<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="pending.xsl"?>

<certificates type="pending">
  <authority name="ACCV" url="http://www.pki.gva.es/"                   status="complete">
    <summary>
      ACCV (Autoritat de Certificacio de la Comunitat Valenciana) is a CA operated by
      the government of the Valencia region of Spain.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.ssiconsultores.com/">
        Seguridad y Sistemas de Informacion S.L.</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=571&amp;file=pdf">
        Informe de Auditoria Independiente</document>
    </audit>

    <certificate name="ACCV Root CA" status="complete">
      <summary>
      </summary>
      <data url="http://www.pki.gva.es/gestcert/rootca.crt"
            version="3"
            sha1="A0:73:E5:C5:BD:43:61:0D:86:4C:21:13:0A:85:58:57:CC:9C:EA:46"
            modulus="2048"
            from="2001-07-06"
            to="2021-07-01">
      </data>
      <crl url="http://www.pki.gva.es/gestcert/rootgva_der.crl">CRL</crl>
      <ocsp>http://ocsp.pki.gva.es/</ocsp>
      <type>DV, IV</type>
      <document url="http://www.accv.es/pdf-politicas/ACCV-CPS-V1.7-v.pdf">Declaracion
        de Practicas de Certificacion (CPS) de la ACCV, v1.7
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=274100</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="IdenTrust" url="http://www.identrust.com/"           status="pending">
    <summary>IdenTrust is a for-profit corporation serving the private, commercial and government sectors.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=574&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>

    <certificate name="DST Root CA X3" status="complete">
      <summary></summary>
      <data url="http://apps.identrust.com/roots/DSTROOTCAX3.cer"
            version="3"
            sha1="DA:C9:02:4F:54:D8:F6:DF:94:93:5F:B1:73:26:38:CA:6A:D7:7C:13"
            modulus="2048"
            from="2000-09-30"
            to="2021-09-30"/>
      <crl url="http://crl.identrust.com/DSTROOTCAX3.crl">CRL</crl>
      <ocsp>http://ocsp.digsigtrust.com</ocsp>
      <type>DV</type>
      <document url="https://secure.identrust.com/certificates/policy/ts/TrustID_CP_v1.3.1_20060127.pdf">TrustID CP v1.3.1</document>
      <document url="https://secure.identrust.com/certificates/policy/ts/identrust_trustid_cps_v2.2_20070514.pdf">IdenTrust CPS v2.2</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=359069</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="DST ACES CA X6" status="complete">
      <summary></summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=277051"
            version="3"
            sha1="40:54:DA:6F:1C:3F:40:74:AC:ED:0F:EC:CD:DB:79:D1:53:FB:90:1D"
            modulus="2048"
            from="2003-11-20"
            to="2017-11-20"/>
      <crl url="http://crl.trustdst.com/DSTACESX6.crl">CRL</crl>
      <ocsp>https://ocspaces.trustdst.com</ocsp>
      <type>DV</type>
      <document url="https://secure.identrust.com/certificates/policy/aces/revised_aces_cp_v20040506_1.pdf">Certificate Policy v20040506_1</document>
      <document url="https://secure.identrust.com/certificates/policy/aces/dst-aces-cps-v20040617.pdf">Certificate Practice Statement v4.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=359069</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Trustwave" url="http://www.trustwave.com/" status="pending">
    <summary>Trustwave is a commercial CA serving customers worldwide;
      it includes the former SecureTrust and XRamp CAs. At this time
      there are no subordinate CAs for any of these roots; instead end
      entity certificates are issued directly from the roots as noted
      below, with different classes of certificates under different
      certificate policies.  Note that each root CA is not associated
      with a single CPS, rather end entity certs are associated with
      policies that link to the CPS that the certificate was issued
      under: an EV CPS, an OV CPS, etc.
    </summary>
    <audit type="WebTrust and WebTrust EV">
      <auditor url="">Boysen &amp; Miller PLLC</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=359&amp;file=pdf">Audit Report
      and Management's Assertions</document>
    </audit>

    <certificate name="SecureTrust CA" status="complete">
      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV) and code signing certificates.
      </summary>
      <data url="https://www.securetrust.com/legal/STCA.txt"
            version="3"
            sha1="87:82:C6:C3:04:35:3B:CF:D2:96:92:D2:59:3E:7D:44:D9:34:FF:11"
            modulus="2048"
            from="2006-11-07"
            to="2029-12-31"/>
      <crl url="http://crl.securetrust.com/STCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409837</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418907</technical>
      </inclusion>
    </certificate>

    <certificate name="Secure Global CA" status="complete">
      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV), S/MIME certificates, and (in future)
        code signing certificates.
      </summary>
      <data url="https://www.securetrust.com/legal/SGCA.txt"
            version="3"
            sha1="3A:44:73:5A:E5:81:90:1F:24:86:61:46:1E:3B:9C:C4:5F:F5:3A:1B"
            modulus="2048"
            from="2006-11-07"
            to="2029-12-31"/>
      <crl url="http://crl.securetrust.com/SGCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_SMIME_CPS_1_6_0.pdf">SecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409838</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418907</technical>
      </inclusion>
    </certificate>

    <certificate name="XRamp Global CA" status="complete">

      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV), S/MIME certificates, and code
        signing certificates.
      </summary>
      <data url="http://www.securetrust.com/legal/XGCA.txt"
            version="3"
            sha1="B8:01:86:D1:EB:9C:86:A5:41:04:CF:30:54:F3:4C:52:B7:E5:58:C6"
            modulus="2048"
            from="2004-11-01"
            to="2035-01-01"/>
      <crl url="http://crl.xrampsecurity.com/XGCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_SMIME_CPS_1_6_0.pdf">SecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409840</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418902</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list. The present request is to enable this CA
      certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="KISA" url="http://www.rootca.or.kr/" status="pending">
    <summary>Korea Information Security Agency (KISA) is the
      Electronic Signature Authorization Management Center for South
      Korea. The Korean Certification Authority Central (KCAC) of KISA
      issues certificates to six (6) intermediate CAs ("licensed CAs"
      or LCAs), which then issue end entity certificates to Korean
      citizens, businesses, and other organizations.</summary>
    <audit type="Government (WebTrust equivalent)">
      <auditor url="http://www.mic.go.kr/">Ministry of Information and Communication, Republic of Korea</auditor>
      <document url="http://eng.mic.go.kr/eng/user.tdf?a=common.HtmlApp&amp;c=1001&amp;page=resources/resources_f_01.html&amp;mc=E_04_06">Public statement by MIC re KISA/KCAC audit</document>
    </audit>

    <certificate name="CertRSA01" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root is apparently being phased out in favor of the KISA
        RootCA 1.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa.der"
            version="3"
            sha1="F5:C2:7C:F5:FF:F3:02:9A:CF:1A:1A:4B:EC:7E:E1:96:4C:77:D7:84"
            modulus="2048"
            from="2000-03-03"
            to="2010-03-03"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-2459.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure (Korean)</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 1" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
        LCAs (Licensed CAs), not directly to end entities. Note that
        this root CA is replacing CertRSA01.</summary>
      <data url="http://www.rootca.or.kr/certs/root-rsa-3280.der"
            version="3"
            sha1="02:72:68:29:3E:5F:5D:17:AA:A4:B3:C3:E6:36:1E:1F:92:57:5E:AA"
            modulus="2048"
            from="2005-08-24"
            to="2025-08-24"/>
      <crl url="http://www.rootca.or.kr/certs/root-rsa-3280.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="KISA RootCA 3" status="complete">
      <summary>Certificates are issued from this root only to KISA's 6
LCAs (Licensed CAs), not directly to end entities.</summary>
      <data url="http://www.rootca.or.kr/certs/root-wrsa.der"
            version="3"
            sha1="5F:4E:1F:CF:31:B7:91:3B:85:0B:54:F6:E5:FF:50:1A:2B:6F:C6:CF"
            modulus="2048"
            from="2004-11-19"
            to="2014-11-19"/>
      <crl url="http://www.rootca.or.kr/certs/root-wrsa.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV and IV</type>
      <document url="http://www.kisa.or.kr/kisae/kcac/down/e-cps.pdf">CPS 1.1 (English)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/cps13.pdf">CPS 1.3 (Korean)</document>
      <document url="http://www.kisa.or.kr/kisa/kcac/down/7-Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline%20for%20SSL,%20CodeSigning,%20and%20Secure%20e-Mail.pdf">
Certificate issuing procedure</document>
      <document url="http://www.rootca.or.kr/kisa/kcac/down/Digital%20Signature%20Certificate%20Issuing%20Procedure%20Guideline(EN).pdf">Web Server Security, Code-Signing, Secure E-mail Certificates Issuance Administration Guideline (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335197</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <comments></comments>
  </authority>

  <authority name="SwissSign" url="http://www.swisssign.com/"           status="pending">
    <summary>SwissSign AG is a commercial CSP that provides certification services for
    individual and corporate customers. SwissSign operates the certificate authority
    for the Swiss Post and is mostly focused on Switzerland but Registration Services
    may be used internationally.
The "Platinum G2" Root CA currently has 3 subordinate CAs,
the "Gold G2" Root CA has 2 and the "Silver G2" Root CA has 3.
</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document url="http://www.seco.admin.ch/sas/00229/00251/index.html?lang=en">Swiss Accreditation Service Certified Bodies List</document>
      <document url="http://www.seco.admin.ch/sas/00229/00251/00281/index.html?lang=en">SAS details for SwissSign</document>
    </audit>

