url="http://www.sk.ee/pages.php/0202040202,36">CRL</crl>
      <ocsp>http://ocsp.sk.ee</ocsp>
      <type>OV</type>

      <document url="http://www.sk.ee/files/tree.pdf">Certificate Hierarchy Diagram</document>
      <document url="http://www.sk.ee/file.php?id=432">Certificate Practice statement</document>
      <document url="http://www.sk.ee/files/eid-sk-1.0.pdf">EID-SK Certificate Policy</document>
      <document url="http://www.sk.ee/file.php?id=252">ESTEID-SK Certificate Policy</document>
      <document url="http://www.sk.ee/file.php?id=434">KLASS3-SK Certificate Policy</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=414520</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="VAS Latvijas Pasts" url="http://www.pasts.lv/en" status="incomplete">
    <summary>
    Latvijas Pasts (Latvian Post) is a commercial CA operating primarily in 
    Latvia, targeting also Estonia and Lithuania. Latvian Post provides 
    certificate services to banks and postal services to the legal entities 
    and private individuals of the Republic of Latvia. Their accreditation 
    certification services include electronic signature certificates that are 
    issued according with local legislations (Electronic Document Law), smart 
    cards with two certificates (authentication and qualified signature) used 
    for authentication and document signing in Latvia, and SSL certificates 
    and Code Signing certificates for customers in European Union. 
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.lv/">KPMG Latvia</auditor>
      <document url="http://www.dvi.gov.lv/edokumenti/aplieciba/">Accreditation Certificate by Data State Inspection</document>
    </audit>
    <certificate name="VAS Latvijas Pasts SSI(RCA)" status="incomplete">
      <summary>
      This root CA issues an intermediate Policy CA, which issues the 
      Issuing CAs for Certificate Service Providers (CSPs). 
      </summary>
      <data url="http://www.e-me.lv/aia/vas%20latvijas%20pasts%20ssi(rca).crt"
            version="3"
            sha1="08:64:18:e9:06:ce:e8:9c:23:53:b6:e2:7f:bd:9e:74:39:f7:63:16"
            modulus="4096"
            from="2006-09-13"
            to="2024-09-13"/>
      <crl url="ldap://e-me.lv">CRL</crl>
      <ocsp>http://ocsp.e-me.lv/responder.eme</ocsp>
      <type>OV</type>
      <document url="https://www.e-me.lv/csp-web/certupload.aspx">Certificate Status Check Tool</document>
      <document url="http://info.e-me.lv/en/atbalsts/CA_sertif/">Download links for the root and intermediate CAs</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CP_SP_v3_1.doc">Certificate Policy of the Certification Service Providers</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_RCA_SN_SSI_v2_5.doc">Certificate Practice Statement of the Root CA</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_PCA_SN_PSI_v2_5.doc">Certificate Practice Statement of the Policy CA</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_ICA_SN_ISI_v2_62.doc">Certificate Practice Statment of the Issuing CAs of the Certification Service Providers</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_IC_CPS_v1_2.doc">Certificate Practice Statement of the Infrastructure Certificates</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_LZP_TP_v2_5.doc">Time-Stamp Policy</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_LZN_TPS_v2_61.doc">Time Stamp Authority Practice Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=412747</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="FNMT" url="http://www.cert.fnmt.es" status="incomplete">
    <summary>
     Fábrica Nacional de Moneda y Timbre (FNMT) is a government agency that 
     provides services to Spain as a national CA.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.bsi-global.com">BSI Management Systems B.V</auditor>
      <document url="http://www.cert.fnmt.es/content/pages_std/docs/ETSI.pdf">Auditor Statement of ETSI Compliance</document>
    </audit>
    <certificate name="FNMT Clase 2 CA" status="incomplete">
      <summary>
      This root has no subordinate CAs and is 1024 bit.
      </summary>
      <data url="http://www.cert.fnmt.es/content/pages_std/certificados/FNMTClase2CA.cer"
            version="3"
            sha1="43:F9:B1:10:D5:BA:FD:48:22:52:31:B0:DO:08:2B:37:2F:EF:9A:54"
            modulus="1024"
            from="1999-03-18"
            to="2019-03-18"/>
      <crl url="ldap://ldap.cert.fnmt.es">CRL</crl>
      <ocsp>http://apus.cert.fnmt.es/appsUsuario/ocsp/OcspResponder</ocsp>
      <type>OV</type>
      <document url="http://www.cert.fnmt.es/content/pages_std/docs/dpc.pdf">Certificate Policy</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435736</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="TURKTRUST" url="http://www.turktrust.com.tr/" status="incomplete">
    <summary>
    TURKTRUST Information Security Services Inc. is a public corporation and 
    is an IT company based in Turkey. 
    TURKTRUST is an authorized qualified electronic certificate service provider 
    according to the Turkish Electronic Signature Law. TURKTRUST issues qualified 
    certificates, time-stamping services, SSL certificates, and object signing certificates.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Telecommunications Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=264748">Letter of Official CA Statement</document>
      <document url="http://www.tk.gov.tr/eimza/eshs.htm">List of accredited CAs</document>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/tt.doc">Audit statement on auditor website</document>
    </audit>
    <certificate name="TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı" status="incomplete">
      <summary>
      This is an offline root with one internally-operated subordinate CA that 
      issues qualified electronic certificates in accordance with 
      Turkish Electronic Signature Law. 
      </summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/TURKTRUST_Elektronik_Sertifika_Hizmet_Saglayicisi_s3.crt"
            version="3"
            sha1="F1:7F:6F:B6:31:DC:99:E3:A3:C8:7F:FE:1C:F1:81:10:88:D9:60:33"
            modulus="2048"
            from="2007-12-25"
            to="2017-12-22"/> 
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL_s3.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=322073">Certification Practice Statement</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=322069">Certificate Hierarchy</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=433845</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Chunghwa Telecom" url="http://www.cht.com.tw/CHTFinalE/Web/" status="approved">
    <summary>
      Chunghwa Telecom (CHT) chiefly provides telecommunication and information-related 
      services. A public corporation, CHT is the largest integrated telecommunication 
      operator in Taiwan.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.dfk.com/">Sun Rise CPA Firm of DFK International</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=695">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="ePKI Root Certification Authority" status="approved">
      <summary>
      This is the eCA root, which has two subordinate CAs: CHTCA and Public CA. 
