CA/Included Certificates: Difference between revisions

From MozillaWiki
< CA
Jump to navigation Jump to search
(Change ccadb-public.secure.force.com to ccadb.my.salesforce-sites.com)
 
(34 intermediate revisions by 3 users not shown)
Line 1: Line 1:
= Mozilla Included CA Certificate List =
= Mozilla Included CA Certificate List =


Mozilla products ship with a [https://mozillacaprogram.secure.force.com/CA/IncludedCACertificateReport default list of Certification Authority (CA) certificates].  
The Mozilla CA Certificate Program's list of included root certificates is stored in a file called [https://hg.mozilla.org/releases/mozilla-beta/file/tip/security/nss/lib/ckfw/builtins/certdata.txt certdata.txt] in the Mozilla source code management system.


CAs are parties who are trusted to attest to the identity of websites. Mozilla has a rigorous process for CAs to request inclusion of their certificates, the details of which are described in the following wiki pages:
If you are '''choosing a CA to provide a certificate for your website''', we have a list of [https://ccadb.my.salesforce-sites.com/mozilla/CACertificatesInFirefoxReport all root certificates that Firefox trusts for SSL/TLS], together with contact information and geographical focus for the owning CA.
* [[CA|Process Overview]]
* [http://www.mozilla.org/projects/security/certs/policy/ Mozilla CA Certificate Policy]
* [[CA:FAQ | General Background and FAQ on CAs and the Mozilla process]]
* [[CA:How_to_apply | CA Inclusion Process in detail]]
* [[CA:Schedule | Current queue of inclusion requests]]
* [[CA:Overview | Other useful information]]


=== OBSOLETE ===
If you are '''embedding our root store''', you need to know that we have imposed some restrictions on certain CAs or certificates which are not encoded in certdata.txt. These are [[CA/Additional_Trust_Changes|documented]] on a best-efforts basis.
'''The data below is no longer maintained, because it has been replaced by the report at the link above which is automatically-generated directly from the data in Salesforce.'''
<br /><br />
 
<big>[https://www.ccadb.org/rootstores/usage#ccadb-data-usage-terms CCADB Data Usage Terms]</big>
This is a list of CA certificates that are distributed with Mozilla software products. You can [http://mxr.mozilla.org/mozilla-central/source/security/nss/lib/ckfw/builtins/certdata.txt view the source file with all of the included root certificates].
* [[CA/FAQ#Can_I_use_Mozilla.27s_set_of_CA_certificates.3F|Can I use Mozilla's set of CA certificates?]]
 
** [https://ccadb.my.salesforce-sites.com/mozilla/IncludedRootsPEMTxt?TrustBitsInclude=Websites PEM of Root Certificates in Mozilla's Root Store with the Websites (TLS/SSL) Trust Bit Enabled] (TXT)
If the spreadsheet does not display in the widget below, then you may [https://docs.google.com/spreadsheet/ccc?key=0Ah-tHXMAwqU3dGx0cGFObG9QM192NFM4UWNBMlBaekE&usp=sharing access the spreadsheet directly].
** [https://ccadb.my.salesforce-sites.com/mozilla/IncludedRootsPEMCSV?TrustBitsInclude=Websites PEM of Root Certificates in Mozilla's Root Store with the Websites (TLS/SSL) Trust Bit Enabled] (CSV)
 
** [https://ccadb.my.salesforce-sites.com/mozilla/IncludedRootsPEMTxt?TrustBitsInclude=Email PEM of Root Certificates in Mozilla's Root Store with the Email (S/MIME) Trust Bit Enabled] (TXT)
{{#widget:Google Spreadsheet
** [https://ccadb.my.salesforce-sites.com/mozilla/IncludedRootsPEMCSV?TrustBitsInclude=Email PEM of Root Certificates in Mozilla's Root Store with the Email (S/MIME) Trust Bit Enabled] (CSV)
|key=0Ah-tHXMAwqU3dGx0cGFObG9QM192NFM4UWNBMlBaekE
* [https://ccadb.my.salesforce-sites.com/mozilla/IncludedCACertificateReport Included CA Certificates] (HTML)
|width=100%
* [https://ccadb.my.salesforce-sites.com/mozilla/IncludedCACertificateReportCSVFormat Included CA Certificates] (CSV)
|height=700px
* [https://ccadb.my.salesforce-sites.com/mozilla/IncludedCACertificateReportPEMCSV Included CA Certificates] (CSV with PEM of raw certificate data)
}}
* [https://ccadb.my.salesforce-sites.com/mozilla/UpcomingRootInclusionsReport Root Inclusions in Progress] (HTML)
* [https://ccadb.my.salesforce-sites.com/mozilla/UpcomingRootInclusionsReportCSVFormat Root Inclusions in Progress] (CSV)

Latest revision as of 23:44, 22 May 2023

Mozilla Included CA Certificate List

The Mozilla CA Certificate Program's list of included root certificates is stored in a file called certdata.txt in the Mozilla source code management system.

If you are choosing a CA to provide a certificate for your website, we have a list of all root certificates that Firefox trusts for SSL/TLS, together with contact information and geographical focus for the owning CA.

If you are embedding our root store, you need to know that we have imposed some restrictions on certain CAs or certificates which are not encoded in certdata.txt. These are documented on a best-efforts basis.

CCADB Data Usage Terms