<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="pending.xsl"?>

<certificates type="pending">
  <authority name="ACCV" url="http://www.pki.gva.es/"  status="incomplete">
    <summary>
      ACCV (Autoritat de Certificacio de la Comunitat Valenciana) is 
      a CA operated by the government of the Valencia region of Spain.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.ssiconsultores.com/">
        Seguridad y Sistemas de Informacion S.L.</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=571&amp;file=pdf">
        Informe de Auditoria Independiente</document>
    </audit>

    <certificate name="Root CA Generalitat Valenciana" status="incomplete">
      <summary>
      </summary>
      <data url="http://www.pki.gva.es/gestcert/rootca.crt"
            version="3"
            sha1="A0:73:E5:C5:BD:43:61:0D:86:4C:21:13:0A:85:58:57:CC:9C:EA:46"
            modulus="2048"
            from="2001-07-06"
            to="2021-07-01">
      </data>
      <crl url="http://www.pki.gva.es/gestcert/rootgva_der.crl">CRL</crl>
      <ocsp>http://ocsp.pki.gva.es/</ocsp>
      <type>DV, IV</type>
      <document url="http://www.accv.es/pdf-politicas/ACCV-CPS-V1.7-v.pdf">
        Declaracion de Practicas de Certificacion (CPS) de la ACCV, v1.7 in Spanish
      </document>
      <document url="http://www.pki.gva.es/legislacion_c.htm">
        Certification policies and practices for the different types of certs (Spanish)
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=274100</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="KISA" url="http://www.rootca.or.kr/" status="pending">
    <summary>Korea Information Security Agency (KISA) is the
      Electronic Signature Authorization Management Center for South
      Korea. The Korean Certification Authority Central (KCAC) of KISA
      issues certificates to six (6) intermediate CAs ("licensed CAs"
      or LCAs), which then issue end entity certificates to Korean
      citizens, businesses, and other organizations.</summary>
    <audit type="Government (WebTrust equivalent)">
      <auditor url="http://www.mic.go.kr/">Ministry of Information and Communication, Republic of Korea</auditor>
      <document url="http://eng.mic.go.kr/eng/user.tdf?a=common.HtmlApp&amp;c=1001&amp;page=resources/resources_f_01.html&amp;mc=E_04_06">Public statement by MIC re KISA/KCAC audit</document>
    </audit>

    <certificate name="CertRSA01" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root is apparently being phased out in favor of the KISA
        RootCA 1.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa.der"
            version="3"
            sha1="F5:C2:7C:F5:FF:F3:02:9A:CF:1A:1A:4B:EC:7E:E1:96:4C:77:D7:84"
            modulus="2048"
            from="2000-03-03"
            to="2010-03-03"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-2459.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure (Korean)</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 1" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root CA is replacing CertRSA01.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa-3280.der"
            version="3"
            sha1="02:72:68:29:3E:5F:5D:17:AA:A4:B3:C3:E6:36:1E:1F:92:57:5E:AA"
            modulus="2048"
            from="2005-08-24"
            to="2025-08-24"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-3280.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 3" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
LCAs (Licensed CAs), not directly to end entities.</summary>
      <data url="http://www.rootca.or.kr/certs/root-wrsa.der"
            version="3"
            sha1="5F:4E:1F:CF:31:B7:91:3B:85:0B:54:F6:E5:FF:50:1A:2B:6F:C6:CF"
            modulus="2048"
            from="2004-11-19"
            to="2014-11-19"/>
      <crl url="http://www.rootca.or.kr/certs/root-wrsa.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <comments></comments>
  </authority>

  <authority name="S-TRUST" url="https://www.s-trust.de/" status="complete">
    <summary>Deutscher Sparkassen Verlag GmbH is the world's largest
      smartcard provider and the central certification service
      provider for all German savings banks. This CA exists to enable
      up to 40 million German customers (end-users) to use their
      banking card as a certificate based signature, encryption and
      authentication device.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6701UE.pdf">
      ETSI TS 101.456 Certificate</document>
    </audit>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6702UE.pdf">
      ETSI TS 102.042 Certificate</document>
    </audit>
    <certificate name="S-TRUST Qualified Root CA 2008-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate1/ordner_crt_dateien/S-TRUSTQualifiedRootCA2008-00l_v3_509.crt"
            version="3"
            sha1="C9:2F:E6:50:DB:32:59:E0:CE:65:55:F3:8C:76:E0:B8:A8:FE:A3:CA"
            modulus="2048"
            from="2007-12-31"
            to="2012-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2008001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
    <certificate name="S-TRUST Qualified Root CA 2007-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/STRUSTQualifiedRootCA2007-001.crt"
            version="3"
            sha1="7A:3C:1B:60:2E:BD:A4:A1:E0:EB:AD:7A:BA:4F:D1:43:69:A9:39:FC"
            modulus="2048"
            from="2006-12-31"
            to="2011-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2007001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
    <certificate name="S-TRUST Qualified Root CA 2006-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/S-TRUST_Qualified_Root_CA_2006-001_PN.crt"
            version="3"
            sha1="7D:DC:76:1C:FD:AF:4C:E0:3A:B5:3A:DD:C9:FA:13:35:19:A3:DE:C9"
            modulus="2048"
            from="2005-12-31"
            to="2010-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2006001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Not approved for inclusion.</comments>
    </certificate>
  </authority>

  <authority name="Austrian TCC" url="http://www.signatur.rtr.at/"      status="complete">
    <summary>The Telekom-Control Commission is the Austrian supervisory authority for electronic signatures. Its
responsibility includes supervision of all certification service providers
established in Austria. For every CA key used by an
Austrian certification service provider, the TKK issues a certificate to the
certification service provider. Based on these certificates, all certificates
issued by supervised Austrian certification service providers can be verified.
There are five subordinate CAs, each of which issues certificates for a different purpose.
</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.a-sit.at/">Secure Information Technology Center - Austria</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=204776">Conformity Assessment Statement</document>
    </audit>

    <certificate name="Telekom-Control-Kommission Top 1" status="complete">
      <summary>The TKK issues certificates to certification service providers who are
supervised according to the Austrian Electronic Signatures Act.
The corresponding private keys of certification service
providers are used for issuing certificates to end entities (signatories).</summary>
      <data url="http://www.signatur.rtr.at/currenttop.cer"
            version="3"
            sha1="91:49:29:EE:C7:A0:21:B5:DA:49:1A:35:A5:98:4C:2C:F2:5B:C7:55"
            modulus="2048"
            from="2005-09-13"
            to="2010-09-13"/>
      <crl url="http://www.signatur.rtr.at/current.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>

      <document url="http://www.signatur.rtr.at/repository/tkk-cp-10-20020909-de.pdf">Certificate
      Policy</document>
      <document url="http://www.signatur.rtr.at/repository/tkk-cps-14-20060612-de.pdf">Certificate
      Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373174</authorisation>
        <technical></technical>
      </inclusion>
      <comments>CRL doesn't work in Firefox - bug 133191.</comments>
    </certificate>
  </authority>

  <authority name="VeriSign" url="http://www.verisign.com/" status="incomplete">
    <summary>VeriSign is a major commercial CA with worldwide
    operations and customer base.</summary>
    <audit type="WebTrust CA and WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=304&amp;file=pdf">Audit
      Reports and Management's Assertions</document>
    </audit>
<certificate name="VeriSign Universal Root Certification Authority" status="incomplete">
      <summary>
        This request is to EV-enable this SHA256 root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. VeriSign is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=368998"
            version="3"
            sha1="36:79:CA:35:66:87:72:30:4D:30:A5:FB:87:3B:0F:A7:7B:B7:0D:54"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV, EV (Policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <document url="http://www.verisign.com/repository/hierarchy/hierarchy.pdf">CA Hierarchy Diagram</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=536318</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=515470</technical>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="VeriSign Class 3 Public Primary Certificate Authority - G4" status="incomplete">
      <summary>
        This request is to EV-enable this ECC root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. VeriSign is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=335538"
            version="3"
            sha1="22:D5:D8:Df:8F:02:31:D1:8D:F7:9D:B7:CF:8A:2D:64:C9:3F:6C:3A"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-4-11"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV, EV (Policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <document url="http://www.verisign.com/repository/hierarchy/hierarchy.pdf">CA Hierarchy Diagram</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=536318</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=515472</technical>
      </inclusion>
      <comments></comments>
    </certificate>
    
    <certificate name="VeriSign Class 1 Public Primary Certification Authority" status="approved">
      <summary>
      This root CA (also known as PCA1-G1-SHA1) has Signature Algorithm SHA-1.
      This root will supersede the PCA1-G1 root that is already included 
      in NSS, which has Signature Algorithm MD2.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375224"
            version="1"
            sha1="CE:6A:64:A3:09:E4:2F:BB:D9:85:1C:45:3E:64:09:EA:E8:7D:60:F1"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://crl.verisign.com/IndC1DigitalID.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>DV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <document url="http://www.verisign.com/repository/hierarchy/hierarchy.pdf">CA Hierarchy Diagram</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=515462</technical>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="VeriSign Class 2 Public Primary Certification Authority" status="pending">
      <summary>
      This root CA (also known as PCA2-G1-SHA1) has Signature Algorithm SHA-1.
      This root will supersede the PCA2-G1 root that is already included in 
      NSS, which has Signature Algorithm MD2.
      This root does not have any active sub-CAs, but VeriSign wants the root to be included 
      to enable their customers to read thair archived S/MIME mail.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375223"
            version="1"
            sha1="57:F0:3D:CE:FB:45:69:4C:1C:25:E6:EE:A0:2C:43:D7:52:38:D3:C4"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://crl.verisign.com/pca2.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <document url="http://www.verisign.com/repository/hierarchy/hierarchy.pdf">CA Hierarchy Diagram</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
      </inclusion>
      <comments> 
       As per Comment #40 in the bug, 
       VeriSign concurrs that this root does not need to be included in NSS.
      </comments>
    </certificate>

    <certificate name="VeriSign Class 3 Public Primary Certification Authority" status="approved">
      <summary>
      This root CA (also known as PCA3-G1-SHA1) has Signature Algorithm SHA-1.
      This root will supersede the PCA3-G1 root that is already included in 
      NSS, which has Signature Algorithm MD2.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375222"
            version="1"
            sha1="A1:DB:63:93:91:6F:17:E4:18:55:09:40:04:15:C7:02:40:B0:AE:6B"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-02"/>
      <crl url="http://crl.verisign.com/SVRSecure2005.crl">CRL</crl>
      <ocsp>http://ocsp.verisign.com</ocsp>
      <type>OV</type>
      <document url="http://www.verisign.com/repository/CPS/">VeriSign Certification Practice Statement</document>
      <document url="http://www.verisign.com/repository/vtnCp.html">VeriSign Trust Network Certificate Policies</document>
      <document url="http://www.verisign.com/repository/hierarchy/hierarchy.pdf">CA Hierarchy Diagram</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=490895</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=515462</technical>
      </inclusion>
      <comments>The initial request was also to EV-enable this root. However, it was deteremined that EV-enablement was not necessary.</comments>
    </certificate>
  </authority>

<authority name="GeoTrust" url="http://www.geotrust.com/" status="incomplete">
    <summary>GeoTrust is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust CA and WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=650&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="GeoTrust Primary Certificate Authority - G2" status="incomplete">
      <summary>
        This request is to EV-enable this ECC root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. GeoTrust is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
        </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=294057"
            version="3"
            sha1="8D:17:84:D5:37:F3:03:7D:EC:70:FE:57:8B:51:9A:99:E6:10:D7:B0"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-11-04"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV, EV (Policy OID 1.3.6.1.4.1.14370.1.6) </type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.1.2.pdf">GeoTrust Certification Practice Statement, Version 1.1.2</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/gt_ssl_SA_v.2.0.pdf">GeoTrust Subscriber Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/gt_ssl_rpa_v.1.0.pdf">GeoTrust Relying Party Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/reseller_agreement_5.0.pdf">GeoTrust Reseller Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/enterprisessl_agreement.pdf">GeoTrust EnterpriseSSL Agreement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=539255</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=517242</technical>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="GeoTrust Primary Certification Authority - G3" status="incomplete">
      <summary>
        This request is to EV-enable the SHA256 root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. 
        </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=368997"
            version="3"
            sha1="03:9E:ED:B8:0B:E7:A0:3C:69:53:89:3B:20:D2:D9:32:3A:4C:2A:FD"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV, EV (OID 1.3.6.1.4.1.14370.1.6)</type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.1.2.pdf">GeoTrust Certification Practice Statement, Version 1.1.2</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/gt_ssl_SA_v.2.0.pdf">GeoTrust Subscriber Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/gt_ssl_rpa_v.1.0.pdf">GeoTrust Relying Party Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/reseller_agreement_5.0.pdf">GeoTrust Reseller Agreement</document>
      <document url="http://www.geotrust.com/resources/cps/pdfs/enterprisessl_agreement.pdf">GeoTrust EnterpriseSSL Agreement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=539255</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=517234</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

 <authority name="thawte" url="http://www.thawte.com/" status="incomplete">
    <summary>thawte is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust/WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=527&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="thawte Primary Root CA - G2" status="incomplete">
      <summary>
        This request is to EV-enabled this ECC root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. thawte is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=335551"
            version="3"
            sha1="AA:DB:BC:22:23:8F:C4:01:A1:27:BB:38:DD:F4:1D:DB:08:9E:F0:12"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2007-11-04"
            to="2038-01-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV, EV (Policy OID 2.16.840.1.113733.1.7.48.1) </type>
      <document url="http://www.thawte.com/repository">Thawte Document Repository (English)</document>
      <document url="http://www.thawte.com/cps/index.html">Thawte CPS (English)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=539257</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=521869</technical>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="thawte Primary Root CA - G3" status="incomplete">
      <summary>
        This request is to EV-enabled this SHA256 root which is currently included in NSS.
        This CA will be used to sign certificates for SSL-enabled servers, 
        and may in the future be used to sign certificates for 
        digitally-signed executable code objects. thawte is not yet 
        actively issuing certificates from this root, so they have not 
        yet published a CRL. All subordinated CAs for this root will 
        be internally operated.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=369000"
            version="3"
            sha1="F1:8B:53:8D:1B:E9:03:B6:A6:F0:56:43:5B:17:15:89:CA:F3:6B:F2"
            modulus="2048"
            from="2008-04-01"
            to="2037-12-01"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV,OV, EV (Policy OID 2.16.840.1.113733.1.7.48.1) </type>
      <document url="http://www.thawte.com/repository">Thawte Document Repository (English)</document>
      <document url="http://www.thawte.com/cps/index.html">Thawte CPS (English)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=539257</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=521869</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>
  
  <authority name="A-Trust" url="https://www.a-trust.at/" status="incomplete">
    <summary>
      A-Trust is an accredited TrustCenter in Austria issuing smartcard based qualified 
      certificates for Austrian citizens used in eGovernment. A-Trust has been accredited 
      according to the Austrian Signature Law by Telekom-Control-Kommission, the Austrian 
      supervisory body.
      A-Trust’s product range comprises user certificates, developer certificates and corporate 
      certificates as well as consultation services and support with  the development of 
      e-commerce and signature applications in accordance with the Directive 1999/93/EC.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst &amp; Young</auditor>
      <document url="">In Progress</document>
    </audit>
    <certificate name="A-Trust-nQual-03" status="incomplete">
      <summary>
       The intermediate CAs below this CA issue smartCard-based certificates to a natural 
       person after a face-to-face identification (eg.: email), software certificates (pKCS#12), and
       server certificates (eg. SSL) after domain-verification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-03.crt"
            version="3"
            sha1="D3:C0:63:F2:19:ED:07:3E:34:AD:5D:75:0B:32:76:29:FF:D5:9A:F2"
            modulus="2048"
            from="2005-08-17"
            to="2015-08-17"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-03">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, OV</type>
      <document url="http://www.a-trust.at/docs/cp/a-sign-ssl/a-sign-ssl.pdf">SSL CP</document>
      <document url="http://www.a-trust.at/docs/cps/a-sign-ssl/a-sign-ssl_cps.pdf">SSL CPS</document>
      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=530797</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="A-Trust-Qual-01" status="incomplete">
      <summary>The intermediate CAs below this CA issue only qualified smartCard-based certificates
      to a natural person after a face-to-face identification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-01a.crt"
            version="3"
            sha1="E6:19:D2:5B:38:0B:7B:13:FD:A3:3E:8A:58:CD:82:D8:A8:8E:05:15"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    <comments>Bug #373746 was closed as Won't Fix due to lack of audit.</comments>
    </certificate>