    <certificate name="SwissSign Platinum CA - G2" status="pending">
      <summary>The SwissSign Platinum CA - G2 root has three
subordinate CAs. The SwissSign Qualified Platinum CA - G2 issues
"qualified" certificates according to Swiss digital signature law
(ZertES). The SwissSign Personal Platinum CA - G2 issues certificates
for natural persons and organizations. The Swiss Post Platinum CA - G2
issues the "Postzertifikat", a product of the Swiss Post. (Note that
each of the subordinate CAs has its own CP/CPS separate from the
CP/CPS of the root.) The Platinum CAs require that keys be generated
on Secure Signature Creation Devices (SSCDs); since such devices are
not used with servers, this hierarchy is enabled for email and object
signing uses only.</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=50AFCC078715476F38C5B465D1DE95AAE9DF9CCC&amp;into=browser"
            version="3"
            sha1="56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/34C58C2353ADD6DEE70092B06BFA269451CA07E4">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/34C58C2353ADD6DEE70092B06BFA269451CA07E4</ocsp>
      <type>IV</type>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Root-CP-CPS-R1.pdf">SwissSign Platinum Root CP/CPS</document>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Qualified-CP-CPS-R1.pdf">SwissSign Qualified Platinum CP/CPS</document>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Personal-CP-CPS-R1.pdf">SwissSign Personal Platinum CP/CPS</document>
      <document url="http://repository.swisssign.com/Swiss-Post-Platinum-CP-CPS-R1.pdf">Swiss Post Platinum CP/CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
      </inclusion>
    </certificate>

    <certificate name="SwissSign Gold CA - G2" status="pending">
      <summary>The "Gold G2" root CA currently has two subordinate
CAs: "Personal" issues certificates for natural persons and
organizations, while "Server" issues certificates for systems.  This
root CA may also operate other customer-specific Issuing CAs if and
only if they fully comply with all the stipulations of the "Gold G2"
CP/CPS.</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=5B257B96A465517EB839F3C078665EE83AE7F0EE&amp;into=browser"
            version="3"
            sha1="D8:C5:38:8A:B7:30:1B:1B:6E:D4:7A:E6:45:25:3A:6F:9F:1A:27:61"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/0E414F33ED1FEE8DAF6A1916B706D286B253008A">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/0E414F33ED1FEE8DAF6A1916B706D286B253008A</ocsp>
      <type>IV</type>
      <document url="http://repository.swisssign.com/SwissSign-Gold-CP-CPS-R2.pdf">SwissSign Gold CP/CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
      </inclusion>
    </certificate>

    <certificate name="SwissSign Silver CA - G2" status="pending">
      <summary>The "Silver G2" root CA currently has three subordinate
CAs: "Personal" issues certificates for natural persons and
organizations, "Server" issues certificates for systems, and "Switch"
is operated for a customer that issues certificates for the academic
community</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=17A0CDC1E441B63A5B3BCB459DBD1CC298FA8658&amp;into=browser"
            version="3"
            sha1="9B:AA:E5:9F:56:EE:21:CB:43:5A:BE:25:93:DF:A7:F0:40:D1:1D:CB"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/A5045DFC48B74304F31B3B90ACB036034D6AC84F">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/A5045DFC48B74304F31B3B90ACB036034D6AC84F</ocsp>
      <type>IV</type>
      <document url="http://repository.swisssign.com/SwissSign-Silver-CP-CPS-R2.pdf">SwissSign Silver CP/CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="DCSSI" url="http://www.ssi.gouv.fr/"                 status="incomplete">
    <summary>DCSSI is a part of the French Government. It issues certificates to French
    Government websites which are used by the general public. Each department has a sub CA; there
    are at least 20 at the moment, and potentially up to 60.</summary>
    <audit type="WebTrust">
      <auditor url="">Secretariat Général de la Défense Nationale</auditor>
      <document url="">Documents Classified!</document>
    </audit>

    <certificate name="IGC/A" status="incomplete">
      <summary></summary>
      <data url="http://www.ssi.gouv.fr/fr/sigelec/igca/cert_igca_rsa.crt"
            version="3"
            sha1="60:D6:89:74:B5:C2:65:9E:8A:0F:C1:88:7C:88:D2:46:69:1B:18:2C"
            modulus="2048"
            from="2002-12-13"
            to="2020-10-17"/>
      <crl url=""><!-- none -->3</crl>
      <ocsp></ocsp>
      <type>DV</type>
      <document url=""></document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=368970</authorisation>
        <technical></technical>
      </inclusion>
      <comments>No CRL or OCSP. No CPS or CP.</comments>
    </certificate>

    <certificate name="IGC/A" status="incomplete">
      <summary></summary>
      <data url="http://www.ssi.gouv.fr/fr/sigelec/igca/cert_igca_dsa.crt"
            version="3"
            sha1="95:1E:F4:DC:A3:1D:5C:57:55:16:02:86:51:AB:6A:BA:15:FC:4E:4B"
            modulus="2048"
            from="2002-12-13"
            to="2020-10-17"/>
      <crl url=""><!-- none --></crl>
      <ocsp></ocsp>
      <type>DV</type>
      <document url=""></document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=368970</authorisation>
        <technical></technical>
      </inclusion>
      <comments>No CRL or OCSP. No CPS or CP.</comments>
    </certificate>

    <comments>Audit documents are classified.</comments>
  </authority>

  <authority name="Microsec" url="http://www.e-szigno.hu/"              status="complete">
    <summary>Microsec Ltd. is a Hungarian certificate authority.</summary>
    <audit type="Government">
      <auditor url="http://www.nhh.hu/">Hungarian Government National Communications Authority</auditor>
      <document url="http://www.e-szigno.hu/docs/NhhCertification.pdf">Authority statement</document>
    </audit>

    <certificate name="Microsec e-Szigno Root CA" status="complete">
      <summary></summary>
      <data url="http://www.e-szigno.hu/RootCA.crt"
            version="3"
            sha1="23:88:C9:D3:71:CC:9E:96:3D:FF:7D:3C:A7:CE:fC:D6:25:EC:19:0D"
            modulus="2048"
            from="2005-04-06"
            to="2017-04-06"/>
      <crl url="http://www.e-szigno.hu/minositett_crl.html">Qualified services (list of CRLs)</crl>
      <crl url="http://www.e-szigno.hu/fokozott_crl.html">Non-qualified services (list of CRLs)</crl>
      <ocsp><!-- none that is public --></ocsp>
      <type>OV</type>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--minositett--v4.1.pdf">Qualified
      Certificate CPS</document>
      <document url="http://www.e-szigno.hu/docs/hitelesitesiRend--v3.1.pdf">ETSI TS
      101.456, QCP public CP</document>
      <document url="http://www.e-szigno.hu/docs/mhr_v14_e.pdf">ETSI TS
      101.456, SSCD CP</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--fokozott--v1.1.pdf">Non-qualified
      Certificates CPS (electronic signatures)</document>
      <document url="http://www.e-szigno.hu/docs/ehr+_v14_e.pdf">ETSI TS 102.042, NCP+ CP</document>
      <document url="http://www.e-szigno.hu/docs/ehr_v14_e.pdf">ETSI TS 102.042, NCP CP</document>
      <document url="http://www.e-szigno.hu/docs/hrf--v1.2.pdf">ETSI TS 102.042, NCP
      and ETSI TS 102.042, LCP CP</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--altalanos--v1.0.pdf">Non-qualified
      Certificates CPS (other uses)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370505</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="S-TRUST" url="https://www.s-trust.de/" status="complete">

    <summary>Deutscher Sparkassen Verlag GmbH is the world's largest
      smartcard provider and the central certification service
      provider for all German savings banks. This CA exists to enable
      up to 40 million German customers (end-users) to use their
      banking card as a certificate based signature, encryption and
      authentication device.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="https://www.secure.trusted-site.de/certuvit/pdf/6701UE.pdf">
      ETSI TS 101.456 Certificate</document>
    </audit>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6702UE.pdf">
      ETSI TS 102.042 Certificate</document>
    </audit>

    <certificate name="S-TRUST Authentication and Encryption Root CA 2005:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/authentication.crt"
            version="3"
            sha1="BE:B5:A9:95:74:6B:9E:DF:73:8B:56:E6:DF:43:7A:77:BE:10:6B:81"
            modulus="2048"
            from="2005-06-21"
            to="2030-06-21"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2005001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="S-TRUST Qualified Root CA 2008-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate1/ordner_crt_dateien/S-TRUSTQualifiedRootCA2008-00l_v3_509.crt"
            version="3"
            sha1="C9:2F:E6:50:DB:32:59:E0:CE:65:55:F3:8C:76:E0:B8:A8:FE:A3:CA"
            modulus="2048"
            from="2007-12-31"
            to="2012-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2008001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="S-TRUST Qualified Root CA 2007-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/STRUSTQualifiedRootCA2007-001.crt"
            version="3"
            sha1="7A:3C:1B:60:2E:BD:A4:A1:E0:EB:AD:7A:BA:4F:D1:43:69:A9:39:FC"
            modulus="2048"
            from="2006-12-31"
            to="2011-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2007001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="S-TRUST Qualified Root CA 2006-001:PN" status="complete">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/S-TRUST_Qualified_Root_CA_2006-001_PN.crt"
            version="3"
            sha1="7D:DC:76:1C:FD:AF:4C:E0:3A:B5:3A:DD:C9:FA:13:35:19:A3:DE:C9"
            modulus="2048"
            from="2005-12-31"
            to="2010-12-30"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2006001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="DigiNotar" url="http://www.diginotar.nl/" status="complete">
    <summary>DigiNotar is a Dutch trusted third party, mainly
      operating in the Netherlands.  They issue certificates based on
      notary verification of applicants. They service the business,
      government and consumer markets.</summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.pwc.nl/">Price Waterhouse Coopers</auditor>
      <document url="http://www.diginotar.nl/files/etsi.pdf">ETSI Certificate</document>
    </audit>