      The CHTCA is the internal CA of Chunghwa Telecom (CHT) which signs certificates 
      for CHT employees. The Public CA signs certificates for CHT clients.  
      </summary>
      <data url="http://210.71.154.6/download/ROOTeCA.cer"
            version="3"
            sha1="67:65:0d:f1:7e:8e:7e:5b:82:40:a4:f4:56:4b:cf:e2:3d:69:c6:f0"
            modulus="4096"
            from="2004-12-19"
            to="2034-12-19"/> 
      <crl url="http://210.71.154.6/repository/CRL/CA.crl">CRL</crl>
      <type>DV, OV</type>
      <document url="http://210.71.154.6/repository_en.htm">CHT Certificate Repository</document>
      <document url="http://210.71.154.6/download/ePKI_CP_V1_2004.pdf">ePKI CP</document>
      <document url="http://210.71.154.6/download/eCA_CPS_english.pdf">eCA CPS</document>
      <document url="http://210.71.154.6/download/PublicCA%20CPS%20English%20version1.3.pdf">Public CA CPS</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=448794</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=496193</technical>
      </inclusion>
      <comments>
       In the eCA CPS the term cross-certificate means a certificate used to establish 
       a trust relationship between two CAs. Within the ePKI the cross-certificate is 
       intended to mean subordinate CA. All subordinate CAs are operated by the Data 
       Communication Business Group, which is a division of Chunghwa Telecom.
</comments>
    </certificate>
  </authority>

  <authority name="Swiss BIT" url="http://www.bit.admin.ch" status="complete">
    <summary>
    Swiss BIT is also known as the Federal Office of Information Technology and 
    Telecommunication (FOITT) which operates servers and software applications for the 
    Confederation (one of the biggest employers in Switzerland) and third parties. The 
    FOITT also operates a carrier network for the Federal administration and organisations 
    close to the administration. Various, partly encrypted, virtual private networks (VPN) 
    are operated on this carrier network. Overall the FOITT serves 1200 locations in 
    Switzerland and 200 locations worldwide. The FOITT is also responsible for networking 
    the Swiss cantons and the Principality of Liechtenstein.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG SA Switzerland</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362013">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Admin-Root-CA" status="complete">
      <summary>
      This root has three internally-operated subordinate CAs, with two currently in 
      operation. The sub-CAs issue certificates for hardware tokens to be used 1) for 
      identification, digital signatures, encryption, and authentication of individuals 
      2) for qualified digital signatures. The hardware tokens are issued to employees 
      of an administrative unit (federal, cantonal or municipal administration) who 
      already have their information published in Swiss BIT's Admin-Directory.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=377526"
            version="3"
            sha1="25:3f:77:5b:0e:77:97:ab:64:5f:15:91:55:97:c3:9e:26:36:31:d1"
            modulus="2048"
            from="2001-11-15"
            to="2021-11-10"/> 
      <crl url="http://www.pki.admin.ch/crl/Admin-Root-CA.crl">CRL</crl>
      <ocsp>http://ocsp.pki.admin.ch</ocsp>
      <type>DV, OV</type>
      <document url="http://www.pki.admin.ch">Admin PKI Repository</document>
      <document url="http://www.bit.admin.ch/adminpki/00247/index.html">Hierarchy Diagram</document>
      <document url="http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_1_4.pdf">CPS for AdminPKI - ClassA (AdminCA-A-T01 sub-CA)</document>
      <document url="http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_1_3_FR.pdf">CPS for AdminPKI-Class B (Admin-CA2 and Admin-CA3 sub-CAs)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435026</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="AdminCA-CD-T01" status="complete">
      <summary>
      This root does not have subordinate CAs. It issues end-entity certificates directly 
      for users/organizations and devices/servers for identification, digital signatures, 
      encryption, code/document signing, webserver authentication (SSL), and application 
      server authentication. These certificates may be applied for by members of an 
      administrative unit (federal, cantonal or municipal administration) that have concluded 
      a framework agreement and SLA with Swiss BIT.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=377531"
            version="3"
            sha1="6b:81:44:6a:5c:dd:f4:74:a0:f8:00:ff:be:69:fd:0d:b6:28:75:16"
            modulus="2048"
            from="2006-01-25"
            to="2016-01-25"/> 
      <crl url="http://www.pki.admin.ch/crl/AdminCA-CD-T01.crl">CRL</crl>
      <ocsp>http://ocsp.pki.admin.ch</ocsp>
      <type>DV, OV</type>
      <document url="http://www.pki.admin.ch">Admin PKI Repository</document>
      <document url="http://www.bit.admin.ch/adminpki/00247/index.html">Hierarchy Diagram</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=376403">AdminPKI CP/CPS Class CD-T01 (English)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=382263">Process Description for Provisioning Server certificates (German)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435026</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Disig" url="http://www.disig.eu" status="complete">
    <summary>
    Disig is a public Certification Service Provider, located in Slovakia. 
    Disig is a member of international ASSECO Group, one of the strongest 
    software houses in the CEE region. Asseco is a leader in selected IT 
    segments in countries across Central and Eastern Europe. 
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.asint.sk/isaca/index.php?amp;option=com_content&amp;task=view&amp;id=43&amp;Itemid=56">Independent Team of Auditors managed by Mr. Jan Cesnak</auditor>
      <document url="http://www.disig.sk/_pdf/Audit_report_CA_statement.pdf">Audit Report Statement</document>
   </audit>
    <certificate name="CA Disig" status="complete">
      <summary>
      This root has no subordinate CAs, issuing end-entity certs 
      for SSL, email, and code signing directly.