    <certificate name="A-Trust-Qual-02" status="incomplete">
      <summary>The intermediate CAs below this CA issue qualified smartCard-based certificates to a natural person after a face-to-face identification,
   smartCard-based certificates to a natural person after a face-to-face identification (eg.: email), and
   server certificates (eg. SSL) after domain-verification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-02a.crt"
            version="3"
            sha1="67:9A:4F:81:FC:70:5D:DE:C4:19:77:8D:D2:EB:D8:75:F4:C2:42:C6"
            modulus="2048"
            from="2004-12-02"
            to="2014-12-02"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-02">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Bug #373746 was closed as Won't Fix due to lack of audit.</comments>
      </certificate>

    <certificate name="A-Trust-nQual-01" status="incomplete">
      <summary>The intermediate CAs below this CA issue smartCard-based certificates to a natural person after a face-to-face identification (eg.: email),
   software certificates (pKCS#12), and
   server certificates (eg. SSL) after domain-verification</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-01a.crt"
            version="3"
            sha1="51:A4:4C:28:F3:13:E3:F9:CB:5E:7C:0A:1E:0E:0D:D2:84:37:58:AE"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>
      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    <comments>Bug #373746 was closed as Won't Fix due to lack of audit.</comments>
    </certificate>
  </authority>

  <authority name="ARGE DATEN" url="http://www.a-cert.at/"              status="incomplete">
    <summary>ARGE DATEN, the Austrian Society for Data Protection is a non-profit
    non-governmental organisation. It is the Austrian market leader
in issuing certificates for eBilling. It operates subordinate CAs for eBilling,
SSL Server Certificates, SSL Client Certificates, and members of
governmental institutions.</summary>
<!--
    <audit type="Government">
      <auditor url="http://www.rtr.at/">Rundfunk und Telekom Regulierungs GmbH</auditor>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-globaltrust.html">GLOBALTRUST Audit</document>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-a-cert-advanced.html">A-CERT ADVANCED Audit</document>
      <document url="http://www.globaltrust.info/static/third-party-audits.pdf">List of Third Party Audits</document>
    </audit>
-->

    <certificate name="A-CERT ADVANCED" status="complete">
      <summary>This root certificate issues both end-user certificates and CA certificates.
      It is the current root certificate of ARGE DATEN.</summary>
      <data url="http://www.a-cert.at/static/a-cert-advanced.crt"
            version="3"
            sha1="29:64:B6:86:13:5B:5D:FD:DD:32:53:A8:9B:BC:24:D7:4B:08:C6:4D"
            modulus="2048"
            from="2004-10-23"
            to="2011-10-23"/>
      <crl url="http://www.a-cert.at/static/advanced.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.a-cert.at/static/a-cert-certificate-policy-english.pdf">A-CERT Certificate Policy v1.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="GLOBALTRUST" status="complete">
      <summary>This root certificate will not directly issue end-user certificates. It is used
      to issue the subordinate CA certificates which in turn issue the end-user
      certificates. This certificate is the
      successor to the A-CERT ADVANCED root certificate.</summary>
      <data url="http://www.globaltrust.info/static/globaltrust2006.crt"
            version="3"
            sha1="34:2C:D9:D3:06:2D:A4:8C:34:69:65:29:7F:08:1E:BC:2E:F6:8F:DC"
            modulus="4096"
            from="2006-08-07"
            to="2036-09-18"/>
      <crl url="http://www.globaltrust.info/static/globaltrust2006.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.globaltrust.eu/static/globaltrust-certificate-policy-english.pdf">GLOBALTRUST Certificate Policy v1.2</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Trustis" url="http://www.trustis.com/" status="incomplete">
    <summary>Trustis is a commercial CA operating primarily in the UK and Europe.</summary>
    <audit type="WebTrust Equivalent">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.trustis.com/pki/fps/policy/T-TSC-AUDIT-KPMG%20FPS%20Audit%20Report.pdf">Audit
      Report and Management Assertions</document>
    </audit>
    <audit type="tScheme">
      <auditor url="http://www.tscheme.org/about/index.html">tScheme</auditor>
      <document url="http://www.tscheme.org/directory/trustis/index.html">tScheme Grant of Approval</document>
    </audit>

    <certificate name="Trustis FPS Root CA" status="incomplete">
      <summary></summary>
      <data url="http://www.trustis.com/roots/fps/certs/fpsroot.crt"
            version="3"
            sha1="3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04"
            modulus="2048"
            from="2003-12-23"
            to="2024-01-21"/>
      <crl url="http://www.trustis.com/pki/fps/crl/fpsder.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>IV</type>

      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-certificate-policy-v1.04.pdf">Trustis FPS Root CP v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-PDS-v1.04.pdf">PKI Disclosure Statement v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/Trustis-Certification-Practice-Statement V1.1.pdf">Trustis CPS v1.1</document>

      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=324126</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Izenpe" url="http://www.izenpe.com/"    status="complete">
    <summary>Izenpe is owned by the government of the Basque country, Spain.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.bsi-global.com/ClientDirectory">BSI Management Systems</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=401406">ETSI Certificate</document>
    </audit>
    <audit type="WebTrust EV Readiness">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=359717">Audit Report and Management Assertions</document>
    </audit>
    <certificate name="Izenpe.com (Old Root)" status="complete">
      <summary>
        This is the original root, which is still needed. This root has four 
        internally-operated subordinate CAs. There are two sub-CAs for Qualified 
        certificates, one for Public Administration, and one for Citizens and Entities.  
        There are also two sub-CAs for non-Qualified certificates, one for Public 
        Administration and one for Citizens and Entities, which issue SSL Server, 
        Email, and Code Signing certs.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=385225"
            version="3"
            sha1="4A:3F:8D:6B:DC:0E:1E:CF:CD:72:E3:77:DE:F2:D7:FF:92:C1:9B:C7"
            modulus="2048"
            from="2003-01-30"
            to="2018-01-30"/>
      <crl url="http://crl.izenpe.com/cgi-bin/crl">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>OV</type>
      <document url="https://servicios.izenpe.com/jsp/descarga_ca/s27descarga_ca_c.jsp">CA Hierarchy</document>
      <document url="http://www.izenpe.com/cps">Links to CPS in Spanish, Basque, and English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/adjuntos/DPC%204.3%20ingles.pdf">CPS in English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/DPC%204.3%20castellano.pdf">CPS in Spanish</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/solicitar_certificado_digital.html">Certificate Specific Documentation</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Documentacin%20especfica%20%20SSL%20EV%20castellano.pdf">Procedures for EV SSL Secure Server Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Procedimiento_Servidor_castellano_06-01-10.pdf">Procedures for Secure Server Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Procedimiento_Firma_C%C3%B3digo_castellano_06-03-24.pdf">Procedures for Code Signing Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/cert_corporativos/es_cert/adjuntos/Documentaci%C3%B3n%20Espec%C3%ADfica%20Corporativo%20reconocido%20castellano.pdf">Procedures for Corporate Certificates (Spanish)</document>

      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="Izenpe.com (New Root, SHA-256)" status="complete">
      <summary>
       This is the new root, signed with SHA-256. 
       This root has five internally-operated subordinate CAs. 
       One sub-CA issues EV SSL certs. Two of the sub-CAs are for Qualified certificates, 
       one for Public Administration, and one for Citizens and Entities.  There are also 
       two sub-CAs for non-Qualified certificates, one for Public Administration and one 
       for Citizens and Entities, which issue SSL Server, Email, and Code Signing certs.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=385230"
            version="3"
            sha1="2F:78:3D:25:52:18:A7:4A:65:39:71:B5:2C:A2:9C:45:15:6F:E9:19"
            modulus="4096"
            from="2007-12-13"
            to="2037-12-13"/>
      <crl url="http://crl.izenpe.com/cgi-bin/crl2">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>OV, EV (Policy OID 1.3.6.1.4.1.14777.6.1.1)</type>
      <document url="https://servicios.izenpe.com/jsp/descarga_ca/s27descarga_ca_c.jsp">CA Hierarchy</document>
      <document url="http://www.izenpe.com/cps">Links to CPS in Spanish, Basque, and English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/informacion_juridica/es_i_juridi/adjuntos/DPC%204.3%20ingles.pdf">CPS in English</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/DPC%204.3%20castellano.pdf">CPS in Spanish</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/solicitar_certificado_digital.html">Certificate Specific Documentation</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Documentacin%20especfica%20%20SSL%20EV%20castellano.pdf">Procedures for EV SSL Secure Server Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Procedimiento_Servidor_castellano_06-01-10.pdf">Procedures for Secure Server Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/solicitar_certificado_digital/es_solicita/adjuntos/Procedimiento_Firma_C%C3%B3digo_castellano_06-03-24.pdf">Procedures for Code Signing Certificates (Spanish)</document>
      <document url="http://www.izenpe.com/s15-12020/es/contenidos/informacion/cert_corporativos/es_cert/adjuntos/Documentaci%C3%B3n%20Espec%C3%ADfica%20Corporativo%20reconocido%20castellano.pdf">Procedures for Corporate Certificates (Spanish)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TC TrustCenter" url="http://www.trustcenter.de/"     
             status="complete">
    <summary>
    TC TrustCenter GmbH  is a commercial company based in Germany, 
    with customers in all major regions of the world. TC TrustCenter 
    offers a variety of products and services including SSL Server 
    certificates and Email certificates.
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT Germany</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6711UE_s.pdf">ETSI TS 102 042 V2.1.1 EV Certificate</document>
    </audit>
    <certificate name="TC TrustCenter Universal CA III" status="complete">
      <summary>
       This root will eventually have an internally-operated subordinate CA for each registration 
       strength; “Class 1”, “Class 2”, “Class 3” and “Class 4”. This root currently has one 
       Class 4 subordinate CA, “TC TrustCenter Class 4 Extended Validation CA I”, which will 
       only issue EV certificates.
       This new root will co-exist with the “TC TrustCenter Universal CA I” root that is 
       currently included in NSS.
       This new root will effectively replace the "TC Universal CA II" root which was not 
       included in NSS. For this new root, TC TrustCenter generated a new key (supervised 
       by their auditor) to be compliant with the CA/B Forum guidelines.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=411063"
            version="3"
            sha1="96:56:cd:7b:57:96:98:95:d0:e1:41:46:68:06:fb:b8:c6:11:06:87"
            modulus="2048"
            from="2009-09-09"
            to="2029-12-31"/>
      <crl url="http://crl.tcuniversal-III.trustcenter.de/crl/v2/tc_universal_root_III.crl">CRL</crl>
      <ocsp>http://ocsp.tcuniversal-iii.trustcenter.de</ocsp>
      <type>OV, EV (policy OID 1.2.276.0.44.1.1.1.4)</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=411145">CPS (English)</document>
      <document url="http://www.trustcenter.de/cps">CPS</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">CP (English)</document>
      <document url="http://www.trustcenter.de/cpd">CP</document>
      <document url="http://www.trustcenter.de/infocenter/root_certificates.htm">All TC TrustCenter root certs</document>
       <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=436467</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="QuoVadis" url="http://www.quovadis.bm/" status="pending">
    <summary>QuoVadis is a commercial CA, based in Bermuda and
    operating globally.  QuoVadis is a Qualified Certification
    Services Provider in Switzerland.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst &amp; Young
      (Technology and Security Risk Services)</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=612&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document
      url="http://www.seco.admin.ch/sas/00229/00251/00254/index.html?lang=en">Swiss
      Accreditation Service statement</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/">Ernst &amp; Young</auditor>
      <document
      url="https://bugzilla.mozilla.org/attachment.cgi?id=288529">CA-supplied
      auditor's letter re WebTrust EV audit</document>
    </audit>

    <certificate name="QuoVadis Root CA 2" status="complete">
      <summary>This root will be used for SSL/device certificates,
      including standard "organisation validated" certificates as well
      as EV certificates. The associated EV policy OID is
      1.3.6.1.4.1.8024.0.2.100.1.2.</summary>
      <data url="http://www.quovadis.bm/public/qvrca2.crt"
            version="3"
            sha1="CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7"
            modulus="4096"
            from="2006-11-24"
            to="2031-11-24"
            ev-oid="1.3.6.1.4.1.8024.0.2.100.1.2"/>
      <crl url="http://crl.quovadisglobal.com/qvrca2.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV, EV</type>
      <document url="https://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.8.pdf">QuoVadis
      Root CA2 CP/CPS v1.8</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403665</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418701</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list (per bug 365281). The present request is to
      enable this CA certificate for EV.</comments>
    </certificate>

  </authority>

<!--
  <authority name="" url="" status="incomplete">
    <summary></summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url=""
            version=""
            sha1=""
            modulus=""
            from=""
            to=""/>
      <crl url="">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url=""></document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation></authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
-->

<!--
  <authority name="Visa" url="http://www.visaca.com/"                   status="incomplete">
    <summary>Certificates used with this root will be used with various Visa
websites associated with Visa products and services. Our main website is
visa.com.</summary>
    <audit type="">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.pem"
            version="3"
            sha1=""
            modulus="2048"
            from="2005-06-27"
            to="2025-06-29"/>
      <crl url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.crl">CRL</crl>
      <ocsp><!- - none - -></ocsp>
      <type>DV, IV</type>

      <document url=""></document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380067</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Certificate is served with the wrong content-type</comments>
  </authority>

  <authority name="ANCERT" url="http://www.ancert.com/"                 status="incomplete">
    <summary>ANCERT is the Notary Agency of Certification in Spain. It issues
    electronic recognized certificates to persons, companies, public corporations
    and others according to the requirements of the current Spanish regulations.</summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="Ancert Notarial" status="incomplete">
      <summary></summary>
      <data url="http://www.ancert.com/?do=productos.getDocuments&amp;group=certificados_notariales&amp;option=personal&amp;id=163"
            version="3"
            sha1="C0:9A:B0:C8:AD:71:14:71:4E:D5:E2:1A:5A:27:6A:DC:D5:E7:EF:CB"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTNOT.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="Ancert General Council of Notaries" status="incomplete">
      <summary></summary>
      <data url="http://www.notariado.org/n_tecno/feren/archivos/ANCERTCGN.crt"
            version="3"
            sha1="11:C5:B5:F7:55:52:B0:11:66:9C:2E:97:17:DE:6D:9B:FF:5F:A8:10"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTCGN.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Cert 1 is a BIN file</comments>
  </authority>

-->

  <authority name="DigiCert" url="http://www.digicert.com/" status="complete">
    <summary>DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert
provides digital certification and identity assurance services internationally
to a variety of sectors including business, education, and government.</summary>
    <audit type="WebTrust CA">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=845">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=962">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="DigiCert Assured ID Root CA" status="complete">
      <summary>
      This request is to enable the Code Signing trust bit for a root that is already in NSS.
      </summary>
      <data url="http://www.digicert.com/CACerts/DigiCertAssuredIDRootCA.crt"
            version="3" 
            sha1="05:63:B8:63:0D:62:D7:5A:BB:C8:AB:1E:4B:DF:B5:A8:99:B2:4D:43" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/ssl-cps-repository.htm">Document Repository</document>
      <document url="http://www.digicert.com/DigiCert_CPS.pdf">CPS</document>
      <document url="http://www.digicert.com/DigiCert_EV-CPS.pdf">CPS for EV</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=515425</authorisation>
      </inclusion>
    </certificate>