    <certificate name="DigiNotar Root CA" status="complete">
      <summary>This is the top root, used only to issue CA
        certificates for five application-specific subordinate CAs:
        DigiNotar Public CA 2025 (non-qualified personal
        certificates), DigiNotar Qualified CA (qualified personal
        certificates), DigiNotar Services CA (SSL and object signing
        certificates), DigiNotar Extended Validation CA (EV
        certificates), and DigiNotar Private CA (CA certificates for
        organizational CAs).</summary>
        <data url="http://www.diginotar.nl/files/Rootcertificaten/DigiNotar%20root%20CA2007.crt"
        version="3"
        sha1="C0:60:ED:44:CB:D8:81:BD:0E:F8:6C:0B:A2:87:DD:CF:81:67:47:8C"
        modulus="4096" from="2007-05-16" to="2025-03-31"/>
      <crl url="http://service.diginotar.nl/crl/root/latestCRL.crl">CRL</crl>
      <ocsp>http://validation.diginotar.nl</ocsp>
      <type>DV, IV, EV (policy OID ??)</type>
      <document url="http://www.diginotar.com/Portals/0/General%20terms/DigiNotar_CPS_3.5_-_EN.pdf">CPS DigiNotar 30 October 2007, Version 3.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=369357</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Austrian TCC" url="http://www.signatur.rtr.at/"      status="complete">
    <summary>The Telekom-Control Commission is the Austrian supervisory authority for electronic signatures. Its
responsibility includes supervision of all certification service providers
established in Austria. For every CA key used by an
Austrian certification service provider, the TKK issues a certificate to the
certification service provider. Based on these certificates, all certificates
issued by supervised Austrian certification service providers can be verified.
There are five subordinate CAs, each of which issues certificates for a different purpose.
</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.a-sit.at/">Secure Information Technology Center - Austria</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=204776">Conformity Assessment Statement</document>
    </audit>

    <certificate name="Telekom-Control-Kommission Top 1" status="complete">
      <summary>The TKK issues certificates to certification service providers who are
supervised according to the Austrian Electronic Signatures Act.
The corresponding private keys of certification service
providers are used for issuing certificates to end entities (signatories).</summary>
      <data url="http://www.signatur.rtr.at/currenttop.cer"
            version="3"
            sha1="91:49:29:EE:C7:A0:21:B5:DA:49:1A:35:A5:98:4C:2C:F2:5B:C7:55"
            modulus="2048"
            from="2005-09-13"
            to="2010-09-13"/>
      <crl url="http://www.signatur.rtr.at/current.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>

      <document url="http://www.signatur.rtr.at/repository/tkk-cp-10-20020909-de.pdf">Certificate
      Policy</document>
      <document url="http://www.signatur.rtr.at/repository/tkk-cps-14-20060612-de.pdf">Certificate
      Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373174</authorisation>
        <technical></technical>
      </inclusion>
      <comments>CRL doesn't work in Firefox - bug 133191.</comments>
    </certificate>
  </authority>

  <authority name="VeriSign" url="http://www.verisign.com/" status="incomplete">
    <summary>VeriSign is a major commercial CA with worldwide
    operations and customer base.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=304&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://bugzilla.mozilla.org/attachment.cgi?id=287877">CA-supplied
      auditor's letter re WebTrust EV audit</document>
    </audit>
    <certificate name="VeriSign Class 3 Public Primary Certification Authority - G5" status="pending">
      <summary>This CA issues a CA certificate to the subordinate CA
        "VeriSign Class 3 Extended Validation SSL SGC CA", which in
        turn issues Extended Validation certificates for SSL-enabled
        servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=304810"
            version="3"
            sha1="4E:B6:D5:78:49:9B:1C:CF:5F:58:1E:AD:56:BE:3D:9B:67:44:A5:E5"
            modulus="2048"
            from="2006-11-07"
            to="2036-07-16"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPSv3.5.pdf">VeriSign
      Certification Practice Statement, Version 3.5</document>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPv2.5.pdf">VeriSign
      Trust Network Certificate Policies, Version 2.5</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=402947</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=422921</technical>
      </inclusion>
      <comments>Note that for compatibility reasons VeriSign has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter VeriSign EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing VeriSign Class 3 Public Primary CA
        root.</comments>
    </certificate>

    <certificate name="VeriSign Class 3 Public Primary Certification Authority" status="incomplete">
      <summary>This root CA (also known as PCA3 - G1) participates in
        the cross-signing scheme by which EV certs issued under the
        VeriSign Class 3 Public Primary Certification Authority - G5
        hierarchy may chain up to existing VeriSign roots.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=311901"
            version="1"
            sha1="74:2c:31:92:e6:07:e4:24:eb:45:49:54:2b:e1:bb:c5:3e:61:74:e2"
            modulus="1024"
            from="1996-01-28"
            to="2028-08-01"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPSv3.5.pdf">VeriSign
      Certification Practice Statement, Version 3.5</document>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPv2.5.pdf">VeriSign
      Trust Network Certificate Policies, Version 2.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=420760</authorisation>
      </inclusion>
      <comments>This root CA certificate is already included in
      Mozilla; the present request is to enable this root for
      EV.</comments>
    </certificate>

    <certificate name="VeriSign Class 3 Public Primary Certification Authority - G2" status="incomplete">
      <summary>This root CA (also known as PCA3 - G2) participates in
        the cross-signing scheme by which EV certs issued under the
        VeriSign Class 3 Public Primary Certification Authority - G5
        hierarchy may chain up to existing VeriSign roots.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=311902"
            version="3"
            sha1="85:37:1C:A6:E5:50:14:3D:CE:28:03:47:1B:DE:3A:09:E8:F8:77:0F"
            modulus="1024"
            from="1998-05-17"
            to="2028-08-01"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPSv3.5.pdf">VeriSign
      Certification Practice Statement, Version 3.5</document>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPv2.5.pdf">VeriSign
      Trust Network Certificate Policies, Version 2.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=420760</authorisation>
      </inclusion>
      <comments>This root CA certificate is already included in
      Mozilla; the present request is to enable this root for
      EV.</comments>
    </certificate>

    <certificate name="VeriSign Class 3 Public Primary Certification Authority - G3" status="incomplete">
      <summary>This root CA (also known as PCA3 - G3) participates in
        the cross-signing scheme by which EV certs issued under the
        VeriSign Class 3 Public Primary Certification Authority - G5
        hierarchy may chain up to existing VeriSign roots.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=311902"
            version="1"
            sha1="13:2D:0D:45:53:4B:69:97:CD:B2:D5:C3:39:E2:55:76:60:9B:5C:C6"
            modulus="2048"
            from="1999-09-30"
            to="2036-07-16"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPSv3.5.pdf">VeriSign
      Certification Practice Statement, Version 3.5</document>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPv2.5.pdf">VeriSign
      Trust Network Certificate Policies, Version 2.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=420760</authorisation>
      </inclusion>
      <comments>This root CA certificate is already included in
      Mozilla; the present request is to enable this root for
      EV.</comments>
    </certificate>
  </authority>

  <authority name="WISeKey" url="http://www.wisekey.com/" status="pending">
    <summary>WISeKey operates the CertifyID Trust Service, which
      supports customer-specific CAs under a CA hierarchy rooted at
      the WISeKey Global Root GA CA and containing Policy CAs
      (subordinate to the root) and Issuing CAs (subordinate to the
      Policy CAs). Note that all end-entity certificates are issued by
      the Issuing CAs under policies set by WISeKey.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.webtrust.es/">WTE y E. Álvarez Auditores, S.L.</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=643&amp;file=pdf">Audit Report
      and Management's Assertions</document>
    </audit>

    <certificate name="OISTE WISeKey Global Root GA CA" status="complete">

      <summary>As noted above, the Global Root GA CA is the one and
        only root for the entire CertifyID system. It issues CA
        certificates to Policy CAs, which in turn issue CA
        certificates to Issuing CAs. There are three types of Policy
        CAs (Standard, Advanced, and Qualified) and three types of
        Issuing CAs corresponding to these, each issuing a different
        class of certificates; verification requirements for
        applicants vary by class.
      </summary>
      <data url="http://public.wisekey.com/crt/owgrgaca.crt"
            version="3"
            sha1="59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9"
            modulus="2048"
            from="2005-12-11"
            to="2037-12-11"/>
      <crl url="http://public.wisekey.com/crl/owgrgaca.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV</type>