      </summary>
        <data url="http://www.disig.eu/ca/cert/ca_disig.der"
        version="3"
        sha1="2a:c8:d5:8b:57:ce:bf:2f:49:af:f2:fc:76:8f:51:14:62:90:7a:41"
        modulus="2048" 
        from="2006-03-21" to="2016-03-21"/>
      <crl url="http://www.disig.eu/ca/crl/ca_disig.crl">CRL</crl>
      <type>OV</type>
      <document url="https://bug455878.bugzilla.mozilla.org/attachment.cgi?id=384717">Certificate Policy in English</document>
      <document url="http://www.disig.eu/_pdf/cp-disig.pdf">Certificate Policy in Slovak</document>
      <document url="http://www.disig.eu/index.php?id=ca&amp;L=1">Disig Certification Authority Website</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=455878</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Staat der Nederlanden" url="http://www.pkioverheid.nl/english" status="complete">
    <summary>
     Staat der Nederlanden is the Netherlands national government CA. The Dutch 
     governmental PKI hierarchy consists of 2 roots. This first root, Staat der 
     Nederlanden Root CA, is already included in NSS. The second root is the 
     next generation, Staat der Nederlanden Root CA – G2. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://cert.webtrust.org/SealFile?seal=683&amp;file=pdf">Audit Report and Management Asserstions</document>
   </audit>
    <certificate name="Staat der Nederlanden Root CA - G2" status="complete">
      <summary>
       This is the next generation of the Staat der Nederlandend Root CA that 
       is currently in the Mozilla store. The PKIoverheid issues two internally 
       operated subordinate CAs, which issue subordinate CAs to CSPs. The CSPs 
       are commercial and governmental organizations. Each CSP has to prove that 
       it complies with ETSI TS 101 456 and the Dutch law on electronic signatures. 
       CSPs must conclude a contract with a representative of a government 
       organization or commercial company before issuing end-entity certificates. 
       A request for a certificate is always signed by a specified representative 
       of a government organization or commercial company. 
      </summary>
        <data url="http://www.pkioverheid.nl/fileadmin/PKI/PKI_certifcaten/staatdernederlandenrootca-g2.crt"
        version="3"
        sha1="59:af:82:79:91:86:c7:b4:75:07:cb:cf:03:57:46:eb:04:dd:b7:16"
        modulus="4096" 
        from="2008-03-26" 
        to="2020-03-25"/>
      <crl url="http://crl.pkioverheid.nl/">CRL</crl>
      <type>OV</type>
      <document url="http://www.pkioverheid.nl/english/">Description of PKI Overheid</document>
      <document url="http://www.pkioverheid.nl/fileadmin/PKI/CPS_PA_PKIoverheid_v3.0.pdf">Certification Practice Statement of the Policy Authority PKI Overheid</document>
      <document url="http://www.pkioverheid.nl/fileadmin/PKI/pve/PvE_deel3a_v1.2.pdf">Certificate Policy Part 3a for employees of governmental organizations or commercial companies</document>
      <document url="http://www.pkioverheid.nl/fileadmin/PKI/pve/PvE_deel3b_v1.2.pdf">Certificate Policy Part 3b for SSL services of governmental organizations or commercial companies</document>
      <document url="http://www.pkioverheid.nl/fileadmin/PKI/pve/PvE_deel3c_v1.2.pdf">Certificate Policy Part 3c for personal use of civilians</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=436056</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Serasa S.A." url="http://www.serasa.com.br/us/index.htm" status="incomplete">
    <summary>
    Serasa has 5 CAs under ICP-Brasil and 4 CAs not linked to ICP-Brasil. 
    This request is in regards to the CAs not linked to ICP-Brasil.
    Serasa is a subsidiary of Experian which is a public, global corporation.
    Serasa is an economic and financial analysis and information firm with global 
    coverage. Serasa has presence in all Brazilian state capitals and major cities, 
    and is the holder of Latin America's largest data bank on individuals, businesses 
    and corporate concerns. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.deloitte.com.br">Deloitte Touche Tohmatsu</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=347519">Auditor Statement from 2004</document>
   </audit>
    <certificate name="Serasa Certificate Authority I" status="incomplete">
      <summary>
       Serasa CA I provides and sells digital certificates for general public that 
       need to sign electronic documents or be authenticated in a website.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAI.cer"
        version="3"
        sha1="a7:f8:39:0b:a5:77:05:09:6f:d3:69:41:d4:2e:71:98:c6:d4:d9:d5"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAI.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority II" status="incomplete">
      <summary>
      Serasa CA II provides and sells server and code signing certificates for 
      corporations.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAII.cer"
        version="3"
        sha1="31:e2:c5:2c:e1:08:9b:ef:fd:da:db:26:dd:7c:78:2e:bc:40:37:bd"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAII.cer">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority III" status="incomplete">
      <summary>
       Serasa CA III provides CA certificates for Serasa and their clients in CA business.  
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAIII.cer"
        version="3"
        sha1="9e:d1:80:28:fb:1e:8a:97:01:48:0a:78:90:a5:9a:cd:73:df:f8:71"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIII.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority IV" status="incomplete">
      <summary>
      Serasa CA IV provides and sells digital certificates for general public that 
      need to sign any kind of electronic documents or be authenticated in a website. 
      It has also “Smart Card Logon” (OID 1.3.6.1.4.1.311.20.2.2) applied.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAIV.cer"
        version="3"
        sha1="1b:4c:a3:c4:74:a4:4b:56:c8:22:41:98:14:29:20:78:65:4f:11:6f"
        modulus="2048" 
        from="2005-07-04" 
        to="2025-06-29"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIV.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Japanese GPKI" 
              url="http://www.gpki.go.jp" status="complete">
    <summary>
     In Japan there are two root CAs, one is GPKI (Government Public Key Infrastructure)
     and the other one is LGPKI (Local government public Key Infrastructure). 