    <certificate name="DigiCert Global Root CA" status="complete">
      <summary>
      This request is to enable the Code Signing trust bit for a root that is already in NSS.
      </summary>
      <data url="http://www.digicert.com/CACerts/DigiCertGlobalRootCA.crt"
            version="3" 
            sha1="A8:98:5D:3A:65:E5:E5:C4:B2:D7:D6:6D:40:C6:DD:2F:B1:9C:54:36" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertGlobalRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/ssl-cps-repository.htm">Document Repository</document>
      <document url="http://www.digicert.com/DigiCert_CPS.pdf">CPS</document>
      <document url="http://www.digicert.com/DigiCert_EV-CPS.pdf">CPS for EV</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=515425</authorisation>
      </inclusion>
    </certificate>

    <certificate name="DigiCert High Assurance EV Root CA" status="complete">
      <summary>
      This request is to enable the Code Signing trust bit for a root that is already in NSS.
      </summary>
      <data url="http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt"
            version="3" 
            sha1="5F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV (policy OID 2.16.840.1.114412.2.1)</type>
      <document url="http://www.digicert.com/ssl-cps-repository.htm">Document Repository</document>
      <document url="http://www.digicert.com/DigiCert_CPS.pdf">CPS</document>
      <document url="http://www.digicert.com/DigiCert_EV-CPS.pdf">CPS for EV</document>
      <trust>  
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=515425</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Comodo" url="http://www.comodo.com/" status="incomplete">
    <summary>Comodo CA Ltd is a commercial CA based in the UK and
      serving customers worldwide. Comodo has eleven root CA certs
      already included in Mozilla, all of which it would like upgraded
      for EV use, and one additional EV root requested for
      inclusion. There are altogether 124 subordinate CAs signed by
      the root CAs listed below.  Some of them exist to differentiate
      between different Comodo brands or products and some are used to
      re-brand products for its partners. In each case Comodo retains
      the private key for the subordinate CA within its
      infrastructure.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=636&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.comodo.com/repository/ev_audit_report_and_management_assertions.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="AddTrust Class 1 CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustClass1CARoot.crt"
            version="3"
            sha1="CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustClass1CARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and code signing.</comments>
    </certificate>

    <certificate name="AddTrust External CA Root" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustExternalCARoot.crt"
            version="3"
            sha1="02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustExternalCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="AddTrust Public CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustPublicCARoot.crt"
            version="3"
            sha1="2A:B6:28:48:5E:78:FB:F3:AD:9E:79:10:DD:6B:DF:99:72:2C:96:E5"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustPublicCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and to enable all trust bits if not already
        enabled.</comments>
    </certificate>

    <certificate name="AddTrust Qualified CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustQualifiedCARoot.crt"
            version="3"
            sha1="4D:23:78:EC:91:95:39:B5:00:7F:75:8F:03:3B:21:1E:C5:4D:8B:CF"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustQualifiedCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="UTN - DATACorp SGC" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-DATACorpSGC.crt"
            version="3"
            sha1="58:11:9F:0E:12:82:87:EA:50:FD:D9:87:45:6F:4F:78:DC:FA:D6:D4"
            modulus="2048"
            from="1999-06-24"
            to="2019-06-24"/>
      <crl url="http://crl.comodoca.com/UTN-DATACorpSGC.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, code signing, and email.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Client Authentication and Email" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crt"
            version="3"
            sha1="B1:72:B1:A5:6D:95:F9:1F:E5:02:87:E1:4D:37:EA:6A:44:63:76:8A"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Hardware" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Hardware.crt"
            version="3"
            sha1="04:83:ED:33:99:AC:36:08:05:87:22:ED:BC:5E:46:00:E3:BE:F9:D7"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Hardware.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Object" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Object.crt"
            version="3"
            sha1="E1:2D:FB:4B:41:D7:D9:C3:2B:30:51:4B:AC:1D:81:D8:38:5E:2D:46"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Object.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, SSL, and email.</comments>
    </certificate>

    <certificate name="AAA Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AAACertificateServices.crt"
            version="3"
            sha1="D1:EB:23:A4:6D:17:D6:8F:D9:25:64:C2:F1:F1:60:17:64:D8:E3:49"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/AAACertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/November_2007_CPS_Amendment.pdf">November 2007 Addendum to the Comodo Certification Practice Statement v.3.0 (31 October 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_Intel_Pro.pdf">August 2007 Intel Pro SSL Addendum to the Comodo Certification Practice Statement v.3.0 (17 August 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_of_Version_3_UCC.pdf">March 2007 Unified Communications Addendum to the Comodo Certification Practice Statement v.3.0 (1 March 2007)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Secure Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/SecureCertificateServices.crt"
            version="3"
            sha1="4A:65:D5:F4:1D:EF:39:B8:B8:90:4A:4A:D3:64:81:33:CF:C7:A1:D1"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/SecureCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Trusted Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/TrustedCertificateServices.crt"
            version="3"
            sha1="E1:9F:E3:0E:8B:84:60:9E:80:9B:17:0D:72:A8:C5:BA:6E:14:09:BD"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/TrustedCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="Cisco" url="http://www.cisco.com/" status="incomplete">
    <summary>Cisco is a leading provider of networking equipment to
      consumers and businesses worldwide.
    </summary>

    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/">PricewaterhouseCoopers</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=728">Audit Report and Management Assertions</document>
    </audit>

    <certificate name="Cisco Root CA 2048" status="incomplete">

      <summary>This is an off-line root CA that issues CA certificates
        to one or more Cisco-controlled subordinate CAs (including the
        Cisco Manufacturing Sub-CA). The subordinate CAs in turn issue
        end entity certificates, e.g., for use in Cisco network
        equipment with embedded web servers and web-based
        administrative interfaces.
      </summary>
      <data url="http://www.cisco.com/security/pki/certs/crca2048.cer"
            version="3"
            sha1="DE:99:0C:ED:99:E0:43:1F:60:ED:C3:93:7E:7C:D5:BF:0E:D9:E5:FA"
            modulus="2048"
            from="2004-05-14"
            to="2029-05-14"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV</type>
      <document url="http://www.cisco.com/security/pki/policies/Certification_Practice_Statement_-_Cisco_Root_CA_2048_v1.1.doc">Cisco Root CA 2048
Certification Practice Statement, Version 1.1</document>
      <document url="http://www.cisco.com/security/pki/policies/Certificate_Policy_-_Cisco_Root_CA_2048_v1.0.doc">Cisco Root CA 2048 Certificate Policy, Version 1.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=416842</authorisation>
        <technical></technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Verizon / Cybertrust" url="http://www.verizonbusiness.com/us/products/security/identity/"                   status="complete">
    <summary>
      Verizon Business Security Solutions Powered by Cybertrust
      operates a commercial certificate authority service for
      businesses and governments internationally.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=799&amp;file=pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cybertrust.omniroot.com/repository/WT_EV_2008_SealFile.pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="GTE CyberTrust Global Root" status="complete">
      <summary>
        The request is to enable EV for this GTE CyberTrust Global Root 
        certificate, which is already included in NSS. This is presently
        Cybertrust's mainstream root, issuing their standard
        validation SSL server certificates, user authentication and
        secure email certificates, and code signing certificates. This
        root has existing subordinate CAs that are operated both
        internally and by third-parties. The sub-CAs are required to
        follow the CPS and to have regular audits. This CA will be
        superseded by the Baltimore CybertTrust Root.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=323777"
            version="1"
            sha1="97:81:79:50:d8:1c:96:70:cc:34:d8:09:cf:79:44:31:36:7e:f4:74"
            modulus="1024"
            from="1998-08-12"
            to="2018-08-13">
      </data>
      <crl url="http://www.public-trust.com/cgi-bin/CRL/2018/cdp.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV, EV (policy OID 1.3.6.1.4.1.6334.1.100.1)</type>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CP_v_2_3_cl.pdf"> Cybertrust CA Certificate Policy
      </document>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CPS_v_5_4.pdf"> Certification Practice Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=430694</authorisation>
        <technical></technical>
      </inclusion>
    <comments>During the public discussion it was decided that this root should not be enabled for EV. Therefore, the bug has been closed as won't fix.</comments>
    </certificate>
    <certificate name="Baltimore CyberTrust Root" status="pending">
      <summary>
        The request is to enable EV and add the Code Signing trust bit
        for the Baltimore CyberTrust Root certificate, which is already included 
        in NSS. This root will supersede Cybertrust's current
        mainstream root, GTE CyberTrust Global Root. When that
        happens, this root will have subordinate CAs that are operated
        both internally and by third-parties. The sub-CAs are required
        to follow the CPS and to have regular audits.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=323781"
            version="3"
            sha1="d4:de:20:d0:5e:66:fc:53:fe:1a:50:88:2c:78:db:28:52:ca:e4:74"
            modulus="2048"
            from="2000-05-12"
            to="2025-05-12">
      </data>
      <crl url="http://www.public-trust.com/cgi-bin/CRL/202501/cdp.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV, EV (policy OID 1.3.6.1.4.1.6334.1.100.1)</type>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CP_v_2_3_cl.pdf"> Cybertrust CA Certificate Policy
      </document>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CPS_v_5_4.pdf"> Certification Practice Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=430698</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="SSC" url="http://www.ssc.lt"  status="pending">
    <summary>
      SSC, Skaitmeninio Sertifkavimo Centras, is the Lithuanian Government accredited commercial CA issuing certificates to Government institutions, public services, businesses and citizens.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.ivpk.lt/main_en.php?cat=10&amp;gr=4">Information Society Development Committee Under The Government Of The Republic Of Lithuania
      </auditor>
      <document url= "http://www.ssc.lt/files/SSC%20CA%20Application%20to%20Trusted%20Root%20CA%20program.pdf">Statement of Compliance with ETSI TS 101.456</document>
      <document url= "http://epp.ivpk.lt/en/providers/">Lithuanian Government Qualified Certificate Service Provider</document>
    </audit>
    <certificate name="SSC Root CA A" status="complete">
      <summary>
        Root CA with four internally operated subordinate CAs: Class 1, Class 2, Qualified Class 3, and Qualified Class 3 VS.
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_a.crt"
            version="3"
            sha1="5a:5a:4d:af:78:61:26:7c:4b:1f:1e:67:58:6b:ae:6e:d4:fe:b9:3f"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-28">
      </data>
      <crl url="http://crl.ssc.lt/root-a/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="SSC Root CA B" status="complete">
      <summary>
        This Root CA is a special purpose CA that has no subordinate CAs. 
        Root B is used for single-root certificates (SSL, Code Signing, 
        OCSP, time stamping). 
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_b.crt"
            version="3"
            sha1="3e:84:d3:bc:c5:44:c0:f6:fa:19:43:5c:85:1f:3f:2f:cb:a8:e8:14"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-25">
      </data>
      <crl url="http://crl.ssc.lt/root-b/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <certificate name="SSC Root CA C" status="complete">
      <summary>
        Root C serves as a backup CA for Roots A and B. Just in case either 
        of those two roots become unusable and become revoked. According to 
        the government project that SSC is involved in, Root C will have to 
        be tested in a specific project where they must demonstrate availability 
        of its CRL and OCSP services. The project will accept Root C only if it 
        is a FireFox built-in object. If Root A does get revoked and Root C gets 
        put into service, then Root C will have four internally operated subordinate 
        CAs: Class 1, Class 2, Qualified Class 3, and Qualified Class 3 VS.
      </summary>
      <data url="http://www.ssc.lt/cacert/ssc_root_c.crt"
            version="3"
            sha1="23:e8:33:23:3e:7d:0c:c9:2b:7c:42:79:ac:19:c2:f4:74:d6:04:ca"
            modulus="4096"
            from="2006-12-27"
            to="2026-12-22">
      </data>
      <crl url="http://crl.ssc.lt/root-c/cacrl.crl">CRL</crl>
      <ocsp>http://ocsp.ssc.lt:2560</ocsp>
      <type>DV, OV</type>
      <document url="http://repository.ssc.lt/files/viesa-info/pki_disclosure_v1-0-0%5BLT%5D.pdf">
      PKI Disclosure Statement
      </document>
      <document url="http://repository.ssc.lt/files/cp/ssc_trusted_root_cp_v1-0-0%5BLT%5D.pdf">
      Certificate Practices
      </document>
      <document url="http://repository.ssc.lt/files/cps/ssc_trusted_root_cps_v1-0-0%5BLT%5D.pdf">
      Certificate Practices Statement
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=379152</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Certicamara S.A." url="http://www.certicamara.com"  status="complete">
    <summary>
      Sociedad Cameral de Certificación Digital - Certicámara S.A. is a 
      commercial CA primarily serving Colombia and Andean Region
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.com">Deloitte and Touche
      </auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=750&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Certificado Empresarial Clase-A" status="incomplete">
      <summary>
        This is the orginal root which expires in 2011. Certicámara 
        requests that this root also be added to the NSS database 
        because they have a significant number of customers that use it, 
        and their certificates expire in 2010. End entity certificates 
        have been issued directly from this root, rather than using an 
        offline root and issuing certs through a subordinate CA. 
      </summary>
      <data url="http://www.certicamara.com/certicamara.crt"
            version="3"
            sha1="8b:1a:11:06:b8:e2:6b:23:29:80:fd:65:2e:61:81:37:64:41:fd:11"
            modulus="2048"
            from="2001-05-23"
            to="2011-05-23">
      </data>
      <crl url="http://www.certicamara.com/certicamara.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.certicamara.com/certificate_hierarchy_diagram.jpg">Certificate Hierarchy
      </document> 
      <document url="http://www.certicamara.com/templates/cc/images/dpc/DPC_Julio_de_2008.pdf">Certificate Policy
      </document>
      <document url="http://www.certicamara.com/index.php?option=com_content&amp;task=category&amp;sectionid=22">Declaration of Practices
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=401262</authorisation>
        <technical></technical>
      </inclusion>
      <comments>This root will not be approved for inclusion.</comments>
    </certificate>
  </authority>