      <document url="http://www.wisekey.com/NR/rdonlyres/2591F1F6-4E8D-4648-B78D-0DE6DB1B1EA2/0/OISTEWISEKEYROOTCPS101Jan162007.pdf">OISTE WISeKey Root CPS 1.01</document>
      <document url="http://www.wisekey.com/NR/rdonlyres/5E650761-E829-4622-88FD-B02122723A4D/0/CertifyIDValidationVerificationOverview.pdf">CertifyID Identity Validation Overview, Version 1.0</document>
      <document url="http://www.wisekey.com/NR/rdonlyres/04231832-B4A9-4163-A66E-AFF28476EFED/0/WISeKeyAdvancedIssuingCACPSv101Jan162007signed.pdf">WISeKey SA Advanced Services Issuing Certification Authority Certification Practice Statement, Version 1.01</document>
      <document url="http://www.wisekey.com/NR/rdonlyres/658D7472-9AD2-4F44-AD63-2314B13F787D/0/WD0011TECHNICALSECURITYCONTROLS.pdf">Technical Security Controls WD0011 - Version 1.0.1</document>
      <document url="http://www.wisekey.com/NR/rdonlyres/BA29BF9E-C56E-4FB2-A780-A85617892096/0/cidclassed.pdf">Table comparing the three different classes of end-entity certificates issued by Issuing CAs.</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=371362</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <comments>Note that the CPS for the root CA addresses only
      procedures related to issuance of certificates for its
      subordinate CAs. Issues related to issuance of end entity
      certificates are addressed in the other two documents
      references, in particular the CPS for the Advanced Services
      Issuing CA.</comments>
  </authority>

  <authority name="A-Trust" url="https://www.a-trust.at/"               status="incomplete">
    <summary>a.trust is an accredited Trust Center in
  Austria issuing smartcard-based qualified certificates for Austrian citizens,
  to be used in eGovernment, etc.</summary>
    <!--
    <audit type="ETSI TS 101.456">
      <auditor url="http://signatur.rtr.at/en/index.html">Telekom Control Commission</auditor>
      <document url="http://www.signatur.rtr.at/en/providers/providers/atrust.html">A-Trust entry on TCC website</document>
    </audit>
    -->

    <certificate name="A-Trust-Qual-01" status="complete">
      <summary>The intermediate CAs below this CA issue only qualified smartCard-based certificates
      to a natural person after a face-to-face identification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-01a.crt"
            version="3"
            sha1="E6:19:D2:5B:38:0B:7B:13:FD:A3:3E:8A:58:CD:82:D8:A8:8E:05:15"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="A-Trust-Qual-02" status="complete">
      <summary>The intermediate CAs below this CA issue qualified smartCard-based certificates to a natural person after a face-to-face identification,
   smartCard-based certificates to a natural person after a face-to-face identification (eg.: email), and
   server certificates (eg. SSL) after domain-verification.</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-Qual-02a.crt"
            version="3"
            sha1="67:9A:4F:81:FC:70:5D:DE:C4:19:77:8D:D2:EB:D8:75:F4:C2:42:C6"
            modulus="2048"
            from="2004-12-02"
            to="2014-12-02"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-qual&amp;vers=-02">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
      <comment>Presumably the sub-CA for which they have given a CP/CPS is only signed by one of these four...</comment>
    </certificate>

    <certificate name="A-Trust-nQual-01" status="complete">
      <summary>The intermediate CAs below this CA issue smartCard-based certificates to a natural person after a face-to-face identification (eg.: email),
   software certificates (pKCS#12), and
   server certificates (eg. SSL) after domain-verification</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-01a.crt"
            version="3"
            sha1="51:A4:4C:28:F3:13:E3:F9:CB:5E:7C:0A:1E:0E:0D:D2:84:37:58:AE"
            modulus="2048"
            from="2004-11-30"
            to="2014-11-30"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-01">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="A-Trust-nQual-03" status="complete">
      <summary>The intermediate CAs below this CA issue smartCard-based certificates to a natural person after a face-to-face identification (eg.: email),
   software certificates (pKCS#12), and
   server certificates (eg. SSL) after domain-verification</summary>
      <data url="http://www.a-trust.at/certs/A-Trust-nQual-03.crt"
            version="3"
            sha1="D3:C0:63:F2:19:ED:07:3E:34:AD:5D:75:0B:32:76:29:FF:D5:9A:F2"
            modulus="2048"
            from="2005-08-17"
            to="2015-08-17"/>
      <crl url="http://www.a-trust.at/html/crl_download.asp?CA=a-trust-nqual&amp;vers=-03">CRL</crl>
      <ocsp>http://ocsp.a-trust.at/ocsp</ocsp>
      <type>DV, IV</type>

      <document url="https://www.a-trust.at/docs/cp">Full list of CPs</document>
      <document url="https://www.a-trust.at/docs/cps">Full list of CPSes</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=373746</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="ARGE DATEN" url="http://www.a-cert.at/"              status="incomplete">
    <summary>ARGE DATEN, the Austrian Society for Data Protection is a non-profit
    non-governmental organisation. It is the Austrian market leader
in issuing certificates for eBilling. It operates subordinate CAs for eBilling,
SSL Server Certificates, SSL Client Certificates, and members of
governmental institutions.</summary>
<!--
    <audit type="Government">
      <auditor url="http://www.rtr.at/">Rundfunk und Telekom Regulierungs GmbH</auditor>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-globaltrust.html">GLOBALTRUST Audit</document>
      <document url="http://www.signatur.rtr.at/de/providers/services/argedaten-a-cert-advanced.html">A-CERT ADVANCED Audit</document>
      <document url="http://www.globaltrust.info/static/third-party-audits.pdf">List of Third Party Audits</document>
    </audit>
-->

    <certificate name="A-CERT ADVANCED" status="complete">
      <summary>This root certificate issues both end-user certificates and CA certificates.
      It is the current root certificate of ARGE DATEN.</summary>
      <data url="http://www.a-cert.at/static/a-cert-advanced.crt"
            version="3"
            sha1="29:64:B6:86:13:5B:5D:FD:DD:32:53:A8:9B:BC:24:D7:4B:08:C6:4D"
            modulus="2048"
            from="2004-10-23"
            to="2011-10-23"/>
      <crl url="http://www.a-cert.at/static/advanced.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.a-cert.at/static/a-cert-certificate-policy-english.pdf">A-CERT Certificate Policy v1.5</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="GLOBALTRUST" status="complete">
      <summary>This root certificate will not directly issue end-user certificates. It is used
      to issue the subordinate CA certificates which in turn issue the end-user
      certificates. This certificate is the
      successor to the A-CERT ADVANCED root certificate.</summary>
      <data url="http://www.globaltrust.info/static/globaltrust2006.crt"
            version="3"
            sha1="34:2C:D9:D3:06:2D:A4:8C:34:69:65:29:7F:08:1E:BC:2E:F6:8F:DC"
            modulus="4096"
            from="2006-08-07"
            to="2036-09-18"/>
      <crl url="http://www.globaltrust.info/static/globaltrust2006.crl">CRL</crl>
      <ocsp>http://ocsp.a-cert.at</ocsp>
      <type>IV</type>

      <document url="http://www.globaltrust.eu/static/globaltrust-certificate-policy-english.pdf">GLOBALTRUST Certificate Policy v1.2</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=348987</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Trustis" url="http://www.trustis.com/"               status="complete">
    <summary>Trustis is a commercial CA operating primarily in the UK and Europe.</summary>
    <audit type="WebTrust Equivalent">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.trustis.com/pki/fps/policy/T-TSC-AUDIT-KPMG Full Audit Report FPS.pdf">Audit
      Report and Management Assertions</document>
    </audit>
    <audit type="tScheme">
      <auditor url="http://www.lrqa.co.uk/products/security/">Lloyds Register Quality Assurance</auditor>
      <document url="http://www.tscheme.org/directory/trustis/index.html">Service
      Description and Profile details</document>
    </audit>

    <certificate name="Trustis FPS Root CA" status="complete">
      <summary></summary>
      <data url="http://www.trustis.com/roots/fps/certs/fpsroot.crt"
            version="3"
            sha1="3B:C0:38:0B:33:C3:F6:A6:0C:86:15:22:93:D9:DF:F5:4B:81:C0:04"
            modulus="2048"
            from="2003-12-23"
            to="2024-01-21"/>
      <crl url="http://www.trustis.com/pki/fps/crl/fpsder.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>IV</type>

      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-certificate-policy-v1.04.pdf">Trustis FPS Root CP v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/t-adm-tsc-trustis-fps-root-PDS-v1.04.pdf">PKI Disclosure Statement v1.04</document>
      <document url="http://www.trustis.com/pki/fps/policy/Trustis-Certification-Practice-Statement V1.1.pdf">Trustis CPS v1.1</document>

      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=324126</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>



  <authority name="TÜRKTRUST" url="http://www.turktrust.com.tr/"        status="pending">
    <summary>TÜRKTRUST is a Turkish CA issuing qualified certificates in Turkey.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Telecommunications Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=264748">Letter of Official CA Statement</document>
      <document url="http://www.tk.gov.tr/eimza/eshs.htm">List of accredited CAs</document>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/tt.doc">Audit statement on auditor website</document>
    </audit>