     GPKI is controlled by the Ministry of Internal Affairs/Communications and 
     National Information Security Center, and it is separate from Local government 
     sectors.  The Japanese government decided to centralize to GPKI from each of the 
     ministry's certification systems and it has finished migration on Oct, 2008.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.deloitte.com/jp">Deloitte Touche Tohmatsu</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=886&amp;file=pdf">Audit Report and Management's Assertions (Japanese)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=374841">Audit Report and Management's Assertions (English)</document>
   </audit>
    <certificate name="ApplicationCA - Japanese Government" status="complete">
      <summary>
       This root is operated by the national government of Japan. It issues server 
       certificates and code signing certificates to national government agencies. 
       This root issues end-entity certificates directly, and does not have any subordinate CAs.
      </summary>
        <data url="http://www.gpki.go.jp/apcaself/APCAroot.der"
        version="3"
        sha1="7F:8A:B0:CF:D0:51:87:6A:66:F3:36:0F:47:C8:8D:8C:D3:35:FC:74"
        modulus="2048" 
        from="2007-12-12" 
        to="2017-12-12"/>
      <crl url="http://dir.gpki.go.jp/ApplicationCA.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://www.gpki.go.jp/apca/">ApplicationCA Info</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=379657">CP/CPS in English</document>
      <document url="http://www.gpki.go.jp/apca/cpcps/index.html">CP/CPS in Japanese</document>

      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=474706</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Finnish Population Register" 
              url="http://www.vrk.fi" status="pending">
    <summary>
     The Population Register Centre operates under the Finland Ministry of Finance 
     to develop and maintain the national Population Information System, the guardianship 
     register and the Public Sector Directory Service. The Population Register Centre serves 
     as the Certification Authority for the State of Finland, and thus develops and maintains 
     the national certificate services to Finnish Citizens, state workers and organizations. 
     All certificates issued to natural persons by the Population Register Centre are qualified 
     certificates, i.e. European-wide certificates based on an EU Directive and Finnish legislation.
    </summary>
    <audit type="ETSI TS 101.456 equivalent">
      <auditor url="http://www.inspecta.com">Inspecta Finland</auditor>
      <document url="http://www.inspecta.fi/sfs/sertifikaattihaku/haku_tulokset.php?type=haljar&amp;nayta=1&amp;id=1400">ISO 27001 Audit Certificate</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=358834">ISO 27001 Audit Certificate in English</document>
    </audit>
    <audit type="ETSI TS 101.456 equivalent">
      <auditor url="http://www.inspecta.com">Inspecta Finland</auditor>
      <document url="http://www.inspecta.fi/sfs/sertifikaattihaku/haku_tulokset.php?type=haljar&amp;nayta=1&amp;id=1401">ISO 9001 Audit Certificate</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=358833">ISO 9001 Audit Certificate in English</document>
    </audit>
    <certificate name="VRK Gov. Root CA" status="pending">
      <summary>
        This root issues internally-operated intermediate CAs.
      </summary>
        <data url="http://www.fineid.fi/certs/vrkrootc.crt"
        version="3"
        sha1="fa:a7:d9:fb:31:b7:46:f2:00:a8:5e:65:79:76:13:d8:16:e0:63:b5"
        modulus="2048" 
        from="2002-12-18"
        to="2023-12-18"/>
      <crl url="http://proxy.fineid.fi/crl/vrkspc.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://www.fineid.fi/vrk/fineid/home.nsf/pages/index_eng">Technical Specifications</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/24EA4C4CD4A1EAA0C2257054002A55BD/$file/S2v21.pdf">FINEID Specification S2 - CA-model and certificate contents</document>
      <document url="http://www.fineid.fi/vrk/fineid/home.nsf/pages/FA842EE9BB3C7AA5C2257054002D3FA9">Links to Intermediate CAs</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/B2BC1F39CB3F28AAC225742E004BA2DF/$file/srvcps20080501.pdf">Service Provider for Server CPS in Finnish</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/7AC8EFBD063A723BC225742C001EA6BC/$file/ccps20080501en.pdf">Smartcard Citizen Certificates CPS in English</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/F7A72F2FAD5E83B3C225742C00372EFD/$file/ocps20080501en.pdf">Smartcard Qualified Certificates CPS in English</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/9BB25E8FA98D6D6FC22574F300410999/$file/tccps20081101.pdf">Smartcard Temporary Certificates CPS in Finnish</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/AAF4DE2FF17E1015C225742E004B8B3D/$file/spcps20080501.pdf">Software Cert Service Provider for E-mail Use CPS in Finnish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=463989</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="certSIGN" 
              url="http://www.certsign.ro/certsign_en/" status="complete">
    <summary>
    certSIGN is operated by SC CERTSIGN srl, a private corporation. certSIGN 
    is a company member of UTI Group and an accredited supplier of certification 
    services. certSIGN solutions are developed integrally in Romania.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://bug470756.bugzilla.mozilla.org/attachment.cgi?id=361730">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="certSIGN ROOT CA" status="complete">
      <summary>
        This root issues internally-operated subordinate CAs for different 
        classes of certificates based on use and verification requirements.