  <authority name="ICP-Brasil" url="http://www.icpbrasil.gov.br/" status="pending">
    <summary>
       ICP Brasil (Infra-Estrutura de Chaves Públicas Brasileira) 
       is Brazil's National PKI created by the law Medida 
       Provisória nº 2.200-2 / 2001.
       ICP Certificates are used in all secure Brazilian government 
       sites, other Brazilian sites and by financial institutions. 
       ICP-Brazil has the only (V0 and V1) chain operated by the ITI.
    </summary>
    <audit type="Internal">
      <auditor url="http://www.iti.gov.br/twiki/bin/view/Main/ComiteGestor">Auditor Website</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342298">Audit Hierarchy</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-08_-_v_2.0.pdf">Criteria and Procedures for Audit of ICP-Brasil</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-09_-_v_2.0.pdf ">Criteria and Procedures for Audit of ICP-Brasil sub-CAs</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/Resolucoes/RESOLU__O_29_DE_29_01_2004.PDF">Audit Committee</document>
    </audit>
    <certificate name="Autoridade Certificadora Raiz Brasileira" status="pending">
      <summary>
        Root cert used to secure Brazilian government and financial sites.
        This root has 8 subordinate CAs that are externally operated. 
      </summary>
      <data url="http://acraiz.icpbrasil.gov.br/CertificadoACRaiz.crt"
            version="3"
            sha1="8E:FD:CA:BC:93:E6:1E:92:5D:4D:1D:ED:18:1A:43:20:A4:67:A1:39"
            modulus="2048"
            from="2001-11-30"
            to="2011-11-30"/>
      <crl url="http://acraiz.icpbrasil.gov.br/LCRacraiz.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/EstruturaIcp/Estrutura_completa.pdf">Complete CA Hierarchy</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342297">Subordinate CA Hierarchy</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/EstruturaIcp">Companies operating the subordinate CAs</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-04_-_v._3.0.pdf"> CP (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-01_-_versao_4.0_retificada_em_15-01-09.pdf">CPS of CA-root (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-05_-_versao_3.1_(REQUISITOS_MIN._PARA_AS_DPCs_DAS_ACs).pdf">CPS requirements for sub-CA (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/DocIcp">ICP-Brasil Documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=438825</authorisation>
     </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="Autoridade Certificadora Raiz Brasileira v1" status="complete">
      <summary>
        This is the next version of the Autoridade Certificadora 
        Raiz Brasileira root, which is used to secure Brazilian 
        government and financial sites.
      </summary>
      <data url="http://acraiz.icpbrasil.gov.br/ICP-Brasil.crt"
            version="3"
            sha1="70:5D:2B:45:65:C7:04:7A:54:06:94:A7:9A:F7:AB:B8:42:BD:C1:61"
            modulus="2048"
            from="2008-07-29"
            to="2021-07-29"/>
      <crl url="http://acraiz.icpbrasil.gov.br/LCRacraizv1.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/EstruturaIcp/Estrutura_completa.pdf">Complete CA Hierarchy</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=342297">Subordinate CA Hierarchy</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/EstruturaIcp">Companies operating the subordinate CAs</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-04_-_v._3.0.pdf"> CP (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-01_-_versao_4.0_retificada_em_15-01-09.pdf">CPS of CA-root (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/pub/Certificacao/DocIcp/DOC-ICP-05_-_versao_3.1_(REQUISITOS_MIN._PARA_AS_DPCs_DAS_ACs).pdf">CPS requirements for sub-CA (Portuguese)</document>
      <document url="http://www.iti.gov.br/twiki/bin/view/Certificacao/DocIcp">ICP-Brasil Documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=438825</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Camerfirma" url="http://www.camerfirma.com" status="complete">
    <summary>
    AC Camerfirma S.A. is a commercial CA issuing certificates for companies 
    primarily in Spain. Camerfirma is the digital certification authority for 
    Chambers of Commerce in Spain.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=874">Audit Report and Management's Assertions</document>
    </audit>
        <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="http://docs.camerfirma.com/mod_web/usuarios/pdf/Informe_agrupado_Camerfirma_WebTrust_EV.pdf">Audit Report and Management's Assertions (Spanish)</document>
      <document url="http://docs.camerfirma.com/mod_web/usuarios/pdf/Informe_agrupado_Camerfirma_EV_English.pdf">Audit Report and Management's Assertions (English)</document>
    </audit>
    <certificate name="Chambers of Commerce Root - 2008" status="complete">
      <summary>
       This CA has four internally-operated subordinate CAs that issue certificates 
       for Spanish companies and representatives. Chambers of Commerce act as RAs 
       for end user registration.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=339325"
            version="3"
            sha1="78:6a:74:ac:76:ab:14:7f:9c:6a:30:50:ba:9e:a8:7e:fe:9a:ce:3c"
            modulus="4096"
            from="2008-08-01"
            to="2038-07-31"/>
      <crl url="http://crl.camerfirma.com/camerfirma_cserver-2009.crl">CRL</crl>
      <ocsp>http://ocsp.camerfirma.com</ocsp>
      <type>OV, EV (Policy OIDs 1.3.6.1.4.1.17326.10.14.2.1.2 and 1.3.6.1.4.1.17326.10.14.2.2.2) </type>
      <document url="http://www.camerfirma.com/mod_web/usuarios/pdf/CPS_3.1.1.pdf">Certificate Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406968</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Global Chambersign Root - 2008" status="complete">
      <summary>
       This CA has internally-operated subordinate CAs that issue certificates for 
       general use globally. Other companies act as RAs for end user registration.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=339324"
            version="3"
            sha1="4a:bd:ee:ec:95:0d:35:9c:89:ae:c7:52:a1:2c:5b:29:f6:d6:aa:0c"
            modulus="4096"
            from="2008-08-01"
            to="2038-07-31"/>
      <crl url="http://crl.camerfirma.com/racer-2009.crl">CRL</crl>
      <ocsp>http://ocsp.camerfirma.com</ocsp>
      <type>OV, EV (Policy OIDs 1.3.6.1.4.1.17326.10.8.12.1.2 and 1.3.6.1.4.1.17326.10.8.12.2.2)</type>
      <document url="http://www.camerfirma.com/mod_web/usuarios/pdf/CPS_3.1.1.pdf">Certificate Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406968</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Hongkong Post" url="http://www.hongkongpost.gov.hk/index.html" status="approved">
    <summary>
     Hongkong Post is a government agency and is a recognized CA under 
     the law of Hong Kong Special Administrative Region (HKSAR) of China, 
     and has been issuing digital certificates under the e_Cert brand name 
     to individuals and organizations of HKSAR since January 2000. 
     Hongkong Post CA operations have been outsourced to E-Mice Solutions. 
     This is documented in the CPS and the Management Assertions. 
     The WebTrust audit covers both Hongkong Post and E-Mice CA operations.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/">PricewaterhouseCoopers</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=125">Audit Report and Management Assertions</document>
    </audit>
    <certificate name="Hongkong Post Root CA 1" status="approved">
      <summary>
       This root has only one direct subordinate, Hongkong Post e-Cert CA 1, 
       which is the signer key and is used to issue different types of recognized 
       e-Certs to individuals and organizations.  
      </summary>
      <data url="http://www.hongkongpost.gov.hk/product/download/root/img/smartid_rt.cacert"
            version="3"
            sha1="D6:DA:A8:20:8D:09:D2:15:4D:24:B5:2F:CB:34:6E:B2:58:B2:8A:58"
            modulus="2048"
            from="2003-05-15"
            to="2023-05-15"/>
      <crl url="http://crl1.hongkongpost.gov.hk/crl/eCertCA1CRL1.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.hongkongpost.gov.hk/product/cps/ecert/img/cps_en23.pdf">Certificate Practice Statement for e-Certs</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=408949</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=541499</technical>
      </inclusion>
      <comments>File NSS bug after the CRL issues have all been resolved.</comments>
    </certificate>
  </authority>