    <certificate name="TURKTRUST Certificate Services Provider Root 1" status="pending">
      <summary>Root 1 is a "legacy" root included for compatibility
      with previously-issued certificates. The English version of the
      CPS applies to both roots.</summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/TURKTRUST_Elektronik_Sertifika_Hizmet_Saglayicisi.crt"
            version="3"
            sha1="79:98:A3:08:E1:4D:65:85:E6:C2:1E:15:3A:71:9F:BA:5A:D3:4A:D9"
            modulus="2048"
            from="2005-05-13"
            to="2015-03-22"/>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_KOK1NES.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_SSL_SIL_s1.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr/</ocsp>
      <type>DV, IV</type>

      <document url="http://www.turktrust.com.tr/pdf/cps_third.pdf">CPS v03 (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380635</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=410821</technical>
      </inclusion>
    </certificate>

    <certificate name="TURKTRUST Certificate Services Provider Root 2" status="pending">
      <summary>Root 2 is the new root that replaced Root 1; Root 2 is
      used for certificates currently being issued. The English
      version of the CPS applies to both roots.</summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/kok_s2.crt"
            version="3"
            sha1="B4:35:D4:E1:11:9D:1C:66:90:A7:49:EB:B3:94:BD:63:7B:A7:82:B7"
            modulus="2048"
            from="2005-07-11"
            to="2015-09-16"/>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL_s2.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Nitelikli_SIL_s2.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_SSL_SIL_s2.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr/</ocsp>
      <type>DV, IV</type>

      <document url="http://www.turktrust.com.tr/pdf/cps_third.pdf">CPS v03 (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380635</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=410821</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Entrust" url="http://www.entrust.net/"               status="complete">
    <summary>Entrust is a commercial CA
serving the global market for SSL web certificates. Entrust also issues
certificates to subordiate CAs for enterprise and commercial use.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.ca/">Deloitte and Touche LLP</auditor>
      <document url="https://entrust.webtrust.org/SealFile?seal=328&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>

    <certificate name="Entrust Root Certification Authority" status="complete">
      <summary>This root was primarily created as the trust root for Entrust EV SSL
      certificates.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=267983"
            version="3"
            sha1="B3:1E:B1:B7:40:E3:6C:84:02:DA:DC:37:D4:4D:F5:D4:67:49:52:F9"
            modulus="2048"
            from="2006-11-27"
            to="2026-11-27"/>
      <crl url="http://crl.entrust.net/rootca1.crl">CRL</crl>
      <ocsp>http://ocsp.entrust.net</ocsp>
      <type>OV, EV</type>

      <document url="http://www.entrust.net/CPS/pdf/webcps051404.pdf">CPS v2.06</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=382352</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="ComSign" url="http://www.comsign.co.il/"             status="incomplete">
    <summary>ComSign is a commercial Israeli CA.</summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="ComSign CA" status="incomplete">
      <summary>Used for signing subordinates for issuing digital ID's to individuals and
      corporations in accordance w/ the Israeli Electronic Signature Law.</summary>
      <data url="http://fedir.comsign.co.il/cacert/ComsignCA.crt"
            version="3"
            sha1="E1 A4 5B 14 1A 21 DA 1A 79 F4 1A 42 A9 61 D6 69 CD 06 34 C1"
            modulus="2048"
            from="2004-03-24"
            to="2029-03-19"/>
      <crl url="http://fedir.comsign.co.il/crl/ComSignCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV</type>
      <document url="http://www.comsign.co.il/repository/PDFs/English_CPS_final.pdf">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=382158</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="ComSign Secured CA" status="incomplete">
      <summary>Used for signing subordinates for issuing digital ID's to individuals and
      corporations in accordance w/ the Israeli Electronic Signature Law.</summary>
      <data url="http://fedir.comsign.co.il/cacert/ComsignSecuredCA.crt"
            version="3"
            sha1="F9 CD 0E 2C DA 76 24 C1 8F BD F0 F0 AB B6 45 B8 F7 FE D5 7A"
            modulus="2048"
            from="2004-03-24"
            to="2029-03-16"/>
      <crl url="http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl">CRL</crl>
      <ocsp></ocsp>
      <type>DV, IV, EV</type>
      <document url="http://www.comsign.co.il/repository/PDFs/English_CPS_final.pdf">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=382158</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="ComSign Advanced Security CA" status="incomplete">
      <summary>Used for signing subordinates for issuing digital ID's to individuals and
      corporations in accordance w/ the Israeli Electronic Signature Law.</summary>
      <data url="http://fedir.comsign.co.il/cacert/ComsignAdvancedSecurityCA.crt"
            version="3"
            sha1="80 BF 3D E9 A4 1D 76 8D 19 4B 29 3C 85 63 2C DB C8 EA 8C F7"
            modulus="4096"
            from="2004-03-24"
            to="2029-03-24"/>
      <crl url="http://fedir.comsign.co.il/crl/ComSignAdvancedSecurityCA.crl">CRL</crl>
      <ocsp></ocsp>
      <type>DV, IV, EV</type>
      <document url="http://www.comsign.co.il/repository/PDFs/English_CPS_final.pdf">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=382158</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

  </authority>

  <authority name="Kamu SM" url="http://www.kamusm.gov.tr/"             status="complete">
    <summary>Kamu Sertifikasyon Merkezi is the one government CA in Turkey
    that has authorization to issue certificates to
    government entities. They are also authorised to issue to commercial companies.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Telecommunications Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=269065">Letter from the TA</document>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/ue.doc">TTA statement of ETSI compliance</document>
    </audit>

    <certificate name="TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı" status="complete">
      <summary></summary>
      <data url="http://www.kamusm.gov.tr/BilgiDeposu/KOKSHS.v2.crt"
            version="3"
            sha1="30:30:AC:AB:B5:4B:2D:31:FF:A7:06:00:EA:74:C0:F1:A6:70:BF:91"
            modulus="4096"
            from="2005-10-03"
            to="2015-10-03"/>
      <crl url="http://www.kamusm.gov.tr/BilgiDeposu/KOKSIL.v2.crl">CRL</crl>
      <ocsp>http://ocsp.kamusm.gov.tr</ocsp>
      <type>DV, IV</type>
      <document url="http://www.kamusm.gov.tr/BilgiDeposu/KSM_NES_SI/KSM_NES_SI.pdf">CP</document>
      <document url="http://www.kamusm.gov.tr/BilgiDeposu/KSM_NES_SUE/KSM_NES_SUE.pdf">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381974</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="Izenpe" url="http://www.izenpe.com/"                 status="incomplete">
    <summary>Izenpe is owned by the government of the Basque country, Spain.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.bsi-global.com/">BSI Management Systems</auditor>
      <document url="http://www.izenpe.com/s15-4812/es/contenidos/nota_prensa/nota_prensa_iso27001/es_iso27001/adjuntos/Certificate.pdfs">ETSI Certificate</document>
    </audit>

    <certificate name="Izenpe" status="incomplete">
      <summary></summary>
      <data url="https://servicios.izenpe.com/certificados/ca_raiz.crt"
            version="3"
            sha1="4A:3F:8D:6B:DC:0E:1E:CF:CD:72:E3:77:DE:F2:D7:FF:92:C1:9B:C7"
            modulus="2048"
            from="2006-01-31"
            to="2018-01-31"/>
      <crl url="http://www.izenpe.com/cgi-bin/arl">CRL</crl>
      <ocsp>http://ocsp.izenpe.com:8094</ocsp>
      <type>DV, OV</type>
      <document url="http://www.izenpe.com/cps">Declaración de Prácticas de Certificación v3.8</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=361957</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
  <authority name="T-Systems" url="http://pki.telesec.de/service/certificates/" status="complete">
    <summary>T-Systems is a wholly-owned subsidiary of Deutsche Telekom AG.</summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.t-systems-zert.com/">T-Systems GEI</auditor>
      <document url="http://www.t-systems-zert.com/pdf/ein_03_sig_zda/zf_03a180_e.pdf">ETSI 101.456 Certificate of Compliance</document>
    </audit>

    <certificate name="Deutsche Telekom Root CA 2" status="complete">
      <summary></summary>
      <data url="http://wwwca.telesec.de/cgi-bin/caservice/Common/InstallRoot/DT-Root-CA-2.cer"
            version="3"
            sha1="85:A4:08:C0:9C:19:3E:5D:51:58:7D:CD:D6:13:30:FD:8C:DE:37:BF"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-10"/>
      <crl url="http://pki.telesec.de/cgi-bin/service/af_DownloadARL.crl?-crl_format=X_509?-issuer=DT_ROOT_CA_2">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV</type>
      <document url="http://pki.telesec.de/service/DT_ROOT_CA_2/T-Systems-Root-CP-deutsch-v11.pdf">CP v1.1</document>
      <document url="http://pki.telesec.de/service/DT_ROOT_CA_2/cps.pdf">CPS v1.0</document>
      <document url="http://pki.telesec.de/service/documents/T-Systems-CPS-CA-2-English-v11.pdf">CPS v1.1 (English)</document>
      <document url="http://pki.telesec.de/service/documents/T-Systems-Root-CP-English-v12.pdf">CP v1.2 (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=378882</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TC TrustCenter" url="http://www.trustcenter.de/"     status="needscheck">
    <summary>TC TrustCenter is a commercial CA based in Germany.
They offer a variety of products and services including SSL Server
certificates and Email certificates.</summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuevit.de/">TÜV-IT Germany</auditor>
      <document url="https://www.secure.trusted-site.de/certuvit/pdf/6706UE.pdf">ETSI TS 102.042 LCP Certificate</document>
    </audit>