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=359654"
        version="3"
        sha1="fa:b7:ee:36:97:26:62:fb:2d:b0:2a:f6:bf:03:fd:e8:7c:4b:2f:9b"
        modulus="2048" 
        from="2006-07-04"
        to="2031-07-04"/>
      <crl url="https://www.certsign.ro/certificate_digitale/lista_certificate_revocate_en.htm">CRL</crl>
      <ocsp>http://ocsp.certisgn.ro</ocsp>
      <type>OV</type>
      <document url="http://www.certsign.ro/certsign_en/files/certSIGN_CP_EN_v1.0.pdf">Certification Policy in English</document>
      <document url="http://www.certsign.ro/certsign_en/files/certSIGN_CPS_EN.pdf">Certification Practice Statement in English</document>
      <document url="https://www.certsign.ro/certificate_digitale/lantul_de_incredere_en.htm">Download Links of Subordinate CAs</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=470756</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="D-TRUST" 
              url="https://www.d-trust.net/internet/content/e_index.html" status="incomplete">
    <summary>
     D-TRUST GmbH is a wholly owned subsidiary of Bundesdruckerei 
     (100% Governmental), and is the only German trust center authorised 
     to perform sovereign tasks. The primary market is the German speaking 
     area (Austria, Germany, Switzerland) and B2B focused. 
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuevit.de/">TÜV-IT Germany</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6704UE.pdf">Audit Certificate</document>
    </audit>
    <certificate name="D-TRUST Root Class 3 CA 2007" status="incomplete">
      <summary>
        This root will eventually have three internally-operated subordinate 
        CAs. It currently has one subordinate CA called D-TRUST Service 
        Class 3 CA 1 2008 which issues website certificates. The other two 
        subordinate CAs that will be created will be for email and code signing.
      </summary>
        <data url="https://www.d-trust.net/cgi-bin/D-TRUST_Root_Class_3_CA_2007.crt"
        version="3"
        sha1="FD:1E:D1:E2:02:1B:0B:9F:73:E8:EB:75:CE:23:43:6B:BC:C7:46:EB"
        modulus="2048" 
        from="2007-05-16"
        to="2022-05-16"/>
      <crl url="http://www.d-trust.net/crl/d-trust_service_class_3_ca_1_2008.crl">CRL</crl>
      <ocsp>http://ssl.ocsp.d-trust.net</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=361775">D-TRUST-Root PKI Certification Practice Statement in English</document>
      <document url="http://www.d-trust.net/internet/files/D-TRUST_Root_PKI_CPS.pdf ">CPS in German</document>
      <document url="http://www.d-trust.net/internet/files/D-TRUST_Root_PKI_CP.pdf ">CP in German</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=467891</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="CNNIC" 
              url="http://www.cnnic.cn/en/index/index.htm" status="complete">
    <summary>
     China Internet Network Information Center (CNNIC), the state network information 
     center of China, is a non-profit organization. CNNIC takes orders from the 
     Ministry of Information Industry (MII) to conduct daily business, while it is 
     administratively operated by the Chinese Academy of Sciences (CAS). The CNNIC 
     Steering Committee, a working group composed of well-known experts and commercial 
     representatives in domestic Internet community, supervises and evaluates the structure, 
     operation and administration of CNNIC. The objective customers of the CNNIC root are 
     domain owners from general public, including enterprise, government, organization, 
     league, individual, etc.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/global/content.nsf/China_E/home">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=805&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="CNNIC ROOT" status="complete">
      <summary>
      This root has one internally-operated subordinate CA named CNNIC SSL, which offers 
      only SSL certificates that may be issued to general public, including 
      enterprise, government, organization, league, individual, etc.
      </summary>
        <data url="http://www.cnnic.cn/uploadfiles/rar/2009/2/12/cnnicroot.rar"
        version="3"
        sha1="8b:af:4c:9b:1d:f0:2a:92:f7:da:12:8e:b9:1b:ac:f4:98:60:4b:6f"
        modulus="2048" 
        from="2007-04-16"
        to="2027-04-16"/>
      <crl url="http://www.cnnic.cn/download/crl/CRL1.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.cnnic.cn/html/Dir/2007/04/29/4568.htm">Policies of the CNNIC Trusted Network Service Center</document>
      <document url="http://www.cnnic.cn/uploadfiles/pdf/2008/11/18/142721en.pdf">English CPS of the CNNIC Trusted Network Service Center</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=476766</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="ACEDICOM" 
              url="http://acedicom.edicomgroup.com/en/index.htm" status="complete">
    <summary>
     The Edicom Certification Authority (ACEDICOM) provides companies, communities 
     and physical persons with secure electronic identification mechanisms that 
     enable them to engage in activities where the digital signature replaces the 
     handwritten with identical legal guarantees. To this end, ACEDICOM issues 
     certificates in accordance with the stipulations of Directive 1999/93/EC of 
     13th December 1999 and Law 59/2003 of 19th December, on electronic signature, 
     and so has sufficient recognition to operate in all countries of the European 
     Union. The Edicom CA is responsible for obtaining the corresponding official 
     authorisation in those places outside the Union where it operates commercially.
    </summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.s21sec.com/">S21sec</auditor>
      <document url="http://acedicom.edicomgroup.com/archivos/pdf/ACEDICOM_s21sec.pdf">Audit Report</document>
    </audit>
    <certificate name="ACEDICOM Root" status="complete">
      <summary>
      This root has three internally-operated subordinate CAs. The ACEDICOM 01 
      subordinate CA issues Qualified certificates for identification and advanced 
      electronic signature, for the use of physical persons or legal organisations. 
      The ACEDICOM 02 subordinate CA issues certificates for purposes other than 
      Qualified electronic signature. The ACEDICOM Servidores subordinate CA issues 
      server/client certificates and code signing certificates.