  <authority name="Sertifitseerimiskeskus AS" url="http://www.sk.ee" status="approved">
    <summary>
    SK (Certification Centre, legal name AS Sertifitseerimiskeskus) is a 
    commercial CA, covering the Baltic region (Estonia, Lithuania, Latvia). 
    SK is Estonia's primary certification authority, providing certificates 
    for authentication and digital signing to Estonian ID Cards. Established in 
    2001, SK has the backing of Estonian and Nordic financial and telecom sector. 
    SK’s customers include the Estonian court system and notaries, Central Bank 
    and commercial banks, and enforcement organisations (e.g. Police).
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ee/">KPMG Estonia</auditor>
      <document url="http://www.sk.ee/file.php?id=457">Audit Report</document>
    </audit>
    <certificate name="Juur-SK" status="approved">
      <summary>
       This root issues three types of internally operated subordinate CAs. 
       The first type of subordinate CA is used to issue electronic ID cards 
       which contain certificates for digital signature and for digital 
       identification. 
       The second type of subordinate CA is used to issue internal ID cards 
       of the Republic of Estonia. 
       The third type of subordinate CA is used to issue device and SSL certificates.
      </summary>
      <data url="http://www.sk.ee/files/JUUR-SK.der"
            version="3"
            sha1="40:9D:4B:D9:17:B5:5C:27:B6:9B:64:CB:98:22:44:0D:CD:09:B8:89"
            modulus="2048"
            from="2001-08-30"
            to="2016-08-26"/>
      <crl url="http://www.sk.ee/pages.php/0202040202,36">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.sk.ee/files/tree.pdf">Certificate Hierarchy Diagram</document>
      <document url="http://www.sk.ee/file.php?id=432">Certificate Practice statement</document>
      <document url="http://www.sk.ee/files/eid-sk-1.0.pdf">EID-SK Certificate Policy</document>
      <document url="http://www.sk.ee/file.php?id=252">ESTEID-SK Certificate Policy</document>
      <document url="http://www.sk.ee/file.php?id=434">KLASS3-SK Certificate Policy</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=414520</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=532742</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="VAS Latvijas Pasts" url="http://www.pasts.lv/en" status="incomplete">
    <summary>
    Latvijas Pasts (Latvian Post) is a commercial CA operating primarily in 
    Latvia, targeting also Estonia and Lithuania. Latvian Post provides 
    certificate services to banks and postal services to the legal entities 
    and private individuals of the Republic of Latvia. Their accreditation 
    certification services include electronic signature certificates that are 
    issued according with local legislations (Electronic Document Law), smart 
    cards with two certificates (authentication and qualified signature) used 
    for authentication and document signing in Latvia, and SSL certificates 
    and Code Signing certificates for customers in European Union. 
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.lv/">KPMG Latvia</auditor>
      <document url="http://www.dvi.gov.lv/edokumenti/aplieciba/">Accreditation Certificate by Data State Inspection</document>
    </audit>
    <certificate name="VAS Latvijas Pasts SSI(RCA)" status="incomplete">
      <summary>
      This root CA issues an intermediate Policy CA, which issues the 
      Issuing CAs for Certificate Service Providers (CSPs). 
      </summary>
      <data url="http://www.e-me.lv/aia/vas%20latvijas%20pasts%20ssi(rca).crt"
            version="3"
            sha1="08:64:18:e9:06:ce:e8:9c:23:53:b6:e2:7f:bd:9e:74:39:f7:63:16"
            modulus="4096"
            from="2006-09-13"
            to="2024-09-13"/>
      <crl url="ldap://e-me.lv">CRL</crl>
      <ocsp>http://ocsp.e-me.lv/responder.eme</ocsp>
      <type>OV</type>
      <document url="https://www.e-me.lv/csp-web/certupload.aspx">Certificate Status Check Tool</document>
      <document url="http://info.e-me.lv/en/atbalsts/CA_sertif/">Download links for the root and intermediate CAs</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CP_SP_v3_1.doc">Certificate Policy of the Certification Service Providers</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_RCA_SN_SSI_v2_5.doc">Certificate Practice Statement of the Root CA</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_PCA_SN_PSI_v2_5.doc">Certificate Practice Statement of the Policy CA</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_ICA_SN_ISI_v2_62.doc">Certificate Practice Statment of the Issuing CAs of the Certification Service Providers</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_CPS_IC_CPS_v1_2.doc">Certificate Practice Statement of the Infrastructure Certificates</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_LZP_TP_v2_5.doc">Time-Stamp Policy</document>
      <document url="http://info.e-me.lv/en/dokumenti/LP_LZN_TPS_v2_61.doc">Time Stamp Authority Practice Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=412747</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="VAS LVRTC" url="http://www.lvrtc.lv/eng/" status="complete">
    <summary>
     VAS Latvia State Radio And Television Centre (LVRTC) is a joint-stock company. 
     The Republic of Latvia being represented by the Ministry of Transportation owns all 
     shares of the company.
     LVRTC provides transmission of radio and television signals covering all of Latvia. 
     LVRTC also provides electronic document law enforcement in Latvia. 
    </summary>
    <audit type="ETSI TS 101 456">
      <auditor url="http://www.kpmg.lv/">KPMG Baltics</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=402071">Audit Statement</document>
    </audit>
    <certificate name="E-ME SSI (RCA)" status="complete">
      <summary>
      This root CA issues an intermediate Policy CA, which issues the 
      Issuing CAs for Certificate Service Providers (CSPs). 
      </summary>
      <data url="http://www.eme.lv/aia/E-ME%20SSI%20(RCA).crt"
            version="3"
            sha1="c9:32:1d:e6:b5:a8:26:66:cf:69:71:a1:8a:56:f2:d3:a8:67:56:02"
            modulus="4096"
            from="2009-05-19"
            to="2027-05-19"/>
      <crl url="http://info.e-me.lv/en/atbalsts/atsauktie_sertif/">CRL</crl>
      <ocsp>http://ocsp.eme.lv/responder.eme</ocsp>
      <type>OV</type>
      <document url="http://info.e-me.lv/en/pakalpojumi/dokumentacija/lvrtc_policies_and_regulations.html">LVRTC Policies and Regulations</document>
      <document url="http://info.e-me.lv/en/atbalsts/CA_sertif/">Download links for the root and intermediate CAs</document>
      <document url="http://info.e-me.lv/lv/dokumenti/eme_dokumentacija/E-ME_CP_SP_v1.doc">Certificate Policy (English)</document>
      <document url="http://info.e-me.lv/lv/dokumenti/eme_dokumentacija/E-ME_CPS_RCA_SN_SSI_v1.doc">CPS of Root CA (English)</document>
      <document url="http://info.e-me.lv/lv/dokumenti/eme_dokumentacija/E-ME_CPS_PCA_SN_PSI_v1.doc">CPS of Policy CA (English)</document>
      <document url="http://info.e-me.lv/lv/dokumenti/eme_dokumentacija/E-ME_CPS_ICA_SN_ISI_v1.doc">CPS of Issuing CA (English)</document>
      <document url="http://info.e-me.lv/lv/dokumenti/eme_dokumentacija/E-ME_CPS_IC_CPS_v1.doc">CPS of Infrastructure Certificates (Latvian)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=406189">Certificate Selling Procedure (Latvian)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=518098</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="FNMT" url="http://www.cert.fnmt.es" status="incomplete">
    <summary>
     Fábrica Nacional de Moneda y Timbre (FNMT) is a government agency that 
     provides services to Spain as a national CA.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.bsi-global.com">BSI Management Systems B.V</auditor>
      <document url="http://www.cert.fnmt.es/content/pages_std/docs/ETSI.pdf">Auditor Statement of ETSI Compliance</document>
    </audit>
    <certificate name="FNMT Clase 2 CA" status="incomplete">
      <summary>
       This root has no subordinate CAs, and has modulus length of 1024. 
       FNMT will be transitioning end-entity certs from this root to the new root. 
       However, Spanish users still need the “FNMT Clase 2 CA” because there are 
       more than 2,200,000 certificates issued that will be active for several years. 
       This root issues Qualified Certificates to natural persons according to 
       Qualified Certificates Certification Policy (1.3.6.1.4.1.5734.3.5), 
       Spanish Electronic Signature Law (59/2003) rules, and  ETSI TS 101 456. 
      </summary>
      <data url="http://www.cert.fnmt.es/content/pages_std/certificados/FNMTClase2CA.cer"
            version="3"
            sha1="43:F9:B1:10:D5:BA:FD:48:22:52:31:B0:DO:08:2B:37:2F:EF:9A:54"
            modulus="1024"
            from="1999-03-18"
            to="2019-03-18"/>
      <crl url="ldap://ldap.cert.fnmt.es">CRL</crl>
      <ocsp>http://apus.cert.fnmt.es/appsUsuario/ocsp/OcspResponder</ocsp>
      <type>OV</type>
      <document url="http://www.cert.fnmt.es/dpc/dpc.pdf">Certification Practice Statement (Spanish)</document>
      <document url="http://www.cert.fnmt.es/dpc/dgpc.pdf">Certification Practice Statement General (Spanish)</document>
      <document url="http://www.cert.fnmt.es/dpc/ape/dpc.pdf">Policy and Certification Practices for Electronic Signature (Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435736</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="AC RAIZ FNMT-RCM" status="incomplete">
      <summary>
      This is the new root, which the certificates from the “FNMT Clase 2 CA” 
      hierarchy will be transitioned to. 
      </summary>
      <data url="http://www.cert.fnmt.es/certs/ACRAIZFNMTRCM.crt"
            version="3"
            sha1="B8:65:13:0B:ED:CA:38:D2:7F:69:92:94:20:77:0B:ED:86:EF:BC:10"
            modulus="4096"
            from="2008-10-29"
            to="2029-12-31"/>
      <crl url="ldap://ldap.cert.fnmt.es">CRL</crl>
      <ocsp>http://apus.cert.fnmt.es/appsUsuario/ocsp/OcspResponder</ocsp>
      <type>OV</type>
      <document url="http://www.cert.fnmt.es/dpc/dpc.pdf">Certification Practice Statement (Spanish)</document>
      <document url="http://www.cert.fnmt.es/dpc/dgpc.pdf">Certification Practice Statement General (Spanish)</document>
      <document url="http://www.cert.fnmt.es/dpc/ape/dpc.pdf">Policy and Certification Practices for Electronic Signature (Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435736</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="TURKTRUST" url="http://www.turktrust.com.tr/" status="incomplete">
    <summary>
    TURKTRUST Information Security Services Inc. is a public corporation and 
    is an IT company based in Turkey. 
    TURKTRUST is an authorized qualified electronic certificate service provider 
    according to the Turkish Electronic Signature Law. TURKTRUST issues qualified 
    certificates, time-stamping services, SSL certificates, and object signing certificates.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Telecommunications Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=264748">Letter of Official CA Statement</document>
      <document url="http://www.tk.gov.tr/eimza/eshs.htm">List of accredited CAs</document>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/tt.doc">Audit statement on auditor website</document>
    </audit>
    <certificate name="TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı" status="incomplete">
      <summary>
      This is an offline root with one internally-operated subordinate CA that 
      issues qualified electronic certificates in accordance with 
      Turkish Electronic Signature Law. 
      </summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/TURKTRUST_Elektronik_Sertifika_Hizmet_Saglayicisi_s3.crt"
            version="3"
            sha1="F1:7F:6F:B6:31:DC:99:E3:A3:C8:7F:FE:1C:F1:81:10:88:D9:60:33"
            modulus="2048"
            from="2007-12-25"
            to="2017-12-22"/> 
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL_s3.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=322073">Certification Practice Statement</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=322069">Certificate Hierarchy</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=433845</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Swiss BIT" url="http://www.bit.admin.ch/index.html?lang=en" status="pending">
    <summary>
    Swiss BIT is also known as the Federal Office of Information Technology and 
    Telecommunication (FOITT) which operates servers and software applications for the 
    Confederation (one of the biggest employers in Switzerland) and third parties. The 
    FOITT also operates a carrier network for the Federal administration and organisations 
    close to the administration. Various, partly encrypted, virtual private networks (VPN) 
    are operated on this carrier network. Overall the FOITT serves 1200 locations in 
    Switzerland and 200 locations worldwide. The FOITT is also responsible for networking 
    the Swiss cantons and the Principality of Liechtenstein.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG SA Switzerland</auditor>
      <document url="https://bug435026.bugzilla.mozilla.org/attachment.cgi?id=385981">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Admin-Root-CA" status="pending">
      <summary>
      This root has three internally-operated subordinate CAs, with two currently in 
      operation. The sub-CAs issue certificates for hardware tokens to be used 1) for 
      identification, digital signatures, encryption, and authentication of individuals 
      2) for qualified digital signatures. The hardware tokens are issued to employees 
      of an administrative unit (federal, cantonal or municipal administration) who 
      already have their information published in Swiss BIT's Admin-Directory.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=377526"
            version="3"
            sha1="25:3f:77:5b:0e:77:97:ab:64:5f:15:91:55:97:c3:9e:26:36:31:d1"
            modulus="2048"
            from="2001-11-15"
            to="2021-11-10"/> 
      <crl url="http://www.pki.admin.ch/crl/Admin-Root-CA.crl">CRL</crl>
      <ocsp>http://ocsp.pki.admin.ch</ocsp>
      <type>DV, OV</type>
      <document url="http://www.pki.admin.ch">Admin PKI Repository</document>
      <document url="http://www.bit.admin.ch/adminpki/00247/index.html">Hierarchy Diagram</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=374130">CP/CPS for AdminPKI - Class A (English Translation)</document>
      <document url="http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_1_4.pdf">CP/CPS for AdminPKI - Class A</document>
      <document url="http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_1_3_FR.pdf">CP/CPS for AdminPKI-Class B</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435026</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="AdminCA-CD-T01" status="complete">
      <summary>
      This root does not have subordinate CAs. It issues end-entity certificates directly 
      for users/organizations and devices/servers for identification, digital signatures, 
      encryption, code/document signing, webserver authentication (SSL), and application 
      server authentication. These certificates may be applied for by members of an 
      administrative unit (federal, cantonal or municipal administration) that have concluded 
      a framework agreement and SLA with Swiss BIT.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=377531"
            version="3"
            sha1="6b:81:44:6a:5c:dd:f4:74:a0:f8:00:ff:be:69:fd:0d:b6:28:75:16"
            modulus="2048"
            from="2006-01-25"
            to="2016-01-25"/> 
      <crl url="http://www.pki.admin.ch/crl/AdminCA-CD-T01.crl">CRL</crl>
      <ocsp>http://ocsp.pki.admin.ch</ocsp>
      <type>DV, OV</type>
      <document url="http://www.pki.admin.ch">Admin PKI Repository</document>
      <document url="http://www.bit.admin.ch/adminpki/00247/index.html">Hierarchy Diagram</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=376403">AdminPKI CP/CPS Class CD-T01 (English)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=382263">Process Description for Provisioning Server certificates (German)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=435026</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Disig" url="http://www.disig.eu" status="approved">
    <summary>
    Disig is a public Certification Service Provider, located in Slovakia. 
    Disig is a member of international ASSECO Group, one of the strongest 
    software houses in the CEE region. Asseco is a leader in selected IT 
    segments in countries across Central and Eastern Europe. 
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.scientia.sk/">Scientia</auditor>
      <document url="https://bug455878.bugzilla.mozilla.org/attachment.cgi?id=418236">Audit Statement</document>
   </audit>
    <certificate name="CA Disig" status="approved">
      <summary>
      This root has no subordinate CAs, issuing end-entity certs 
      for SSL, email, and code signing directly.
      </summary>
        <data url="http://www.disig.eu/ca/cert/ca_disig.der"
        version="3"
        sha1="2a:c8:d5:8b:57:ce:bf:2f:49:af:f2:fc:76:8f:51:14:62:90:7a:41"
        modulus="2048" 
        from="2006-03-21" to="2016-03-21"/>
      <crl url="http://www.disig.eu/ca/crl/ca_disig.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.disig.eu/_pdf/cp-disig.pdf">CP Version 4.0 (Slovak)</document>
      <document url="http://www.disig.sk/_pdf/cps_ra_cadisig.pdf">CPS Version 4.0 (Slovak)</document>
      <document url="https://bug455878.bugzilla.mozilla.org/attachment.cgi?id=384717">CP Version 3.4 (English)</document>
      <document url="http://www.disig.eu/index.php?id=ca&amp;L=1">Disig Certification Authority Website</document>
      <document url="http://www.disig.eu/_pdf/bp-disig.pdf">Security Policy (Slovak)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=455878</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=539235</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Staat der Nederlanden" url="http://www.logius.nl/english/" status="approved">
    <summary>
     Staat der Nederlanden is the Netherlands national government CA. The Dutch 
     governmental PKI hierarchy consists of 2 roots. This first root, Staat der 
     Nederlanden Root CA, is already included in NSS. The second root is the 
     next generation, Staat der Nederlanden Root CA – G2. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://cert.webtrust.org/SealFile?seal=683&amp;file=pdf">Audit Report and Management Asserstions</document>
   </audit>
    <certificate name="Staat der Nederlanden Root CA - G2" status="approved">
      <summary>
       This is the next generation of the Staat der Nederlandend Root CA that 
       is currently in the Mozilla store. The PKIoverheid issues two internally 
       operated subordinate CAs, which issue subordinate CAs to CSPs. The CSPs 
       are commercial and governmental organizations. Each CSP has to prove that 
       it complies with ETSI TS 101 456 and the Dutch law on electronic signatures. 
       CSPs must conclude a contract with a representative of a government 
       organization or commercial company before issuing end-entity certificates. 
       A request for a certificate is always signed by a specified representative 
       of a government organization or commercial company. 
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=408102"
        version="3"
        sha1="59:af:82:79:91:86:c7:b4:75:07:cb:cf:03:57:46:eb:04:dd:b7:16"
        modulus="4096" 
        from="2008-03-26" 
        to="2020-03-25"/>
      <crl url="http://crl.pkioverheid.nl/">CRL</crl>
      <type>OV</type>
      <document url="http://www.logius.nl/english/products/">Description of PKI Overheid (English)</document>
      <document url="http://www.logius.nl/fileadmin/logius/product/pkioverheid/documenten/CPS%20PA%20PKIoverheid%20v3.2.pdf">Certification Practice Statement of the Policy Authority PKI Overheid (Dutch)</document>
      <document url="http://www.logius.nl/fileadmin/logius/product/pkioverheid/documenten/pve/PvE%20deel2%20v2.1.pdf">CP for CSPs (Dutch)</document>
      <document url="http://www.logius.nl/fileadmin/logius/product/pkioverheid/documenten/pve/PvE%20deel3a%20v2.1.pdf">Certificate Policy Part 3a for employees of governmental organizations or commercial companies (Dutch)</document>
      <document url="http://www.logius.nl/fileadmin/logius/product/pkioverheid/documenten/pve/PvE%20deel3b%20v2.1.pdf">Certificate Policy Part 3b for SSL services of governmental organizations or commercial companies (Dutch)</document>
      <document url="http://www.logius.nl/fileadmin/logius/product/pkioverheid/documenten/pve/PvE%20deel3c%20v2.1.pdf">Certificate Policy Part 3c for personal use of civilians (Dutch)</document>
      <document url="http://www.logius.nl/producten/toegang/pkioverheid/aansluiten/programma-van-eisen/#c1618 ">Schedule of Requirements (Dutch) </document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=436056</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=529874</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Serasa S.A." url="http://www.serasa.com.br/us/index.htm" status="incomplete">
    <summary>
    Serasa has 5 CAs under ICP-Brasil and 4 CAs not linked to ICP-Brasil. 
    This request is in regards to the CAs not linked to ICP-Brasil.
    Serasa is a subsidiary of Experian which is a public, global corporation.
    Serasa is an economic and financial analysis and information firm with global 
    coverage. Serasa has presence in all Brazilian state capitals and major cities, 
    and is the holder of Latin America's largest data bank on individuals, businesses 
    and corporate concerns. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.deloitte.com.br">Deloitte Touche Tohmatsu</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=347519">Auditor Statement from 2004</document>
   </audit>
    <certificate name="Serasa Certificate Authority I" status="incomplete">
      <summary>
       Serasa CA I provides and sells digital certificates for general public that 
       need to sign electronic documents or be authenticated in a website.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAI.cer"
        version="3"
        sha1="a7:f8:39:0b:a5:77:05:09:6f:d3:69:41:d4:2e:71:98:c6:d4:d9:d5"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAI.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority II" status="incomplete">
      <summary>
      Serasa CA II provides and sells server and code signing certificates for 
      corporations.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAII.cer"
        version="3"
        sha1="31:e2:c5:2c:e1:08:9b:ef:fd:da:db:26:dd:7c:78:2e:bc:40:37:bd"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAII.cer">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority III" status="incomplete">
      <summary>
       Serasa CA III provides CA certificates for Serasa and their clients in CA business.  
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAIII.cer"
        version="3"
        sha1="9e:d1:80:28:fb:1e:8a:97:01:48:0a:78:90:a5:9a:cd:73:df:f8:71"
        modulus="2048" 
        from="2004-11-26" 
        to="2024-11-21"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIII.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="Serasa Certificate Authority IV" status="incomplete">
      <summary>
      Serasa CA IV provides and sells digital certificates for general public that 
      need to sign any kind of electronic documents or be authenticated in a website. 
      It has also “Smart Card Logon” (OID 1.3.6.1.4.1.311.20.2.2) applied.
      </summary>
        <data url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/SerasaCAIV.cer"
        version="3"
        sha1="1b:4c:a3:c4:74:a4:4b:56:c8:22:41:98:14:29:20:78:65:4f:11:6f"
        modulus="2048" 
        from="2005-07-04" 
        to="2025-06-29"/>
      <crl url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/crl/SerasaCAIV.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/dpc/declaracao-ca.pdf">Certificate Policy</document>
      <document url="http://publicacao.certificadodigital.com.br/repositorio/serasaca/pc/politica-ca.pdf">Certificate Practices Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=457921</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Finnish Population Register" 
              url="http://www.vrk.fi" status="pending">
    <summary>
     The Population Register Centre operates under the Finland Ministry of Finance 
     to develop and maintain the national Population Information System, the guardianship 
     register and the Public Sector Directory Service. The Population Register Centre serves 
     as the Certification Authority for the State of Finland, and thus develops and maintains 
     the national certificate services to Finnish Citizens, state workers and organizations. 
     All certificates issued to natural persons by the Population Register Centre are qualified 
     certificates, i.e. European-wide certificates based on an EU Directive and Finnish legislation.
    </summary>
    <audit type="ETSI TS 101.456 equivalent for Qualified Certificates">
      <auditor url="http://www.ficora.fi">Finnish Communications Regulatory Authority (FICORA)</auditor>
      <document url="https://bug463989.bugzilla.mozilla.org/attachment.cgi?id=406413">Audit Statement</document>
      <document url="http://www.ficora.fi/index/palvelut/palvelutaiheittain/sahkoinenallekirjoitus/varmentajarekisteri.html">QC Certificate on FICORA website</document>
    </audit>
    <audit type="ETSI TS 101.456 equivalent for Websites and Code Signing Certificates">
      <auditor url="http://www.inspecta.com">Inspecta Finland</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=416747">Auditor Statement</document>
    </audit>
    <certificate name="VRK Gov. Root CA" status="pending">
      <summary>
        This root issues internally-operated intermediate CAs.
      </summary>
        <data url="http://www.fineid.fi/certs/vrkrootc.crt"
        version="3"
        sha1="fa:a7:d9:fb:31:b7:46:f2:00:a8:5e:65:79:76:13:d8:16:e0:63:b5"
        modulus="2048" 
        from="2002-12-18"
        to="2023-12-18"/>
      <crl url="http://proxy.fineid.fi/crl/vrkspc.crl">CRL</crl>
      <type>IV/OV</type>
      <document url="http://www.fineid.fi/vrk/fineid/home.nsf/pages/index_eng">Technical Specifications</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/24EA4C4CD4A1EAA0C2257054002A55BD/$file/S2v21.pdf">FINEID Specification S2 - CA-model and certificate contents</document>
      <document url="http://www.fineid.fi/vrk/fineid/home.nsf/pages/FA842EE9BB3C7AA5C2257054002D3FA9">Links to Intermediate CAs</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/B2BC1F39CB3F28AAC225742E004BA2DF/$file/srvcps20080501.pdf">Service Provider for Server CPS in Finnish</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/7AC8EFBD063A723BC225742C001EA6BC/$file/ccps20080501en.pdf">Smartcard Citizen Certificates CPS in English</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/F7A72F2FAD5E83B3C225742C00372EFD/$file/ocps20080501en.pdf">Smartcard Qualified Certificates CPS in English</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/9BB25E8FA98D6D6FC22574F300410999/$file/tccps20081101.pdf">Smartcard Temporary Certificates CPS in Finnish</document>
      <document url="http://www.fineid.fi/vrk/fineid/files.nsf/files/AAF4DE2FF17E1015C225742E004B8B3D/$file/spcps20080501.pdf">Software Cert Service Provider for E-mail Use CPS in Finnish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=463989</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="D-TRUST" 
              url="https://www.d-trust.net/internet/content/e_index.html" status="incomplete">
    <summary>
     D-TRUST GmbH is a wholly owned subsidiary of Bundesdruckerei 
     (100% Governmental), and is the only German trust center authorised 
     to perform sovereign tasks. The primary market is the German speaking 
     area (Austria, Germany, Switzerland) and B2B focused. 
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuevit.de/">TÜV-IT Germany</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6704UE.pdf">Audit Certificate</document>
    </audit>
    <certificate name="D-TRUST Root Class 3 CA 2007" status="incomplete">
      <summary>
        This root will eventually have three internally-operated subordinate 
        CAs. It currently has one subordinate CA called D-TRUST Service 
        Class 3 CA 1 2008 which issues website certificates. The other two 
        subordinate CAs that will be created will be for email and code signing.
      </summary>
        <data url="https://www.d-trust.net/cgi-bin/D-TRUST_Root_Class_3_CA_2007.crt"
        version="3"
        sha1="FD:1E:D1:E2:02:1B:0B:9F:73:E8:EB:75:CE:23:43:6B:BC:C7:46:EB"
        modulus="2048" 
        from="2007-05-16"
        to="2022-05-16"/>
      <crl url="http://www.d-trust.net/crl/d-trust_service_class_3_ca_1_2008.crl">CRL</crl>
      <ocsp>http://ssl.ocsp.d-trust.net</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=361775">D-TRUST-Root PKI Certification Practice Statement in English</document>
      <document url="http://www.d-trust.net/internet/files/D-TRUST_Root_PKI_CPS.pdf ">CPS in German</document>
      <document url="http://www.d-trust.net/internet/files/D-TRUST_Root_PKI_CP.pdf ">CP in German</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=467891</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="ACEDICOM" 
              url="http://acedicom.edicomgroup.com/en/index.htm" status="pending">
    <summary>
     The Edicom Certification Authority (ACEDICOM) provides companies, communities 
     and physical persons with secure electronic identification mechanisms that 
     enable them to engage in activities where the digital signature replaces the 
     handwritten with identical legal guarantees. To this end, ACEDICOM issues 
     certificates in accordance with the stipulations of Directive 1999/93/EC of 
     13th December 1999 and Law 59/2003 of 19th December, on electronic signature, 
     and so has sufficient recognition to operate in all countries of the European 
     Union. The Edicom CA is responsible for obtaining the corresponding official 
     authorisation in those places outside the Union where it operates commercially.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/es">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=1001">Audit Report and Management's Assertsions</document>
    </audit>
    