    <certificate name="TC TrustCenter Class 1 CA" status="needscheck">
      <summary>This root is used for email and SSL client auth only.</summary>
      <data url="http://www.trustcenter.de/certservices/cacerts/tcclass1-2011.der"
            version="3"
            sha1="72:0F:C1:5D:DC:27:D4:56:D0:98:FA:BF:3C:DD:78:D3:1E:F5:A8:DA"
            modulus="1024"
            from="1998-03-09"
            to="2011-01-01"/>
      <crl url="http://www.trustcenter.de/crl/v2/tcclass1.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass1.trustcenter.de/</ocsp>
      <type>DV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="TC TrustCenter Class 2 II" status="needscheck">
      <summary>This Root is being used to issue all types of certificate, e.g. Email Security,
SSL-Client-Authentication, SSL-Server, CodeSigning.</summary>
      <data url="http://www.trustcenter.de/media/class_2_ii.der"
            version="3"
            sha1="AE:50:83:ED:7C:F4:5C:BC:8F:61:C6:21:FE:68:5D:79:42:21:15:6E"
            modulus="2048"
            from="2006-01-12"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass2-ii.trustcenter.de</ocsp>
      <type>IV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="TC TrustCenter Class 3 II" status="needscheck">
      <summary>This Root is being used to issue all types of
certificate, e.g. Email Security, SSL-Client-Authentication, SSL-Server,
CodeSigning.</summary>
      <data url="http://www.trustcenter.de/media/class_3_ii.der"
            version="3"
            sha1="80:25:EF:F4:6E:70:C8:D4:72:24:65:84:FE:40:3B:8A:8D:6A:DB:F5"
            modulus="2048"
            from="2006-01-12"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass3-ii.trustcenter.de</ocsp>
      <type>IV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="TC TrustCenter Class 4 II" status="needscheck">
      <summary>This Root is being used to issue all types of certificate, e.g. Email Security,
SSL-Client-Authentication, SSL-Server, CodeSigning.</summary>
      <data url="http://www.trustcenter.de/media/class_4_ii.der"
            version="3"
            sha1="A6:9A:91:FD:05:7F:13:6A:42:63:0B:B1:76:0D:2D:51:12:0C:16:50"
            modulus="2048"
            from="2006-03-23"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_4_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass4-ii.trustcenter.de</ocsp>
      <type>EV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
       <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="TC TrustCenter Universal I" status="needscheck">
      <summary>This Root
is being used to issue all types of certificate, e.g. Email Security,
SSL-Client-Authentication, SSL-Server, CodeSigning.</summary>
      <data url="http://www.trustcenter.de/media/Universal_CA-I.der"
            version="3"
            sha1="6B:2F:34:AD:89:58:BE:62:FD:B0:6B:5C:CE:BB:9D:D9:4F:4E:39:F3"
            modulus="2048"
            from="2006-03-22"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_universal_root_I.crl">CRL</crl>
      <ocsp>http://ocsp.tcuniversal-i.trustcenter.de</ocsp>
      <type>DV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="TC TrustCenter Universal II" status="needscheck">
      <summary>This Root
is being used to issue all types of certificate, e.g. Email Security,
SSL-Client-Authentication, SSL-Server, CodeSigning.</summary>
      <data url="http://www.trustcenter.de/media/Universal_CA-II.der"
            version="3"
            sha1="8C:C4:30:7B:C6:07:55:E7:B2:2D:D9:F7:FE:A2:45:93:6C:7C:F2:88"
            modulus="4096"
            from="2006-03-22"
            to="2030-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_universal_root_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcuniversal-ii.trustcenter.de</ocsp>
      <type>DV</type>
      <document url="http://www.trustcenter.de/media/cpd-en_V44_24-04-06.pdf">CP (October 23rd, 2006)</document>
      <document url="http://www.trustcenter.de/media/cps-en_July-5-2007.pdf">TC TrustCenter GmbH CPS v1.6</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="SECOM Trust" url="http://www.secomtrust.net/" status="complete">
    <summary>SECOM Trust Services Co., Ltd are a commercial CA based in Japan.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/Extweb/home.nsf/docid/CC9D4B80132947F8CA2571E2002A1B75">PricewaterhouseCoopers Aarata</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=599&amp;file=pdf">Report of Independent Certified Public Accountant</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://people.mozilla.com/~gen/secomtrust/SECOM-WTEV-Report.pdf">Audit Report and Management's Assertion</document>
    </audit>

    <certificate name="Security Communication EV RootCA1" status="complete">
      <summary></summary>
      <data url="https://repository.secomtrust.net/EV-Root1/EVRoot1ca.cer"
            version="3"
            sha1="FE:B8:C4:32:DC:F9:76:9A:CE:AE:3D:D8:90:8F:FD:28:86:65:64:7D"
            modulus="2048"
            from="2007-06-06"
            to="2037-06-06"/>
      <crl url="https://repository.secomtrust.net/EV-Root1/EVRoot1CRL.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>EV</type>
      <document url="https://repository.secomtrust.net/EV-Root1/EVRoot1CPS.pdf">Security Communication EV RootCA1 Certification Practice Statement, Version 1.00 (Japanese)</document>
      <document url="https://repository.secomtrust.net/EV-Root1/EVRoot1CP1.pdf">Security Communication EV RootCA1 Subordinate CA Certificate Policy, Version 1.00 (Japanese)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=394419</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="QuoVadis" url="http://www.quovadis.bm/" status="pending">
    <summary>QuoVadis is a commercial CA, based in Bermuda and
    operating globally.  QuoVadis is a Qualified Certification
    Services Provider in Switzerland.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst &amp; Young
      (Technology and Security Risk Services)</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=612&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document
      url="http://www.seco.admin.ch/sas/00229/00251/00254/index.html?lang=en">Swiss
      Accreditation Service statement</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/">Ernst &amp; Young</auditor>
      <document
      url="https://bugzilla.mozilla.org/attachment.cgi?id=288529">CA-supplied
      auditor's letter re WebTrust EV audit</document>
    </audit>

    <certificate name="QuoVadis Root CA 2" status="complete">
      <summary>This root will be used for SSL/device certificates,
      including standard "organisation validated" certificates as well
      as EV certificates. The associated EV policy OID is
      1.3.6.1.4.1.8024.0.2.100.1.2.</summary>
      <data url="http://www.quovadis.bm/public/qvrca2.crt"
            version="3"
            sha1="CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7"
            modulus="4096"
            from="2006-11-24"
            to="2031-11-24"
            ev-oid="1.3.6.1.4.1.8024.0.2.100.1.2"/>
      <crl url="http://crl.quovadisglobal.com/qvrca2.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV, EV</type>
      <document url="https://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.8.pdf">QuoVadis
      Root CA2 CP/CPS v1.8</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403665</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418701</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list (per bug 365281). The present request is to
      enable this CA certificate for EV.</comments>
    </certificate>

  </authority>

<!--
  <authority name="" url="" status="incomplete">
    <summary></summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url=""
            version=""
            sha1=""
            modulus=""
            from=""
            to=""/>
      <crl url="">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url=""></document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation></authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
  </authority>
-->

<!--
  <authority name="Visa" url="http://www.visaca.com/"                   status="incomplete">
    <summary>Certificates used with this root will be used with various Visa
websites associated with Visa products and services. Our main website is
visa.com.</summary>
    <audit type="">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url=""></document>
    </audit>

    <certificate name="" status="incomplete">
      <summary></summary>
      <data url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.pem"
            version="3"
            sha1=""
            modulus="2048"
            from="2005-06-27"
            to="2025-06-29"/>
      <crl url="http://enroll.visaca.com/VisaInfoDeliveryRootCA.crl">CRL</crl>
      <ocsp><!- - none - -></ocsp>
      <type>DV, IV</type>

      <document url=""></document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380067</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Certificate is served with the wrong content-type</comments>
  </authority>

  <authority name="ANCERT" url="http://www.ancert.com/"                 status="incomplete">
    <summary>ANCERT is the Notary Agency of Certification in Spain. It issues
    electronic recognized certificates to persons, companies, public corporations
    and others according to the requirements of the current Spanish regulations.</summary>
    <audit type="">
      <auditor url=""></auditor>
      <document url=""></document>
    </audit>

    <certificate name="Ancert Notarial" status="incomplete">
      <summary></summary>
      <data url="http://www.ancert.com/?do=productos.getDocuments&amp;group=certificados_notariales&amp;option=personal&amp;id=163"
            version="3"
            sha1="C0:9A:B0:C8:AD:71:14:71:4E:D5:E2:1A:5A:27:6A:DC:D5:E7:EF:CB"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTNOT.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>