      </summary>
        <data url="http://acedicom.edicomgroup.com/archivos/certificados/ACEDICOM%20Root.crt"
        version="3"
        sha1="e0:b4:32:2e:b2:f6:a5:68:b6:54:53:84:48:18:4a:50:36:87:43:84"
        modulus="4096" 
        from="2008-04-18"
        to="2028-04-13"/>
      <crl url="http://acedicom.edicomgroup.com/rootca.crl">Root CRL</crl>
      <ocsp>http://ocsp.acedicom.edicomgroup.com/acedicom01</ocsp>
      <type>OV</type>
      <document url="http://acedicom.edicomgroup.com/en/archivos/politicas/ACEDICOM_CertificationPractice.pdf">CPS in English</document>
      <document url="http://acedicom.edicomgroup.com/es/archivos/politicas/ACEDICOM_PracticasCertificacion.pdf">CPS in Spanish</document>
      <document url="http://acedicom.edicomgroup.com/en/contenidos/practicasyPoliticas/punto1.htm">Declaration of Certification Practices and Policies according to Certificate Type</document>
      <document url ="http://acedicom.edicomgroup.com/es/archivos/politicas/ACEDICOM%20-%20Politica%20Certificados%20TLS.pdf">TLS Certificate Policy (in Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=471045</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="NetLock" 
              url="http://www.netlock.hu/USEREN/index.html" status="complete">
    <summary>
     NetLock Ltd. is a qualified Certificate Authority in Hungary that issues certificates to organizations and individuals.
    </summary>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="http://webold.nhh.hu/esign/setLanguageAction.do?lang=en">National Communications Authority, Hungary</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=365687">Statement of audit conformance in English</document>
      <document url="http://webold.nhh.hu/esign/szolgReszlet/init.do?tipus=mi&amp;azon=12201521-2-41">Statement of the NCA that Netlock is a Qualified Service Provider</document>
    </audit>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="http://www.cert-hungary.hu">CERT-Hungary</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=378081">Cover letter of the rDSP audit in Hungarian</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=378711">English Translation of part of the rDSP Audit Report</document>
   </audit>
    <certificate name="NetLock Arany (Class Gold) Főtanúsítvány" status="complete">
      <summary>
       NetLock currently has four separate root CAs included in NSS. The redesigned 
       equivalent of these existing roots will be created under this new root. 
       The new root will sign seven internally-operated subordinate CAs. Two of those 
       subordinate CAs will sign sub-CAs that will be externally-operated by 
       MKB (Hungarian Trade Bank) and MNB (National Bank of Hungary). 
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=365241"
        version="3"
        sha1="06:08:3f:59:3f:15:a1:04:a0:69:a4:6b:a9:03:d0:06:b7:97:09:91"
        modulus="2048" 
        from="2008-12-11"
        to="2028-12-06"/>
      <crl url="http://crl1.netlock.hu/index.cgi?crl=cbca">CRL for Class B</crl>
      <ocsp>http://ocsp1.netlock.hu/gold.cgi</ocsp>
      <type>OV</type>
      <document url="https://bug480966.bugzilla.mozilla.org/attachment.cgi?id=374930">CA Hierarchy</document>
      <document url="http://www.netlock.hu/USEREN/html/dok.html">Practice Statements and Terms of Agreements in Hungarian</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=364923">CPS in English</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366607">Verification Practice for Non-Qualified certificates </document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366794">Non-qualified certificate CRL and OCSP profile definitions</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366795">Certificate Issuance Practice Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=480966</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="CATCert" 
              url="http://www.catcert.net" status="incomplete">
    <summary>
     CATCert is the Catalan Agency of Certification (Agència Catalana de Certificació).
     CATCert’s aim is to provide digital certification services and promote the usage 
     of digital signature in order to make safer the communications within the Catalan 
     government and the communications (within and for) the Catalan government.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/es">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=466&amp;file=pdf">Audit Report and Management Assertions</document>
    </audit>
    <certificate name="EC-ACC" status="incomplete">
      <summary>
      This root has seven internally-operated subordinate CAs. The subordinate CAs 
      are used to distinguish who the certificates are issued to.  The EC-IDCAT 
      certificates are issued to Catalan citizens.  The EC-SAFP (a sub-CA of EG-GENCAT), 
      EC-AL, and EC-PARLAMENT certificates are not issued to the general public, but 
      only to the civil servants and computers or devices of the Regional Catalan 
      government, the Catalan Government, and the Catalan Parliament. The EC-UR and 
      EC-URV certificates are not issued to the general public, but to employees, 
      students and computers or devices of Catalan universities and research centers 
      connected to the “Anella Científica” group, and the Universitat Rovira i 
      Virgili (URV).
      </summary>
        <data url="http://www.catcert.net/descarrega/acc.crt"
        version="3"
        sha1="28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8"
        modulus="2048" 
        from="2003-01-07"
        to="2031-01-07"/>
      <crl url="http://epscd.catcert.net/crl/ec-acc.crl">CRL</crl>
      <ocsp>http://ocsp.catcert.net</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=379561">CA Hierarchy Diagram</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184501">English version of  CPS</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184504">CPS in Catalan</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184505">CP in Catalan</document>
      <document url="http://www.catcert.net/registre">The CPS/CP for each sub-CA in Catalan</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=295474</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="E-Guven" 
              url="http://www.e-guven.com" status="incomplete">
    <summary>
      E-Guven is a private corporation that serves certificates mainly to the 
      Turkish market and they plan to expand their market to other countries.
    </summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.tk.gov.tr">Republic of Turkey Telecommunicatins Authority</auditor>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/eguven.jpg">Letter from Auditor</document>
    </audit>
    <certificate name="e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi" status="incomplete">
      <summary>
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=367292"
        version="3"
        sha1="dd:e1:d2:a9:01:80:2e:1d:87:5e:84:b3:80:7e:4b:b1:fd:99:41:34"
        modulus="2048" 
        from="2007-01-04"
        to="2017-01-04"/>
      <crl url="http://sil.e-guven.com/ElektronikBilgiGuvenligiASSSLClient/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp2.e-guven.com/ocsp.xuda</ocsp>
      <type>OV</type>
      <document url="http://www.e-guven.com/Documents/genel_kullanima_iliskin_nes_ilkeleri.pdf">CPS in Turkish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=476428</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Buypass" 
              url="http://www.buypass.no" status="approved">
    <summary>
     Buypass has over 2 million customers in Norway and is a provider of secure 
     solutions for electronic identification, electronic signature, and payment. 