    <certificate name="ACEDICOM Root" status="pending">
      <summary>
      This root has three internally-operated subordinate CAs. The ACEDICOM 01 
      subordinate CA issues Qualified certificates for identification and advanced 
      electronic signature, for the use of physical persons or legal organisations. 
      The ACEDICOM 02 subordinate CA issues certificates for purposes other than 
      Qualified electronic signature. The ACEDICOM Servidores subordinate CA issues 
      server/client certificates and code signing certificates.
      </summary>
        <data url="http://acedicom.edicomgroup.com/archivos/certificados/ACEDICOM%20Root.crt"
        version="3"
        sha1="e0:b4:32:2e:b2:f6:a5:68:b6:54:53:84:48:18:4a:50:36:87:43:84"
        modulus="4096" 
        from="2008-04-18"
        to="2028-04-13"/>
      <crl url="http://acedicom.edicomgroup.com/rootca.crl">Root CRL</crl>
      <ocsp>http://ocsp.acedicom.edicomgroup.com/acedicom01</ocsp>
      <type>OV</type>
      <document url="http://acedicom.edicomgroup.com/en/archivos/politicas/ACEDICOM_CertificationPractice.pdf">CPS in English</document>
      <document url="http://acedicom.edicomgroup.com/es/archivos/politicas/ACEDICOM_PracticasCertificacion.pdf">CPS in Spanish</document>
      <document url="http://acedicom.edicomgroup.com/en/contenidos/practicasyPoliticas/punto1.htm">Declaration of Certification Practices and Policies according to Certificate Type</document>
      <document url ="http://acedicom.edicomgroup.com/es/archivos/politicas/ACEDICOM%20-%20Politica%20Certificados%20TLS.pdf">TLS Certificate Policy (in Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=471045</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="NetLock" 
              url="http://www.netlock.hu/USEREN/index.html" status="approved">
    <summary>
     NetLock Ltd. is a qualified Certificate Authority in Hungary that issues certificates to organizations and individuals.
    </summary>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="http://webold.nhh.hu/esign/setLanguageAction.do?lang=en">National Communications Authority, Hungary</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=365687">Statement of audit conformance in English</document>
      <document url="http://webold.nhh.hu/esign/szolgReszlet/init.do?tipus=mi&amp;azon=12201521-2-41">Statement of the NCA that Netlock is a Qualified Service Provider</document>
    </audit>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="http://www.cert-hungary.hu">CERT-Hungary</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=378081">Cover letter of the rDSP audit in Hungarian</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=378711">English Translation of part of the rDSP Audit Report</document>
   </audit>
    <certificate name="NetLock Arany (Class Gold) Főtanúsítvány" status="approved">
      <summary>
       NetLock currently has four separate root CAs included in NSS. The redesigned 
       equivalent of these existing roots will be created under this new root. 
       The new root will sign seven internally-operated subordinate CAs. Two of those 
       subordinate CAs will sign sub-CAs that will be externally-operated by 
       MKB (Hungarian Trade Bank) and MNB (National Bank of Hungary). 
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=365241"
        version="3"
        sha1="06:08:3f:59:3f:15:a1:04:a0:69:a4:6b:a9:03:d0:06:b7:97:09:91"
        modulus="2048" 
        from="2008-12-11"
        to="2028-12-06"/>
      <crl url="http://crl1.netlock.hu/index.cgi?crl=cbca">CRL for Class B</crl>
      <ocsp>http://ocsp1.netlock.hu/gold.cgi</ocsp>
      <type>OV</type>
      <document url="https://bug480966.bugzilla.mozilla.org/attachment.cgi?id=374930">CA Hierarchy</document>
      <document url="http://www.netlock.hu/USEREN/html/dok.html">Practice Statements and Terms of Agreements in Hungarian</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=364923">CPS in English</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366607">Verification Practice for Non-Qualified certificates </document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366794">Non-qualified certificate CRL and OCSP profile definitions</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366795">Certificate Issuance Practice Statement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=480966</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=532201</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="CATCert" 
              url="http://www.catcert.net" status="incomplete">
    <summary>
     CATCert is the Catalan Agency of Certification (Agència Catalana de Certificació).
     CATCert’s aim is to provide digital certification services and promote the usage 
     of digital signature in order to make safer the communications within the Catalan 
     government and the communications (within and for) the Catalan government.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/es">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=466&amp;file=pdf">Audit Report and Management Assertions</document>
    </audit>
    <certificate name="EC-ACC" status="incomplete">
      <summary>
      This root has seven internally-operated subordinate CAs. The subordinate CAs 
      are used to distinguish who the certificates are issued to.  The EC-IDCAT 
      certificates are issued to Catalan citizens.  The EC-SAFP (a sub-CA of EG-GENCAT), 
      EC-AL, and EC-PARLAMENT certificates are not issued to the general public, but 
      only to the civil servants and computers or devices of the Regional Catalan 
      government, the Catalan Government, and the Catalan Parliament. The EC-UR and 
      EC-URV certificates are not issued to the general public, but to employees, 
      students and computers or devices of Catalan universities and research centers 
      connected to the “Anella Científica” group, and the Universitat Rovira i 
      Virgili (URV).
      </summary>
        <data url="http://www.catcert.net/descarrega/acc.crt"
        version="3"
        sha1="28:90:3A:63:5B:52:80:FA:E6:77:4C:0B:6D:A7:D6:BA:A6:4A:F2:E8"
        modulus="2048" 
        from="2003-01-07"
        to="2031-01-07"/>
      <crl url="http://epscd.catcert.net/crl/ec-acc.crl">CRL</crl>
      <ocsp>http://ocsp.catcert.net</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=379561">CA Hierarchy Diagram</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184501">English version of  CPS</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184504">CPS in Catalan</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=184505">CP in Catalan</document>
      <document url="http://www.catcert.net/registre">The CPS/CP for each sub-CA in Catalan</document>
      <document url="https://bug295474.bugzilla.mozilla.org/attachment.cgi?id=387876">Operative Procedure in Catalan</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=295474</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="E-Guven" 
              url="http://www.e-guven.com" status="complete">
    <summary>
      E-Guven is a private corporation that serves certificates mainly the 
      Turkish market and they plan to expand their market to other countries.
      E-Guven certificates are used in Public projects, such as www.turkiye.gov.tr,
      and Mobile Signature as well. 
      E-Guven also develops B2B secure transaction projects.
    </summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.tk.gov.tr">Republic of Turkey Telecommunicatins Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=421006">Audit Statement</document>
    </audit>
    <certificate name="e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi" status="complete">
      <summary>
       This root certificate signs SSL certificates directly. 
       Additionally, this root has the following three intermediate CAs: 
       E-Guven Mobile CA issues mobile certificates for end users; 
       E-Guven NES CA issues qualified electronic certificates for Turkish citizens; 
       and E-Guven Secure Client Certificates issues Class 3 certificates. 
       All of the intermediate CAs chaining up to this root are operated internally 
       by e-Guven.
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=367292"
        version="3"
        sha1="dd:e1:d2:a9:01:80:2e:1d:87:5e:84:b3:80:7e:4b:b1:fd:99:41:34"
        modulus="2048" 
        from="2007-01-04"
        to="2017-01-04"/>
      <crl url="http://sil.e-guven.com/ElektronikBilgiGuvenligiASSSLClient/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp2.e-guven.com/ocsp.xuda</ocsp>
      <type>OV</type>
      <document url="https://bug476428.bugzilla.mozilla.org/attachment.cgi?id=360065">CA Hierarchy</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=400444">Qualified Electronic CP (GKNESI) in Turkish</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=400445">Mobility Qualified Electronic CP (MKNESI) in Turkish</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=400445">Qualified Electronic Cert Application Basics (NESUE) in Turkish</document>
      <document url="https://bug476428.bugzilla.mozilla.org/attachment.cgi?id=403222">SSL Cert Application Basics (SUE) in Turkish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=476428</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Japanese LGPKI" 
              url="http://www.lgpki.jp/" status="incomplete">
    <summary>
      In Japan there are two root CAs, one is GPKI which acts as a root for national 
      government agencies, and the other one is LGPKI (Local Government PKI) which 
      serves the same function for regional and local governments. LGPKI is controlled 
      by the Local Government Wide Area Network (LGWAN) Operation Committee. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.deloitte.com/jp">Deloitte Touche Tohmatsu</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=840&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Japan Local Government PKI Application CA" status="incomplete">
      <summary>
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=371920"
        version="3"
        sha1="96:83:38:F1:13:E3:6A:7B:AB:DD:08:F7:77:63:91:A6:87:36:58:2E"
        modulus="2048" 
        from="2006-03-31"
        to="2016-03-31"/>
      <crl url="http://www.lgpki.jp/Information/CRL/AppCACrl.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.lgpki.jp/unei/C-6-3-5_CPCPS_ApCA_20070320.pdf">CP/CPS in Japanese</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=396252">English translation of part of the LGPKI CP/CPS</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=396253">English translation of part of the LGPKI Registration Authority Branch Operation Handbook</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=477314</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="ICA" 
              url="http://www.ica.cz/gb/" status="incomplete">
    <summary>
     První certifikační autorita, a.s. (First certification authority - I.CA), is the 
     largest provider in the field of issuing and administrating the certificates in 
     the Czech republic. It renders its services in the Slovak republic as well. There 
     have been already more than million of issued certificates registered till today.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="">Jozef Vyskoc,P hD., Certified Information Systems Auditor (CISA) no. 9616941</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=396182">Audit Statement</document>
    </audit>
    <certificate name="I.CA - Qualified root certificate" status="incomplete">
      <summary>
      </summary>
        <data url="http://www.ica.cz/userdata/pages/4/qica_root_20080311.der"
        version="3"
        sha1="64:90:2a:d7:27:7a:f3:e3:2c:d8:cc:1d:c7:9d:e1:fd:7f:80:69:ea"
        modulus="2048" 
        from="2008-04-01"
        to="2018-04-01"/>
      <crl url="http://qcrldp1.ica.cz/qica08.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.ica.cz/userdata/pages/2/CP_QCv2.5.pdf">CP in Czech</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484171</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="I.CA - Standard root certificate" status="incomplete">
      <summary>
      </summary>
        <data url="http://www.ica.cz/userdata/pages/4/sica_root_20080311.der"
        version="3"
        sha1="ab:16:dd:14:4e:cd:c0:fc:4b:aa:b6:2e:cf:04:08:89:6f:de:52:b7"
        modulus="2048" 
        from="2008-04-01"
        to="2018-04-01"/>
      <crl url="http://scrldp1.ica.cz/sica08.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.ica.cz/userdata/pages/2/CP_KC_21.pdf">CP in Czech</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=484171</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="SUSCERTE" 
              url="http://www.suscerte.gob.ve/" status="incomplete">
    <summary>
     SUSCERTE stands for Superintendencia de Servicios de Certificación Electrónica, 
     which is part of the Ministry of People's Power for Telecommunications and 
     Informatics in the Bolivarian Republic of Venezuela. SUSCERTE is a national 
     government CA that provides electronic certification services to the Bolivarian 
     Republic of the Government of Venezuela. 
    </summary>
    <audit type="ETSI TS 101.456, ETSI 102.042">
      <auditor url="">Mariclen Villegas</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=381829">Audit Statement in Spanish</document>
    </audit>
    <certificate name="Autoridad de Certificacion Raiz del Estado Venezolano" status="incomplete">
      <summary>
      This root CA is the Root Certification Authority of Venezuela’s National 
      Infrastructure of Electronic Certification. The main function of this root 
      is to issue the intermediate CAs to the Certification Service Suppliers (CSS) 
      of the public and private sector, according to the Law on Data Messages and 
      Electronic Signature (LSMDFE). Once a CSS has been accredited by SUSCERTE according 
      to the LSMDFE, the CSS must issue the certificates in accordance with the purpose of 
      the electronic certificates specified in their own Declaration of Practices of 
      Certification and Policy of Certificates.
      </summary>
        <data url="https://bugzilla.mozilla.org/attachment.cgi?id=375214"
        version="3"
        sha1="DD:83:C5:19:D4:34:81:FA:D4:C2:2C:03:D7:02:FE:9F:3B:22:F5:17"
        modulus="4096" 
        from="2007-02-16"
        to="2027-02-11"/>
      <crl url="http://www.suscerte.gob.ve/lcr">CRL</crl>
      <ocsp>http://ocsp.suscerte.gob.ve</ocsp>
      <type>OV</type>
      <document url="http://acraiz.suscerte.gob.ve/dpc/DPC_AC_RAIZ_V1.0.pdf">Declaration of Practices of Certification (DPC) of root in Spanish</document>
      <document url="http://acraiz.suscerte.gob.ve/dpc/DPC_AC_RAIZ_V1.0_en.pdf">DPC of root in English</document>
      <document url="http://www.suscerte.gob.ve/images/norma-22-2008.pdf">Model of DPC for Certification Service Suppliers (CSS) in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/norma-027.pdf">Guide for Accreditation of CSS in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/SUSCERTENorma040_E21.pdf">Guide Technology Standards and Guidelines for Accreditation of CSS in Spanish</document>
      <document url="http://www.suscerte.gob.ve/images/norma-032.pdf">National Infrastructure of Electronic Certificate: Structure, Certificate, and CRL in Spanish</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=489240</authorisation>
      </inclusion>
      <comments>SUSCERTE has decided to have each of its sub-CAs apply separately for inclusion in NSS as separate trust anchors.</comments>
    </certificate>
  </authority>