    <certificate name="Ancert General Council of Notaries" status="incomplete">
      <summary></summary>
      <data url="http://www.notariado.org/n_tecno/feren/archivos/ANCERTCGN.crt"
            version="3"
            sha1="11:C5:B5:F7:55:52:B0:11:66:9C:2E:97:17:DE:6D:9B:FF:5F:A8:10"
            modulus="2048"
            from="2004-02-11"
            to="2024-02-11"/>
      <crl url="http://www.ancert.com/crl/ANCERTCGN.crl">CRL</crl>
      <ocsp></ocsp>
      <type></type>
      <document url="http://www.ancert.com/?do=productos&amp;group=certificados_notariales&amp;option=declaracion&amp;id=cps">CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=381558</authorisation>
        <technical></technical>
      </inclusion>
    </certificate>
    <comments>Cert 1 is a BIN file</comments>
  </authority>

-->

  <authority name="DigiCert" url="http://www.digicert.com/" status="pending">
    <summary>DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert
provides digital certification and identity assurance services internationally
to a variety of sectors including business, education, and government.</summary>
    <audit type="WebTrust">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=558&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://www.digicert.com/ev-final-webtrust-report.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="DigiCert High Assurance EV Root CA" status="complete">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt"
            version="3"
            sha1="5F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25"
            modulus="2048"
            from="2006-11-10"
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV (policy OID 2.16.840.1.114412.2.1)</type>
      <document url="http://www.digicert.com/DigiCert_CPS.pdf">DigiCert Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.6</document>
      <document url="http://www.digicert.com/DigiCert_EV-CPS.pdf">DigiCert Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403644</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=416827</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list. The present request is to enable this CA
      certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="Comodo" url="http://www.comodo.com/" status="incomplete">
    <summary>Comodo CA Ltd is a commercial CA based in the UK and
      serving customers worldwide. Comodo has eleven root CA certs
      already included in Mozilla, all of which it would like upgraded
      for EV use, and one additional EV root requested for
      inclusion. There are altogether 124 subordinate CAs signed by
      the root CAs listed below.  Some of them exist to differentiate
      between different Comodo brands or products and some are used to
      re-brand products for its partners. In each case Comodo retains
      the private key for the subordinate CA within its
      infrastructure.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=636&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.comodo.com/repository/ev_audit_report_and_management_assertions.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="AddTrust Class 1 CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustClass1CARoot.crt"
            version="3"
            sha1="CC:AB:0E:A0:4C:23:01:D6:69:7B:DD:37:9F:CD:12:EB:24:E3:94:9D"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustClass1CARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and code signing.</comments>
    </certificate>

    <certificate name="AddTrust External CA Root" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustExternalCARoot.crt"
            version="3"
            sha1="02:FA:F3:E2:91:43:54:68:60:78:57:69:4D:F5:E4:5B:68:85:18:68"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustExternalCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="AddTrust Public CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustPublicCARoot.crt"
            version="3"
            sha1="2A:B6:28:48:5E:78:FB:F3:AD:9E:79:10:DD:6B:DF:99:72:2C:96:E5"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustPublicCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV and to enable all trust bits if not already
        enabled.</comments>
    </certificate>

    <certificate name="AddTrust Qualified CA Root" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AddTrustQualifiedCARoot.crt"
            version="3"
            sha1="4D:23:78:EC:91:95:39:B5:00:7F:75:8F:03:3B:21:1E:C5:4D:8B:CF"
            modulus="2048"
            from="2000-05-30"
            to="2020-05-30"/>
      <crl url="http://crl.comodoca.com/AddTrustQualifiedCARoot.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="UTN - DATACorp SGC" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-DATACorpSGC.crt"
            version="3"
            sha1="58:11:9F:0E:12:82:87:EA:50:FD:D9:87:45:6F:4F:78:DC:FA:D6:D4"
            modulus="2048"
            from="1999-06-24"
            to="2019-06-24"/>
      <crl url="http://crl.comodoca.com/UTN-DATACorpSGC.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, code signing, and email.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Client Authentication and Email" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crt"
            version="3"
            sha1="B1:72:B1:A5:6D:95:F9:1F:E5:02:87:E1:4D:37:EA:6A:44:63:76:8A"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmail.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Hardware" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Hardware.crt"
            version="3"
            sha1="04:83:ED:33:99:AC:36:08:05:87:22:ED:BC:5E:46:00:E3:BE:F9:D7"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Hardware.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <document url="http://www.comodo.com/repository/December_2007_CPS_Amendment.pdf">December Addendum to the Comodo Certification Practice Statement v.3.0 (28 November 2007)</document>
      <document url="http://www.comodo.com/repository/Essential_SSL_addendum_to_the_Certification_Practice_Statement.pdf">Essential SSL addendum to the Certification Practice Statement (1 February 2007)</document>
      <document url="http://www.comodo.com/repository/PositiveSSL_addendum_to_the_Certification_Practice_Statement.pdf">Positive SSL addendum to the Certification Practice Statement (23 June 2006)</document>
      <document url="http://www.comodo.com/repository/litessl_cps_addendum.pdf">LiteSSL addendum to the Certification Practice Statement (3 February 2005)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, email, and code signing.</comments>
    </certificate>

    <certificate name="UTN-USERFirst-Object" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/UTN-USERFirst-Object.crt"
            version="3"
            sha1="E1:2D:FB:4B:41:D7:D9:C3:2B:30:51:4B:AC:1D:81:D8:38:5E:2D:46"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-09"/>
      <crl url="http://crl.comodoca.com/UTN-USERFirst-Object.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV, SSL, and email.</comments>
    </certificate>

    <certificate name="AAA Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/AAACertificateServices.crt"
            version="3"
            sha1="D1:EB:23:A4:6D:17:D6:8F:D9:25:64:C2:F1:F1:60:17:64:D8:E3:49"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/AAACertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/November_2007_CPS_Amendment.pdf">November 2007 Addendum to the Comodo Certification Practice Statement v.3.0 (31 October 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_Intel_Pro.pdf">August 2007 Intel Pro SSL Addendum to the Comodo Certification Practice Statement v.3.0 (17 August 2007)</document>
      <document url="http://www.comodo.com/repository/CPS_Amendment_of_Version_3_UCC.pdf">March 2007 Unified Communications Addendum to the Comodo Certification Practice Statement v.3.0 (1 March 2007)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Secure Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/SecureCertificateServices.crt"
            version="3"
            sha1="4A:65:D5:F4:1D:EF:39:B8:B8:90:4A:4A:D3:64:81:33:CF:C7:A1:D1"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/SecureCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="Trusted Certificate Services" status="incomplete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates (DV, OV and EV), email certificates, and code
        signing certificates.</summary>
      <data url="http://crt.comodoca.com/TrustedCertificateServices.crt"
            version="3"
            sha1="E1:9F:E3:0E:8B:84:60:9E:80:9B:17:0D:72:A8:C5:BA:6E:14:09:BD"
            modulus="2048"
            from="2004-01-01"
            to="2028-12-31"/>
      <crl url="http://crl.comodoca.com/TrustedCertificateServices.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.</comments>
    </certificate>

    <certificate name="COMODO Certification Authority" status="complete">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates, email certificates, and code signing
        certificates.</summary>
      <data url="http://crt.comodoca.com/COMODOCertificationAuthority.crt"
            version="3"
            sha1="66:31:BF:9E:F7:4F:9E:B6:C9:D5:A6:0C:BA:6A:BE:D1:F7:BD:EF:7B"
            modulus="2048"
            from="2006-12-01"
            to="2029-12-31"/>
      <crl url="http://crl.comodoca.com/COMODOCertificationAuthority.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical></technical>
      </inclusion>
      <comments>This is a new root CA certificate. The present request
        is to add this CA certificate and enable it for EV.</comments>
    </certificate>

  </authority>

  <authority name="Go Daddy" url="http://www.godaddy.com/" status="pending">
    <summary>Go Daddy operates a commercial CA based in the US and
      serving customers worldwide. Go Daddy has three root CA certs
      already included in Mozilla, all of which it would like upgraded
      for EV use.
    </summary>
    <audit type="WebTrust and WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=355&amp;file=pdf">Independent Accountants' Report</document>
    </audit>

    <certificate name="Valicert Class 2 Policy Validation Authority" status="pending">
      <summary>Root  CA  certificate  with  a  single  subordinate  CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.starfieldtech.com/repository/valicert_class2_root.crt"
            version="1"
            sha1="31:7A:2A:D0:7F:2B:33:5E:F5:A1:C3:4E:4B:57:E8:B7:D8:F1:FC:A6"
            modulus="1024"
            from="1999-06-25"
            to="2019-06-25"/>
      <crl url="https://certificates.starfieldtech.com/repository/root.crl">CRL</crl>
      <ocsp>http://ocsp.startfieldtech.com/</ocsp>
      <type>DV, IV/OV, EV (policy OIDs 2.16.840.1.114413.1.7.23.3 and 2.16.840.1.114414.1.7.23.3)</type>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV. Both of the CA certificates below are
        cross-signed to the Valicert Class 2 Policy Validation
        Authority root for legacy support, so this root should be
        configured to enable EV with both of the EV OIDs associated
        with the other certificates.
      </comments>
    </certificate>