     Buypass is registered with the Post and Telecommunications Authority as the 
     issuer of the qualified ID according to the law on electronic signature. The 
     company has a license from the Ministry of Finance as e-money business pursuant 
     to the Act on e-money.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.com">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=848&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <audit type="WebTrust EV Readiness">
      <auditor url="http://www.kpmg.com">KPMG</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=371230">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Buypass Class 2 CA 1" status="approved">
      <summary>
       This root signs end-entity certificates directly, and does not have 
       subordinate CAs.
       Buypass Class 2 certificates are issued to persons or enterprises and have the 
       same basic usage areas as Class 3 certificates. The Class 2 CP has, however, 
       less strict requirements with respect to identification of the requesting party 
       than Class 3 certificates.
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=361508"
        version="3"
        sha1="a0:a1:ab:90:c9:fc:84:7b:3b:12:61:e8:97:7d:5f:d3:22:61:d3:cc"
        modulus="2048" 
        from="2006-10-13"
        to="2016-10-13"/>
      <crl url="http://crl.prod.buypass.no/crl/BPClass2CA1.crl">CRL</crl>
      <ocsp>https://ocsp.prod.buypass.no/BPClass2</ocsp>
      <type>OV</type>
      <document url="http://www.buypass.no/Bedrift/Produkter+og+tjenester/SSL/SSL%20dokumentasjon">CP and CPS</document>
      <document url="http://www.buypass.no/_binary?download=true&amp;id=1270">Buypass Class 2 SSL Certificate Policy in English</document>
      <document url="http://www.buypass.no/_binary?download=true&amp;id=1272">Buypass Class 2 SSL Certificate Practice Statement in English</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=477028</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=499712</technical>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Buypass Class 3 CA 1" status="approved">
      <summary>
       This root signs end-entity certificates directly, and does not have 
       subordinate CAs.
       The Buypass Class 3 certificates are either issued to persons or enterprises. 
       The certificates may be used for authentication purposes, encryption/decryption
       and/or electronic signatures (non-repudiation). The certificates are part of an 
       infrastructure provided by Buypass AS enabling electronic commerce in Norway.
       The certificates are used by many different service providers ranging from purely 
       commercial companies to governmental and other public institutions including the 
       health sector. 
       Extended Validation SSL certificates will be issued exclusively by Class 3 CA. 
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=361508"
        version="3"
        sha1="61:57:3a:11:df:0e:d8:7e:d5:92:65:22:ea:d0:56:d7:44:b3:23:71"
        modulus="2048" 
        from="2005-05-09"
        to="2015-05-09"/>
      <crl url="http://crl.prod.buypass.no/crl/BPClass3CA1.crl">CRL</crl>
      <ocsp>https://ocsp.prod.buypass.no/BPClass23</ocsp>
      <type>OV, EV (Policy OID 2.16.578.1.26.1.3.3)</type>
      <document url="http://www.buypass.no/Bedrift/Produkter+og+tjenester/SSL/SSL%20dokumentasjon">CP and CPS</document>
      <document url="http://www.buypass.no/_binary?download=true&amp;id=1271">Buypass Class 3 SSL Certificate Policy in English</document>
      <document url="http://www.buypass.no/_binary?download=true&amp;id=1273">Buypass Class 3 SSL Certificate Practice Statement in English</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=477028</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=499712</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=499716</ev>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Japanese LGPKI" 
              url="http://www.lgpki.jp/" status="incomplete">
    <summary>
      In Japan there are two root CAs, one is GPKI which acts as a root for national 
      government agencies, and the other one is LGPKI (Local Government PKI) which 
      serves the same function for regional and local governments. LGPKI is controlled 
      by the Local Government Wide Area Network (LGWAN) Operation Committee. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.deloitte.com/jp">Deloitte Touche Tohmatsu</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=840&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Japan Local Government PKI Application CA" status="incomplete">
      <summary>
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=371920"
        version="3"
        sha1="96:83:38:F1:13:E3:6A:7B:AB:DD:08:F7:77:63:91:A6:87:36:58:2E"
        modulus="2048" 
        from="2006-03-31"
        to="2016-03-31"/>
      <crl url="http://www.lgpki.jp/Information/CRL/AppCACrl.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.lgpki.jp/unei/C-6-3-5_CPCPS_ApCA_20070320.pdf">CP/CPS in Japanese</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=477314</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="ICA" 
              url="http://www.ica.cz/gb/" status="incomplete">
    <summary>
     První certifikační autorita, a.s. (First certification authority - I.CA), is the 
     largest provider in the field of issuing and administrating the certificates in 
     the Czech republic. It renders its services in the Slovak republic as well. There 
     have been already more than million of issued certificates registered till today.
    </summary>
    <audit type="TBD">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>
    <certificate name="I.CA - Qualified root certificate" status="incomplete">
      <summary>
      </summary>
        <data url="http://www.ica.cz/userdata/pages/4/qica_root_20080311.der"
        version="3"
        sha1="64:90:2a:d7:27:7a:f3:e3:2c:d8:cc:1d:c7:9d:e1:fd:7f:80:69:ea"
        modulus="2048" 
        from="2008-04-01"
        to="2018-04-01"/>
      <crl url="http://qcrldp1.ica.cz/qica08.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.ica.cz/userdata/pages/2/CP_QCv2.5.pdf">CP in Czech</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484171</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="I.CA - Standard root certificate" status="incomplete">
      <summary>
      </summary>
        <data url="http://www.ica.cz/userdata/pages/4/sica_root_20080311.der"
        version="3"
        sha1="ab:16:dd:14:4e:cd:c0:fc:4b:aa:b6:2e:cf:04:08:89:6f:de:52:b7"
        modulus="2048" 
        from="2008-04-01"
        to="2018-04-01"/>
      <crl url="http://scrldp1.ica.cz/sica08.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.ica.cz/userdata/pages/2/CP_KC_21.pdf">CP in Czech</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484171</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="SUSCERTE" 
              url="http://www.suscerte.gob.ve/" status="incomplete">
    <summary>
     SUSCERTE stands for Superintendencia de Servicios de Certificación Electrónica, 
     which is part of the Ministry of People's Power for Telecommunications and 
     Informatics in the Bolivarian Republic of Venezuela. SUSCERTE is a national 
     government CA that provides electronic certification services to the Bolivarian 
     Republic of the Government of Venezuela. 