  <authority name="JCSI" 
              url="http://www.jcsinc.co.jp/english/index.html" status="approved">
    <summary>
    Japan Certification Services, Inc. (JCSI) is a commercial CA whose primary 
    market is Japan. Some of the relying parties are outside Japan, such as US, 
    Canada, European countries, and Asia. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young ShinNihon LLC</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=908&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="SecureSign RootCA11" status="approved">
      <summary>
      This root has one internally-operated subordinate CA for issuing SSL 
      certificates to the public. In the future, JCSI plans to add other 
      internally-operated subordinate CAs for S/MIME, Time Stamping, and other 
      certificate types.
      </summary>
        <data url="https://www2.jcsinc.co.jp/repository/certs/SSAD-rca.der"
        version="3"
        sha1="3B:C4:9F:48:F8:F3:73:A0:9C:1E:BD:F8:5B:B1:C3:65:C7:D8:11:B3"
        modulus="2048" 
        from="2009-04-07"
        to="2029-04-07"/>
      <crl url="http://ssignadcrl01.jcsinc.co.jp/repository/crl/rca.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.jcsinc.co.jp/english/repository/index.html">Repository</document>
      <document url="https://www2.jcsinc.co.jp/repository/SSAD-CPS-en.pdf">CP/CPS in English</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
          </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=496863</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=542798</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Keynectis" url="http://www.keynectis.com/" status="complete">
    <summary>
    Keynectis is a French commercial CA that issues certificates to the general 
    public. Keynectis was created by merging two previous French certification 
    operators, Certplus and PK7.
    </summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.lsti.fr/">LSTI - La Sécurité des Technologies de l'Information</auditor>
      <document url="http://www.lsti-certification.fr/index.php?option=com_content&amp;view=article&amp;id=58&amp;Itemid=53&amp;lang=fr">ETSI Certificate</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.fr/">KPMG</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=382979">Audit Report and Management's Assertion</document>
    </audit>
    <certificate name="Class 2 Primary CA" status="complete">
      <summary>
       This root is already included in NSS. The current request is to EV-enable the root. 
       A new, internally-operated subordinate CA has been created for issuing EV SSL 
       certificates.
      </summary>
      <data url="http://www.certplus.com/PC/certplus_class2.pem"
            version="3" 
            sha1="74:20:74:41:72:9C:DD:92:EC:79:31:D8:23:10:8D:C2:81:92:E2:BB" 
            modulus="2048" 
            from="1999-07-07" 
            to="2019-07-06"/>
      <crl url="http://trustcenter-crl.certificat2.com/keynectis/class2keynectisevca.crl">CRL</crl>
      <ocsp>http://kvalid.keynectis.com/evssl-ocsp/</ocsp>
      <type>OV, EV (Policy OID 1.3.6.1.4.1.22234.2.5.2.3.1)</type>
      <document url="http://www.keynectis.com/PC/CPS_KEYNECTIS_120407v1.1.pdf">Declaration des Pratiques de Certification (CPS in French)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=387860">CPS for EV SSL CA (English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_CP_RCA_0.6.pdf">Root CA CP (English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_CP__KEYNECTIS_SSL_CA_CP_1.1s.pdf">SSL CP (English)</document>
      <document url="https://www.keynectis.com/static/content/common/pc-dpc/DSQ_PC_PC_AC_KEYNECTIS_SSL_1.2s.pdf">SSL CPS (English)</document>
      <document url="https://www.keynectis.com/en/support-information/pc.html">Keynectis Information (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335392</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=379032</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="GlobalSign" url="http://www.globalsign.com/" status="complete">
    <summary>
      GlobalSign is a commercial CA based in Portsmouth NH and
      serving customers worldwide. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/be/">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=928&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/be">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=929&amp;file=pdf">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="GlobalSign Root CA – R3" status="complete">
      <summary>
      This is the SHA256 version of the GlobalSign root (SHA1) that is already included 
      in NSS. This root is primarily suitable for Server and Client Authentication, 
      Secure e-mail, Code Signing and Timestamping. However the root itself is marked 
      for all issuance policies and therefore can also be used for OCSP, Encrypting File 
      System, IP Sec (Tunnel, User) and CA Encryption Certificate purposes.  
      The root has been created (A ceremony to WebTrust audited standards witnessed by 
      Ernst and Young). However, this root is not yet active, so no CRL or OCSP service 
      has yet been provided for it. GlobalSign will be supporting a new certificate 
      hierarchy in 2010 based on this SHA256 root. 
      </summary>
      <data url="http://secure.globalsign.net/cacert/Root-R3.crt"
            version="3" 
            sha1="D6:9B:56:11:48:F0:1C:77:C5:45:78:C1:09:26:DF:5B:85:69:76:AD" 
            modulus="2048" 
            from="2009-03-18"
            to="2029-03-18"/>
      <crl url="">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV, EV (policy OID 1.3.6.1.4.1.4146.1.1)</type>
      <document url="http://www.globalsign.com/repository/">Repository of All Legal Documents</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v6.5.pdf">GlobalSign Certification Practice Statement v6.5</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CA_CP_v3.4.pdf">GlobalSign CA Certificate Policy v3.4</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=507360</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Microsec" url="http://www.e-szigno.hu/" status="complete">
    <summary>Microsec Ltd. is a Hungarian certificate authority.</summary>
    <audit type="Government, ETSI TS 101.456  equivalent">
      <auditor url="http://webold.nhh.hu/esign/szolgParams/main.do">Hungarian Government National Communications Authority</auditor>
      <document url="http://srv.e-szigno.hu/menu/docs/NhhSupervision2009.pdf">Authority statement</document>
    </audit>
    <certificate name="Microsec e-Szigno Root CA 2009" status="complete">
      <summary>This is a new, SHA256, version of the Microsec SHA1 root that is already 
      included in NSS. The new root has a new DN and a new key. Microsec plans to operate 
      the two roots simultaneously for some years, and the old one shall be phased out 
      afterwards. Under the new root, Microsec issues certificates with an OCSP service 
      usable for the general public. </summary>
      <data url="http://www.e-szigno.hu/rootca2009.crt"
            version="3"
            sha1="a6:5c:b4:73:3d:94:a5:c8:65:a8:64:64:7c:2c:01:27:2c:89:b1:43"
            modulus="2048"
            from="2009-06-16"
            to="2029-12-30"/>
      <crl url="http://crl.e-szigno.hu/rootca2009.crl">CRL for this root</crl>
      <crl url="http://srv.e-szigno.hu/menu/index.php?lap=english_crl">List of CRLs</crl>
      <ocsp>http://a3ocsp2009.e-szigno.hu</ocsp>
      <type>OV</type>
      <document url="http://srv.e-szigno.hu/menu/index.php?lap=english_ca_hierarchy#rootca2009">Certificate 
      Hierarchy in English</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--altalanos--v2.0.pdf">CPS in Hungarian, v2.0</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--altalanos--v1.6--EN.doc">CPS in English, v1.6</document>
      <document url="http://srv.e-szigno.hu/menu/index.php?lap=english_dokszab">Microsec CP and CPS documents</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=510506</authorisation>