    <certificate name="Go Daddy Class 2 CA" status="pending">
      <summary>Root CA certificate  with  a  single  subordinate  CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.godaddy.com/repository/gd-class2-root.crt"
            version="3"
            sha1="27:96:BA:E6:3F:18:01:E2:77:26:1B:A0:D7:77:70:02:8F:20:EE:E4"
            modulus="2048"
            from="2004-06-29"
            to="2034-06-29"/>
      <crl url="https://certificates.godaddy.com/repository/gdroot.crl">CRL</crl>
      <ocsp>http://ocsp.godaddy.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 2.16.840.1.114413.1.7.23.3)</type>
      <document url="https://certs.godaddy.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.
      </comments>
    </certificate>

    <certificate name="Starfield Class 2 CA" status="pending">
      <summary>Root CA certificate with a single subordinate CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.starfieldtech.com/repository/sf-class2-root.crt"
            version="3"
            sha1="AD:7E:1C:28:B0:64:EF:8F:60:03:40:20:14:C3:D0:E3:37:0E:B5:8A"
            modulus="2048"
            from="2004-06-29"
            to="2034-06-29"/>
      <crl url="https://certificates.starfieldtech.com/repository/sfroot.crl">CRL</crl>
      <ocsp>http://ocsp.starfieldtech.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 2.16.840.1.114414.1.7.23.3)</type>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
        in the Mozilla list. The present request is to enable this CA
        certificate for EV.
      </comments>
    </certificate>

  </authority>

  <authority name="GlobalSign" url="http://www.globalsign.com/" status="incomplete">
    <summary>GlobalSign is a commercial CA based in Portsmouth NH and
      serving customers worldwide. It currently has two root CA
      certificates preloaded in Mozilla. The first root has two
      subordinate CAs (for domain-validated and
      organizationally-validated certificates respectively) and the
      second root has one subordinate CA (for extended validation
      certificates). (There is also a valid chain from the EV
      subordinate to the first root via a cross-signing certificate.)
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.be/">Deloitte Belgium</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=637&amp;file=pdf">Certification Authorities Independent Audit Report</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.deloitte.be/">Deloitte Belgium</auditor>
      <document url="">(not available on web)</document>
    </audit>

    <certificate name="GlobalSign Root CA" status="incomplete">
      <summary>Root CA with two subordinate CAs issuing SSL
        certificates (DV and OV), email, and code signing
        certificates.
      </summary>
      <data url="http://secure.globalsign.net/cacert/Root-R1.crt"
            version="3"
            sha1="B1:BC:96:8B:D4:F4:9D:62:2A:A8:9A:81:F2:15:01:52:A4:1D:82:9C"
            modulus="2048"
            from="1998-09-01"
            to="2028-01-28"/>
      <crl url="http://crl.globalsign.net/root.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.4146.1.1)</type>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v6.0.pdf">GlobalSign Certification Practice Statement, version 6.0</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CA_CP_v3.0.pdf">GlobalSign CA Certificate Policy, version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406794</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that a version of this root CA certificate with
        the same public key but an earlier expiration date
        (2014-01-28) is already included in the Mozilla list. The
        present request is to replace the older certificate with this
        certificate and then enable this CA certificate for EV.
      </comments>
    </certificate>

    <certificate name="GlobalSign Root CA - R2" status="incomplete">
      <summary>Root CA with one subordinate CA issuing SSL
        certificates (EV), email, and code signing certificates.
      </summary>
      <data url="http://secure.globalsign.net/cacert/Root-R2.crt"
            version="3"
            sha1="75:E0:AB:B6:13:85:12:27:1C:04:F8:5F:DD:DE:38:E4:B7:24:2E:FE"
            modulus="2048"
            from="2006-12-15"
            to="2021-12-15"/>
      <crl url="http://crl.globalsign.net/root-r2.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.4146.1.1)</type>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v6.0.pdf">GlobalSign Certification Practice Statement, version 6.0</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CA_CP_v3.0.pdf">GlobalSign CA Certificate Policy, version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406796</authorisation>
        <technical></technical>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list. The present request is to enable this CA
      certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="Cisco" url="http://www.globalsign.com/" status="incomplete">
    <summary>Cisco is a leading provider of networking equipment to
      consumers and businesses worldwide.
    </summary>

    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/">PricewaterhouseCoopers</auditor>
      <document url="https://cert.webtrust.org/ViewSeal?id=728">Audit Report and Management Assertions</document>
    </audit>

    <certificate name="Cisco Root CA 2048" status="incomplete">

      <summary>This is an off-line root CA that issues CA certificates
        to one or more Cisco-controlled subordinate CAs (including the
        Cisco Manufacturing Sub-CA). The subordinate CAs in turn issue
        end entity certificates, e.g., for use in Cisco network
        equipment with embedded web servers and web-based
        administrative interfaces.
      </summary>
      <data url="http://www.cisco.com/security/pki/certs/crca2048.cer"
            version="3"
            sha1="DE:99:0C:ED:99:E0:43:1F:60:ED:C3:93:7E:7C:D5:BF:0E:D9:E5:FA"
            modulus="2048"
            from="2004-05-14"
            to="2029-05-14"/>
      <crl url="">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV</type>
      <document url="http://www.cisco.com/security/pki/policies/Certification_Practice_Statement_-_Cisco_Root_CA_2048_v1.1.doc">Cisco Root CA 2048
Certification Practice Statement, Version 1.1</document>
      <document url="http://www.cisco.com/security/pki/policies/Certificate_Policy_-_Cisco_Root_CA_2048_v1.0.doc">Cisco Root CA 2048 Certificate Policy, Version 1.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=416842</authorisation>
        <technical></technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="thawte" url="http://www.thawte.com/" status="complete">
    <summary>thawte is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust/WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=527&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="thawte Primary Root CA" status="complete">
      <summary>This CA issues a CA certificate to the subordinate CAs
        thawte Extended Validation SSL CA and thawte Extended
        Validation SSL SGC CA, which in turn issue Extended Validation
        certificates for SSL-enabled servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=306736"
            version="3"
            sha1="91:C6:D6:EE:3E:8A:C8:63:84:E5:48:C2:99:29:5C:75:6C:81:7B:81"
            modulus="2048"
            from="2006-11-17"
            to="2036-07-16"/>
      <crl url="http://crl.thawte.com/ThawteEVCA2006.crl">CRL</crl>
      <ocsp>http://ocsp.thawte.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.48.1)</type>
      <document url="http://www.thawte.com/guides/pdf/Thawte_CPS_3_5.pdf">thawte Certification Practice Statement, Version 3.5 (January 2008)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=407163</authorisation>
      </inclusion>
      <comments>Note that for compatibility reasons thawte has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter thawte EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing Thawte Premium Server CA root.</comments>
    </certificate>
  </authority>

  <authority name="GeoTrust" url="http://www.geotrust.com/" status="complete">
    <summary>GeoTrust is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust/WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=650&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="GeoTrust Primary Certification Authority" status="complete">
      <summary>This CA issues a CA certificate to the subordinate CA
        GeoTrust Extended Validation SSL CA, which in turn issues
        Extended Validation certificates for SSL-enabled
        servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=306731"
            version="3"
            sha1="32:3C:11:8E:1B:F7:B8:B6:52:54:E2:E2:10:0D:D6:02:90:37:F0:96"
            modulus="2048"
            from="2006-11-26"
            to="2036-07-16"/>
      <crl url="http://EVSSL-crl.geotrust.com/crls/gtextvalca.crl">CRL</crl>
      <ocsp>http://EVSSL-ocsp.geotrust.com/</ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.14370.1.6)</type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.pdf">GeoTrust Certification Practice Statement, Version 1.0 (January 31, 2008)</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=407168</authorisation>
      </inclusion>
      <comments>Note that for compatibility reasons GeoTrust has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter GeoTrust EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing Equifax Secure CA root.</comments>
    </certificate>
  </authority>

  <authority name="Network Solutions" url="http://www.networksolutions.com/" status="complete">
    <summary>Network Solutions is a US-based commercial CA with
      worldwide customer base.</summary>
    <audit type="WebTrust for CAs">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=705&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://www.networksolutions.com/SSL-certificates/kpmg-ev.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation 
Criteria</document>
    </audit>
    <certificate name="Network Solutions Certificate Authority" status="complete">
      <summary>This CA directly issues non-EV certificates for
        SSL-enabled servers (SiteSafe Basic, Pro, and Wildcard). The
        CA also has a subordinate CA, Network Solutions EV SSL CA,
        which issues Extended Validation certificates for SSL-enabled
        servers. There are no other subordinate CAs under this
        root.</summary>
      <data url="ftp://ftp.networksolutions.com/certs/netsolevroot.crt"
            version="3"
            sha1="74:F8:A3:C3:EF:E7:B3:90:06:4B:83:90:3C:21:64:60:20:E5:DF:CE"
            modulus="2048"
            from="2006-12-01"
            to="2029-12-31"/>
      <crl url="http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl">CRL</crl>
      <ocsp></ocsp>
      <type>IV/OV, EV (policy OID 1.3.6.1.4.1.782.1.2.1.8.1)</type>
      <document url="http://www.networksolutions.com/legal/SSL-legal-repository-cps.jsp">Network Solutions Certification Practice Statement, Version 1.4.1</document>
      <document url="https://www.networksolutions.com/legal/SSL-legal-repository-ev-cps.jsp">Certification Practice Statement (CPS) for Extended Validation (EV) Certification, Version 1.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403915</authorisation>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

</certificates>