    </summary>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="">Mariclen Villegas</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=381829">Audit Statement in Spanish</document>
    </audit>
    <certificate name="Autoridad de Certificacion Raiz del Estado Venezolano" status="incomplete">
      <summary>
      This root CA is the Root Certification Authority of Venezuela’s National 
      Infrastructure of Electronic Certification. The main function of this root 
      is to issue the intermediate CAs to the Certification Service Suppliers (CSS) 
      of the public and private sector, according to the Law on Data Messages and 
      Electronic Signature (LSMDFE). Once a CSS has been accredited by SUSCERTE according 
      to the LSMDFE, the CSS must issue the certificates in accordance with the purpose of 
      the electronic certificates specified in their own Declaration of Practices of 
      Certification and Policy of Certificates.
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375214"
        version="3"
        sha1="DD:83:C5:19:D4:34:81:FA:D4:C2:2C:03:D7:02:FE:9F:3B:22:F5:17"
        modulus="4096" 
        from="2007-02-16"
        to="2027-02-11"/>
      <crl url="http://www.suscerte.gob.ve/lcr">CRL</crl>
      <ocsp>http://ocsp.suscerte.gob.ve</ocsp>
      <type>OV</type>
      <document url="http://acraiz.suscerte.gob.ve/dpc/DPC_AC_RAIZ_V1.0.pdf">Declaration of Practices of Certification (DPC) of root in Spanish</document>
      <document url="http://acraiz.suscerte.gob.ve/dpc/DPC_AC_RAIZ_V1.0_en.pdf">DPC of root in English</document>
      <document url="http://www.suscerte.gob.ve/images/norma-22-2008.pdf">Model of DPC for Certification Service Suppliers (CSS) in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/norma-027.pdf">Guide for Accreditation of CSS in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/SUSCERTENorma040_E21.pdf">Guide Technology Standards and Guidelines for Accreditation of CSS in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/norma-032.pdf">National Infrastructure of Electronic Certificate: Structure, Certificate, and CRL in Spanish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=489240</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="JCSI" 
              url="http://www.jcsinc.co.jp/english/index.html" status="complete">
    <summary>
    Japan Certification Services, Inc. (JCSI) is a commercial CA whose primary 
    market is Japan. Some of the relying parties are outside Japan, such as US, 
    Canada, European countries, and Asia. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young ShinNihon LLC</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=908&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="SecureSign RootCA11" status="complete">
      <summary>
      This root has one internally-operated subordinate CA for issuing SSL 
      certificates to the public. In the future, JCSI plans to add other 
      internally-operated subordinate CAs for S/MIME, Time Stamping, and other 
      certificate types.
      </summary>
        <data url="https://www2.jcsinc.co.jp/repository/certs/SSAD-rca.der"
        version="3"
        sha1="3B:C4:9F:48:F8:F3:73:A0:9C:1E:BD:F8:5B:B1:C3:65:C7:D8:11:B3"
        modulus="2048" 
        from="2009-04-07"
        to="2029-04-07"/>
      <crl url="http://ssignadcrl01.jcsinc.co.jp/repository/crl/rca.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.jcsinc.co.jp/english/repository/index.html">Repository</document>
      <document url="https://www2.jcsinc.co.jp/repository/SSAD-CPS-en.pdf">CP/CPS in English</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=496863</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Keynectis" url="http://www.keynectis.com/" status="incomplete">
    <summary>
    Keynectis is a French commercial CA that issues certificates to the general 
    public. Keynectis was created by merging two previous French certification 
    operators, Certplus and PK7.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.lsti.fr/">LSTI - La Sécurité des Technologies de l'Information</auditor>
      <document url="http://www.keynectis.com/PC/Certificat_conformite_ETSI_101-456.pdf">ETSI Certificate</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.fr/">KPMG</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=382979">Audit Report and Management's Assertion</document>
    </audit>
    <certificate name="Class 2 Primary CA" status="incomplete">
      <summary>
       This root is already included in NSS. The current request is to EV-enable the root. 
       A new, internally-operated subordinate CA has been created for issuing EV SSL 
       certificates.
      </summary>
      <data url="http://www.certplus.com/PC/certplus_class2.pem"
            version="3" 
            sha1="74:20:74:41:72:9C:DD:92:EC:79:31:D8:23:10:8D:C2:81:92:E2:BB" 
            modulus="2048" 
            from="1999-07-07" 
            to="2019-07-06"/>
      <crl url="http://trustcenter-crl.certificat2.com/keynectis/class2keynectisevca.crl">CRL</crl>
      <ocsp>http://kvalid.keynectis.com/evssl-ocsp/</ocsp>
      <type>OV, EV (Policy OID 1.3.6.1.4.1.22234.2.5.2.3.1)</type>
      <document url="http://www.keynectis.com/PC/CPS_KEYNECTIS_120407v1.1.pdf">Declaration des Pratiques de Certification (CPS in French)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=382981">EV SSL CPS (in English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_CP_RCA_0.6.pdf">Root CA CP (in English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_CP__KEYNECTIS_SSL_CA_CP_1.1s.pdf">SSL CP (in English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_PC_PC_AC_KEYNECTIS_SSL_1.2s.pdf">SSL CPS (in English)</document>
      <document url="https://www.keynectis.com/en/support-information/pc.html">Keynectis Information (in English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335392</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=379032</technical>
      </inclusion>
    </certificate>
  </authority>

</certificates>