      </inclusion>
    </certificate>
  </authority>

  <authority name="NIC" url="http://nicca.nic.in" status="incomplete">
    <summary>National Informatics Centre (NIC), is part of the Department of 
    Information Technology of the Government of India.
</summary>
    <audit type="Government, WebTrust CA equivalent">
      <auditor url="http://www.cyberqindia.com">CyberQ Consulting Pvt. Ltd.</auditor>
      <document url="https://bug511380.bugzilla.mozilla.org/attachment.cgi?id=405987">Auditor Statement</document>
    </audit>
    <certificate name="NIC Certifying Authority" status="incomplete">
      <summary>
      NIC CA issues three classes of Digital Signatures to subscribers, based on the 
      level of verification that is performed in regards to the identity of the 
      certificate subscriber. The NIC CA directly signs Class 1, Class 2 and Class3 
      end-entity certificates which can be used for SSL, email, and document signing.  
      The NIC CA also signs the E-passport Sub-CA which signs Class 1, Class 2 and 
      Class3 end-entity certificates which can be used for SSL, email, and document signing.   
      These Digital Signatures are issued based on verification procedures as stated in the 
      Information Technology (IT) Act 2000, an Act which was passed by the Indian Parliament 
      in June 2000.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=397595"
            version="3"
            sha1="48:22:82:4e:ce:7e:d1:45:0c:03:9a:a0:77:dc:1f:8a:e3:48:9b:bf"
            modulus="2048"
            from="2007-07-01"
            to="2015-07-03"/>
      <crl url="https://nicca.nic.in/crl_2783.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV</type>
      <document url="https://bug511380.bugzilla.mozilla.org/attachment.cgi?id=398631">CA Hierarchy</document>
      <document url="http://nicca.nic.in/pdf/niccacps.pdf">Certificate Practice Statement of NIC CA (English)</document>
      <document url="http://nicca.nic.in/index.jsp">Overview of Information Technology Act 2000 (English)</document>
      <document url="http://nicca.nic.in/pdf/itact2000.pdf">Details of Information Technology Act 2000 (English)</document>
      <document url="http://nicca.nic.in/pdf/DSC-Request-Form.pdf">Digital Signature Certificate Request Form (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=511380</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TWCA" url="http://www.twca.com.tw/Portal/english/coporate_profile/mission.html" status="incomplete">
    <summary>
     Taiwan CA. Inc. (TWCA) is a commercial CA that provides a consolidated on-line 
     financial security certificate service and a sound financial security environment, 
     to ensure the security of on-line finance and electronic commercial trade in Taiwan.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.dfk.com/">SunRise CPAs’ Firm, a member firm of DFK</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=900">Audit Report and Management's Assertsions</document>
    </audit>
    <certificate name="TWCA Root Certification Authority" status="incomplete">
      <summary>
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=402647"
            version="3"
            sha1="cf:9e:87:6d:d3:eb:fc:42:26:97:a3:b5:a3:7a:a0:76:a9:06:23:48"
            modulus="2048"
            from="2008-08-28"
            to="2030-12-31"/>
      <crl url="http://RootCA.twca.com.tw/TWCARCA/revoke_2048.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV, OV</type>
      <document url="http://www.twca.com.tw/picture/file/20090403-113227911.pdf">TWCA PKI Certificate Policy (Traditional Chinese)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=422485">TWCA PKI Certificate Policy (English)</document>
      <document url="http://www.twca.com.tw/picture/file/20090114-11212952.pdf">TWCA Root CA Certification Practice Statement (Traditional Chinese)</document>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=422486">TWCA Root CA Certification Practice Statement (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=518503</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Actalis" url="http://www.actalis.it" status="incomplete">
    <summary>
     Actalis is a public CA offering PKI services to a wide number of customers, 
     mainly banks and local government. 
     Actalis is a Qualified certification service provider according to the 
     EU Signature Directive (Directive 1999/93/EC).
     Actalis designs, develops, delivers and manages services and solutions 
     for on-line security, digital signatures and document certification; 
     develops and offers PKI-enabling components, supplies complete digital 
     signature and strong authentication kits (including hardware and software), 
     delivers ICT security consultancy and training.
    </summary>
    <audit type="ETSI TS 101 456">
      <auditor url="http://www.cnipa.gov.it/site/it-IT/">Centro Nazionale per L’Informatica nella Pubblica Amministrazione (CNIPA)</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=414040">Audit Report</document>
      <document url="http://ec.europa.eu/information_society/policy/esignature/eu_legislation/notification/italy/index_en.htm">Accredited National Certification Service Provider</document>
      <document url="http://www.cnipa.gov.it/QCSP">Accredited Certifier on CNIPA website</document>
    </audit>
    <certificate name="Actalis Authentication CA G1" status="incomplete">
      <summary>
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=405122"
            version="3"
            sha1="91:58:C5:EF:98:73:01:A8:90:3C:FD:AB:03:D7:2D:A1:D8:89:09:C9"
            modulus="2048"
            from="2009-06-23"
            to="2022-06-24"/>
      <crl url="http://portal.actalis.it/Repository/AuthCA1/getCRL">CRL</crl>
      <ocsp>http://ocsp.actalis.it</ocsp>
      <type>OV</type>
      <document url="https://portal.actalis.it/cms/actalis/Info/Manuali/CPS_SSLServer_CodeSigning_v2">CPS for SSL and Code Signing Certs (Italian)</document>
      <document url="https://portal.actalis.it/cms/actalis/Info/Manuali/CPS_SSL_Server_Code_Signing_v201_EN">CPS for SSL and Code Signing Certs (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=520557</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Firmaprofesional" url="http://www.firmaprofesional.com" status="complete">
    <summary>
     Firmaprofesional is a commercial CA in Spain that issues certificates to professional 
     corporations, companies and other institutions.  Their main activity is the generation, 
     transmission and distribution of digital certificates through professional corporations, 
     companies or other institutions, which act as Registration Authorities and Certification 
     Authorities in the hierarchy of certification Firmaprofesional. Firmaprofesional has a 
     network of more than 70 Registration Authorities located throughout Spain.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/es">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=946">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Autoridad de Certificacion Firmaprofesional CIF A62634068" status="complete">
      <summary>
      This is a renewal for the Firmaprofesional root certificate that is currently in NSS. 
      Sub-CAs of the new root cross-sign end-entity certs with sub-CAs of the old root, 
      in order to maintain business continuity.
      This root CA signs subordinate CAs that sign end-entity certificates. 
      One sub-CA is used by Firmaprofesional, and other sub-CAs are issued for organizations
      including professional corporations, companies or other institutions, which act as 
      Registration Authorities and Certification Authorities in the hierarchy of certification Firmaprofesional.
      </summary>
      <data url="http://crl.firmaprofesional.com/carootnew.crt"
            version="3"
            sha1="AE:C5:FB:3F:C8:E1:BF:C4:E5:4F:03:07:5A:9A:E8:00:B7:F7:B6:FA"
            modulus="4096"
            from="2009-05-20"
            to="2030-12-31"/>
      <crl url="http://crl.firmaprofesional.com/firmaprofesional1.crl">CRL</crl>
      <ocsp>http://servicios.firmaprofesional.com/ocsp</ocsp>
      <type>OV</type>
      <document url="http://www.firmaprofesional.com/index.php?option=com_content&amp;view=article&amp;id=62&amp;Itemid=75">Certification Policies and Practices (Spanish)</document>
      <document url="http://www.firmaprofesional.com/cps/FP_CPS_4_1.pdf">CPS (Spanish)</document>
      <document url="http://www.firmaprofesional.com/cps/FP_CP_SSL_4.pdf">SSL CP (Spanish)</document>
      <document url="http://www.firmaprofesional.com/cps/FP_CP_FirmaCodigo_4.pdf">Code Signing CP (Spanish)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=521439</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="US FPKI" url="http://www.cio.gov/fpkipa" status="incomplete">
    <summary>
    The United States Federal Public Key Infrastructure (FPKI) Policy Authority 
    is an interagency body set up under the CIO Council to enforce digital certificate 
    standards for trusted identity authentication across the federal agencies and between 
    federal agencies and outside bodies, such as universities, state and local governments 
    and commercial entities.
    </summary>
    <audit type="Internal">
      <auditor url="http://www.gsa.gov">U. S. General Services Administration</auditor>
      <document url="http://www.cio.gov/fpkia/documents/FPKIAato.pdf">Audit Information</document>
      <document url="http://www.idmanagement.gov/fpkia/documents/FPKIAato.pdf">Letter of Authorization to Operate</document>
    </audit>
    <certificate name="Common Policy - U.S. Government" status="incomplete">
      <summary>
      This is the root certificate for the U.S. Federal Common Policy Framework Certificate 
      Authority (FCPF CA). The Common Policy CA is online and issues CRLs with an 18 hour validity 
      period every 12 hours.  It does not sign end-entity certificates directly. It signs subordinate 
      CAs for Shared Service Providers (SSP). The sub-CAs are operated by the SSPs. End-entity 
      certificates may be issued to Federal employees, contractors, affiliated personnel, and devices 
      operated by or on behalf of Federal agencies. The list of certified SSPs is provided on the 
      FPKI website.
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=408655"
            version="3"
            sha1="cb:44:a0:97:85:7c:45:fa:18:7e:d9:52:08:6c:b9:84:1f:2d:51:b5"
            modulus="2048"
            from="2007-10-15"
            to="2027-10-15"/>
      <crl url="http://fpkia.gsa.gov/CommonPolicy/CommonPolicy(1).crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.idmanagement.gov/fpkipa/documents/CommonPolicy.pdf">FCPF CP</document>
      <document url="http://www.idmanagement.gov/fpkipa/documents/FPKIA_CPS.pdf">FPKIA CPS</document>
      <document url="http://www.idmanagement.gov/fpkipa/cpl.cfm">List of Certified PKI Shared Service Providers</document>
      <document url="http://www.idmanagement.gov/fpkipa/documents/SSProadmap.pdf">Shared Service Provider Roadmap</document>
      <document url="http://www.idmanagement.gov/fpkipa/documents/CPSmatrix.doc">CPS Evaluation Matrix For Evaluation Against the Requirements for the Common Policy Framework </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=478418</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="DNIe" url="http://www.dnie.es" status="incomplete">
    <summary>
    DNIe, is the electronic Spanish National Identity Card. It is the electronic version 
    of the Spanish National Identity Document (DNI) issued by the Dirección General 
    de la Policía (the National Police Force in Spain). The DNI is required for every citizen 
    over 14 years of age. Most of the Spanish citizens use the DNIe to identify themselves 
    and interact against both, government and private online services.
    </summary>
    <audit type="TBD">
      <auditor url="">TBD</auditor>
      <document url="">TBD</document>
    </audit>
    <certificate name="AC RAIZ DNIE" status="incomplete">
      <summary>
      This root has three subordinates CA. The validation activity has been segregated 
      in order to improve privacy. The number of subordinates CA will be increased if necessary. 
      </summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=410022"
            version="3"
            sha1="22:29:F0:56:D3:4D:1C:B6:3E:98:6F:26:B2:D0:8A:B9:4F:F0:8E:4D"
            modulus="4096"
            from="2006-02-16"
            to="2036-02-08"/>
      <crl url="http://crls.dnielectronico.es/crls/ARL.crl">CRL</crl>
      <ocsp>http://ocsp.dnie.es</ocsp>
      <type>OV</type>
      <document url="http://www.dnie.es/PDFs/politicas_de_certificacion.pdf">Certificate Policy (Spanish)</document>
      <document url="http://www.dnie.es/servicios_disponibles/index.html">List of e-services accepting DNIe certificates</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=526181</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="SECOM Trust" url="http://www.secomtrust.net/" status="incomplete">
    <summary>
    SECOM Trust Services Co., Ltd are a commercial CA based in Japan.
    </summary>
    <audit type="WebTrust Readiness">
      <auditor url="http://www.kpmg.com">KPMG</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=975">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Security Communication RootCA2" status="incomplete">
      <summary>
      </summary>
      <data url="https://repository.secomtrust.net/SC-Root2/SCRoot2ca.cer"
            version="3"
            sha1="5F:3B:8C:F2:F8:10:B3:7D:78:B4:CE:EC:19:19:C3:73:34:B9:C7:74"
            modulus="2048"
            from="2009-05-28"
            to="2029-05-28"/>
      <crl url="https://repository.secomtrust.net/SC-Root2/SCRoot2CRL.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="https://repository.secomtrust.net/SC-Root2/index.html">Documents relating to this root</document>
      <document url="https://repository.secomtrust.net/SC-Root/SCRootCPS.pdf">CPS (Japanese)</document>
      <document url="https://repository.secomtrust.net/SC-Root/SCRootCP1.pdf">CP (Japanese)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=527419</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="ipsCA" url="http://www.ipsca.com/" status="incomplete">
    <summary>
     ipsCA, primarily located in Spain, is a worldwide CA which has issued with more 
     than 12,000 SSL certificates to Universities and educational entities (mainly in USA).
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.com">KPMG</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=933">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="ipsCA Main CA Root" status="incomplete">
      <summary>
       This root certificate is intended to replace the “IPS SERVIDORES” root that is currently included in NSS.
      </summary>
      <data url="http://certs.ipsca.com/store/ipsCAMain.der"
            version="3"
            sha1="cf:e4:31:3d:ba:05:b8:a7:c3:00:63:99:5a:9e:b7:c2:47:ad:8f:d5"
            modulus="2048"
            from="2009-09-07"
            to="2029-12-25"/>
      <crl url="http://crlmain01.ipsca.com/crl/crlmain01.crl">CRL</crl>
      <ocsp>http://ocspmain01.ipsca.com/</ocsp>
      <type>OV</type>
      <document url="http://www.ipsca.com/es/Certificates/CPSIPSCAv31.pdf">CPS (Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=529286</authorisation>
      </inclusion>
    </certificate>
    <certificate name="ipsCA Global CA Root" status="incomplete">
      <summary>
      </summary>
      <data url="http://certs.ipsca.com/store/ipsCAGlobal.der"
            version="3"
            sha1="3c:71:d7:0e:35:a5:da:a8:b2:e3:81:2d:c3:67:74:17:f5:99:0d:f3"
            modulus="2048"
            from="2009-09-07"
            to="2029-12-25"/>
      <crl url="http://crlglobal01.ipsca.com/crl/crlglobal01.crl">CRL</crl>
      <ocsp>http://ocspglobal01.ipsca.com/</ocsp>
      <type>OV</type>
      <document url="http://www.ipsca.com/es/Certificates/CPSIPSCAv31.pdf">CPS (Spanish)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=529286</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Go Daddy" url="http://www.godaddy.com/" status="complete">
    <summary>
     Go Daddy operates a commercial CA based in the US and serving customers worldwide. 
    </summary>
    <audit type="WebTrust CA and WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=355&amp;file=pdf">Independent Accountants' Report</document>
    </audit>
    <certificate name="Go Daddy Root Certificate Authority - G2" status="complete">
      <summary>
      This new root will eventually replace the “Go Daddy Class 2 CA” root cert that is 
      currently included in NSS. The “Go Daddy Class 2 CA” root has a single internally-operated 
      subordinate CA issuing SSL certificates (DV, OV and EV), email certificates, and code signing certificates.
      </summary>
      <data url="https://certificates.godaddy.com/repository/gdroot-g2.crt"
            version="3"
            sha1="47:BE:AB:C9:22:EA:E8:0E:78:78:34:62:A7:9F:45:C2:54:FD:E6:8B"
            modulus="2048"
            from="2009-08-31"
            to="2037-12-31"/>
      <crl url="http://crl.godaddy.com/gdroot-g2.crl">CRL</crl>
      <ocsp>http://ocsp.godaddy.com/</ocsp>
      <type>DV, OV, EV (policy OID 2.16.840.1.114413.1.7.23.3)</type>
      <document url="https://certificates.godaddy.com/repository">Repository of certs and policies</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">CP and CPS</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldRelyingPartyAgreement.pdf">Relying Party Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldSubscriberAgreement.pdf">Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldEVSubscriberAgreement.pdf">Premium EV Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCodeSigningCertificateSubscriberAgreement_1.0.pdf">Code Signing Subscriber Agreement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=527056</authorisation>
      </inclusion>
      <comments>Not currently requesting email trust bit because current documentation does not include requirements to verify email address ownership/control.</comments>
    </certificate>
    <certificate name="Starfield Root Certificate Authority - G2" status="complete">
      <summary>
       This new root will eventually replace the “Starfield Class 2 CA” root cert that 
       is currently included in NSS. The “Starfield Class 2 CA” root has a single subordinate 
       CA issuing SSL certificates (DV, OV and EV), email certificates, and code signing certificates.
      </summary>
      <data url="https://certificates.starfieldtech.com/repository/sfroot-g2.crt"
            version="3"
            sha1="B5:1C:06:7C:EE:2B:0C:3D:F8:55:AB:2D:92:F4:FE:39:D4:E7:0F:0E"
            modulus="2048"
            from="2009-08-31"
            to="2037-12-31"/>
      <crl url="http://crl.starfieldtech.com/sfroot-g2.crl">CRL</crl>
      <ocsp>http://ocsp.starfieldtech.com</ocsp>
      <type>DV, OV, EV (policy OID 2.16.840.1.114413.1.7.23.3)</type>
      <document url="https://certificates.godaddy.com/repository">Repository of certs and policies</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">CP and CPS</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldRelyingPartyAgreement.pdf">Relying Party Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldSubscriberAgreement.pdf">Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldEVSubscriberAgreement.pdf">Premium EV Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCodeSigningCertificateSubscriberAgreement_1.0.pdf">Code Signing Subscriber Agreement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=527056</authorisation>
      </inclusion>
      <comments>Not currently requesting email trust bit because current documentation does not include requirements to verify email address ownership/control.</comments>
    </certificate>
    <certificate name="Starfield Services Root Certificate Authority - G2" status="complete">
      <summary>
       This new self-signed root CA does not yet have subordinate CAs. Before issuing from this root, 
       at least one appropriate, internally-operated subordinate issuing CA will be created.
      </summary>
      <data url="https://certificates.starfieldtech.com/repository/sfsroot-g2.crt"
            version="3"
            sha1="92:5A:8F:8D:2C:6D:04:E0:66:5F:59:6A:FF:22:D8:63:E8:25:6F:3F"
            modulus="2048"
            from="2009-08-31"
            to="2037-12-31"/>
      <crl url="http://crl.starfieldtech.com/sfsroot-g2.crl">CRL</crl>
      <ocsp>http://ocsp.starfieldtech.com</ocsp>
      <type>DV, OV</type>
      <document url="https://certificates.godaddy.com/repository">Repository of certs and policies</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">CP and CPS</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldRelyingPartyAgreement.pdf">Relying Party Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldSubscriberAgreement.pdf">Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldEVSubscriberAgreement.pdf">Premium EV Subscriber Agreement</document>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCodeSigningCertificateSubscriberAgreement_1.0.pdf">Code Signing Subscriber Agreement</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=527056</authorisation>
      </inclusion>
      <comments>Not currently requesting email trust bit because current documentation does not include requirements to verify email address ownership/control.</comments>
    </certificate>
  </authority>

  <authority name="Scientific Trust" url="http://www.scientific-trust.de/index_en.php" status="complete">
    <summary>
      Scientific Trust is a division of the University of Hagen and has its own Root Certificate. 
      Scientific Trust offers Intermediate Certificates to other universities and companies. 
      The primary market is the German speaking area (Austria, Germany, Switzerland).
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.de">KPMG</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=974">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Scientific Trust operated by FernUniversitaet in Hagen – G1" status="complete">
      <summary>
       This root has one internally-operated subordinate CA issuing client and server certificates. 
       In the future there will be externally-operated subordinate CAs, issuing client and server certificates.
      </summary>
      <data url="http://www.scientific-trust.de/scientific-trust.crt"
            version="3"
            sha1="8A:A3:F5:A6:44:D1:B4:23:97:CF:82:67:5D:1F:D8:35:D0:BA:31:46"
            modulus="4096"
            from="2009-08-24"
            to="2037-12-25"/>
      <crl url="http://cdp1.scientific-trust.de/g1/crl/root.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>OV</type>
      <document url="http://www.scientific-trust.de/download/cps_st.pdf">CPS Scientific Trust URL (English)</document>
      <document url="http://www.scientific-trust.de/download/cp.pdf">Certificate Policy URL (English)</document>
      <document url="http://www.scientific-trust.de/download/cps_feu_V1.0.pdf">CPS FernUniversitaet in Hagen URL (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=531237</authorisation>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Certum" url="http://www.certum.eu/" status="complete">
    <summary>
     Broader Certification Center (CERTUM) is an organizational unit of Unizeto Technologies SA, 
     providing certification services related to electronic signatures. It is the oldest public 
     certification authority in Poland and the commercial certification authority, operating on 
     a global scale - serving customers in over 50 countries worldwide.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/pl">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=965">Audit Report and Management’s Assertions</document>
    </audit>
    <audit type="WebTrust EV Point In Time Readiness">
      <auditor url="http://www.ey.com/pl">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=980">Audit Report and Management’s Assertions</document>
    </audit>
    <certificate name="Certum Trusted Network CA" status="complete">
      <summary>
       This root currently has two internally-operated sub-CAs; the Certum Class 1 sub-CA signs 
       3 month test certs, and the Certum Extended Validation CA signs EV SSL certs.
       Eventually, the certificates under the old “Certum CA” root (included in NSS) will be 
       moved to this new root. The sub-CAs of the “Certum CA” root are Certum Level I CA, 
       Certum Level II CA, Certum Level III CA, Certum Level IV CA, and Certum Partners CA.
      </summary>
      <data url="http://repository.certum.pl/CTNCA.crt"
            version="3"
            sha1="07:E0:32:E0:20:B7:2C:3F:19:2F:06:28:A2:59:3A:19:A7:0F:06:9E"
            modulus="2048"
            from="2008-10-22"
            to="2029-12-31"/>
      <crl url="http://crl.certum.pl/ctnca.crl">CRL</crl>
      <ocsp>http://ocsp.certum.pl</ocsp> 
      <type>DV, OV, EV (policy OID 1.2.616.1.113527.2.5.1.1)</type>
      <document url="http://www.certum.pl/repository">Certum Cert and Document Repository</document>
      <document url="http://www.certum.eu/upload_module/downloads/certum/dokumenty/kodeks_postepowania_certyfikacyjnego/Certum_CPS_v3_0.pdf">CPS of CERTUM’s Non-Qualified Certification Services (English)</document>
      <document url="http://www.certum.eu/upload_module/downloads/certum/dokumenty/polityka_certyfikacji/Certum_CP_v3_0.pdf">CP of CERTUM’s Non-Qualified Certification Services (English)</document>
      <document url="http://www.certum.eu/upload_module/downloads/certum/dokumenty/kodeks_postepowania_certyfikacyjnego/Certum_CPS_v3_0_AppendixEV.pdf">EV CP (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=532377</authorisation>
      </inclusion>
    </certificate>
  </authority>
  
  <authority name="TeliaSonera" url="http://www.teliasonera.com/home" status="incomplete">
    <summary>
     TeliaSonera provides telecommunication services in the Nordic and Baltic countries, 
     the emerging markets of Eurasia, including Russia and Turkey, and in Spain. CA operations 
     currently only in Nordic countries. 
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/GL/EN/Home">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=970">Audit Report and Management’s Assertions</document>
    </audit>
        <certificate name="TeliaSonera Root CA v1" status="incomplete">
      <summary> 
       This root has five internally-operated subordinate CA's: Class1 CA v1 (smart card or usb 
       token based client certificates), Class2 CA v2 (software client certificates for VPN services, S
       SL, Signatures, Authentication, and E-mail encryption),TeliaSonera Server CA v1, 
       TeliaSonera Email CA v3, and TeliaSonera VPN CA v1.
      </summary>
      <data url=""
            version="3"
            sha1="43:13:bb:96:f1:d5:86:9b:c1:4e:6a:92:f6:cf:f6:34:69:87:82:37"
            modulus="4096"
            from="2007-10-18"
            to="2032-10-18"/>
      <crl url="http://crl-2.trust.teliasonera.com/teliasonerarootcav1.crl">CRL</crl>
      <type>DV, OV</type>
      <document url="http://repository.trust.teliasonera.com/index2_en.php">Document and CA repository</document>
      <document url="http://repository.trust.teliasonera.com/download/CA/TeliaSonera_Root_CA_v1_CPS%20Rev_A.pdf">TeliaSonera Root CA v1 Practice Statement (English)</document>
      <document url="http://repository.trust.teliasonera.com/download/CA/TeliaSonera_Class2_CA_v1_Rev_A.pdf">TeliaSonera Class2 CA v1/TeliaSonera E-mail v3 Practice Statement (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=539924</authorisation>
      </inclusion>
    </certificate>
  </authority>

</certificates>
