<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="included.xsl"?>

<certificates type="included">
  <!-- Example -->
  <authority name="DigiCert" url="http://www.digicert.com/"             >
    <summary>DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert
provides digital certification and identity assurance services internationally
to a variety of sectors including business, education, and government.</summary>
    <audit type="WebTrust">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=558&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>

    <certificate name="DigiCert Assured ID Root CA" status="complete">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertAssuredIDRootCA.crt"
            version="3" 
            sha1="05:63:B8:63:0D:62:D7:5A:BB:C8:AB:1E:4B:DF:B5:A8:99:B2:4D:43" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>

    <certificate name="DigiCert Global Root CA" status="complete">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertGlobalRootCA.crt"
            version="3" 
            sha1="A8:98:5D:3A:65:E5:E5:C4:B2:D7:D6:6D:40:C6:DD:2F:B1:9C:54:36" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertGlobalRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>

    <certificate name="DigiCert High Assurance EV Root CA" status="complete">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt"
            version="3" 
            sha1="5F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="QuoVadis" url="http://www.quovadis.bm/"              >
    <summary>QuoVadis is a commercial CA, based in Bermuda and operating globally. 
    QuoVadis is a Qualified Certification Services Provider in Switzerland.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst &amp; Young 
      (Technology and Security Risk Services)</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=612&amp;file=pdf">Audit Report 
      and Management's Assertions</document>
    </audit>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document url="http://www.seco.admin.ch/sas/00229/00251/00254/index.html?lang=en">Swiss Accreditation Service statement</document>
    </audit>

    <certificate name="QuoVadis Root CA 2" status="complete">
      <summary>This root will be used for SSL/device certificates, including
      standard "organisation validated" certificates as well as EV certificates.</summary>
      <data url="http://www.quovadis.bm/public/qvrca2.crt"
            version="3" 
            sha1="CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7" 
            modulus="4096" 
            from="2006-11-24" 
            to="2031-11-24"
            ev-oid="1.3.6.1.4.1.8024.0.2.100.1.2"/>
      <crl url="http://crl.quovadisglobal.com/qvrca2.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV, EV</type>
      <document url="http://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.7.pdf">QuoVadis 
      Root CA2 CP/CPS v1.7</document>
      <document url="http://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.7.pdf">QuoVadis 
      Root CA2 CP/CPS v1.7</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=365281</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378161</technical>
      </inclusion>
    </certificate>
    
    <certificate name="QuoVadis Root CA 3" status="complete">
      <summary>This root will operate under a similar CP/CPS to our existing "qualified" Root CA 1,
      primarily used for end user certificates.</summary>
      <data url="http://www.quovadis.bm/public/qvrca3.crt"
            version="3" 
            sha1="1F:49:14:F7:D8:74:95:1D:DD:AE:02:C0:BE:FD:3A:2D:82:75:51:85" 
            modulus="4096" 
            from="2006-11-24" 
            to="2031-11-24"/>
      <crl url="http://crl.quovadisglobal.com/qvrca3.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV</type>
      <document url="http://www.quovadis.bm/policies/QV_CPCPS_V4_3.pdf">QuoVadis Root CA CP/CPS 4.3</document>
      <document url="http://www.quovadis.bm/policies/QV_CPCPS_V4_3.pdf">QuoVadis Root CA CP/CPS 4.3</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=365281</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378161</technical>
      </inclusion>
    </certificate>    
  </authority>

  <authority name="GlobalSign" url="http://www.globalsign.com/"         >
    <summary></summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.dk">Deloitte (Denmark)</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=327&amp;file=pdf">Audit Report 
      and Management's Assertions</document>
    </audit>

    <certificate name="GlobalSign Root CA - R2" status="complete">
      <summary>Created for EV backward compatibility on XP</summary>
      <data url="https://secure.globalsign.net/cacert/root-r2.crt"
            version="3" 
            sha1="75:E0:AB:B6:13:85:12:27:1C:04:F8:5F:DD:DE:38:E4:B7:24:2E:FE" 
            modulus="2048" 
            from="2006-12-15" 
            to="2021-12-15"/>
      <crl url="http://crl.globalsign.net/root-r2.crl">CRL</crl>
      <ocsp><!-- None yet --></ocsp>
      <type>EV</type>
      <document url="http://www.globalsign.com/repository/GlobalSign_CP_v_2_1.pdf">GlobalSign CP v2.1</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v_5_3.pdf">GlobalSign CPS v5.3</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=367245</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378163</technical>
      </inclusion>
    </certificate>
  </authority>
  
  <authority name="Keynectis/Certplus" url="http://www.keynectis.com/"  >
    <summary>Keynectis is a French company, created by merging 2 previous French
    certification operators, Certplus and PK7.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.lsti.fr/">LSTI - La Sécurité des Technologies de l'Information</auditor>
      <document url="http://www.keynectis.com/PC/Certificat_conformite_ETSI_101-456.pdf">ETSI Certificate</document>
    </audit>

    <certificate name="Certplus Class 2 Primary CA" status="">
      <summary></summary>
      <data url="http://www.certplus.com/PC/certplus_class2.pem"
            version="3" 
            sha1="74:20:74:41:72:9C:DD:92:EC:79:31:D8:23:10:8D:C2:81:92:E2:BB" 
            modulus="2048" 
            from="1999-07-07" 
            to="2019-07-06"/>
      <crl url="http://www.certplus.com/CRL/class2.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV</type>
      <document url="http://www.keynectis.com/PC/DSQ_CP_SSL_RCA_CP_1%200.pdf">Root CA Certification Policy for SSL Services</document>
      <document url="http://www.keynectis.com/PC/CPS_KEYNECTIS_120407v1.1.pdf">Declaration des Pratiques de Certification (CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335392</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=379032</technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="StartCom" url="http://www.startssl.com/"             >
    <summary>Commercial, worldwide, 8 subordinate CAs.</summary>
    <audit type="WebTrust equivalent">
      <auditor url="http://www.we-can.co.il">We! Consulting Group</auditor>
      <document url="http://cert.startcom.org/audit.pdf">Independent Audit Report</document>
    </audit>

    <certificate name="StartCom Certification Authority" status="complete">
      <summary></summary>
      <data url="http://cert.startcom.org/sfsca.crt"
            version="3" 
            sha1="3E:2B:F7:F2:03:1B:96:F3:8C:E6:C4:D8:A8:5D:3E:2D:58:47:6A:0F" 
            modulus="4096" 
            from="2006-09-17" 
            to="2036-09-17"/>
      <crl url="http://cert.startcom.org/sfsca-crl.crl">CRL</crl>
      <ocsp>http://ocsp.startcom.org/sub/class2/server/ca</ocsp>
      <type>DV, OV</type>
      <document url="http://cert.startcom.org/policy.pdf">Certificate Policy and CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-15">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=362304</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=383722</technical>
      </inclusion>
    </certificate>
  </authority>

</certificates>
