<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="included.xsl"?>

<certificates type="included">
  <!-- Example -->
  <authority name="DigiCert" url="http://www.digicert.com/"             >
    <summary>DigiCert is a US-based commercial CA with headquarters in Lindon, UT. DigiCert
provides digital certification and identity assurance services internationally
to a variety of sectors including business, education, and government.</summary>
    <audit type="WebTrust">
      <auditor url="http://kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=558&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>

    <certificate name="DigiCert Assured ID Root CA" status="included">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertAssuredIDRootCA.crt"
            version="3" 
            sha1="05:63:B8:63:0D:62:D7:5A:BB:C8:AB:1E:4B:DF:B5:A8:99:B2:4D:43" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>

    <certificate name="DigiCert Global Root CA" status="included">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertGlobalRootCA.crt"
            version="3" 
            sha1="A8:98:5D:3A:65:E5:E5:C4:B2:D7:D6:6D:40:C6:DD:2F:B1:9C:54:36" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertGlobalRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>

    <certificate name="DigiCert High Assurance EV Root CA" status="included">
      <summary></summary>
      <data url="http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt"
            version="3" 
            sha1="5F:B7:EE:06:33:E2:59:DB:AD:OC:4C:9A:E6:D3:8F:1A:61:C7:DC:25" 
            modulus="2048" 
            from="2006-11-10" 
            to="2031-11-10"/>
      <crl url="http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl">CRL</crl>
      <ocsp>http://ocsp.digicert.com</ocsp>
      <type>OV, EV</type>
      <document url="http://www.digicert.com/CPS_V3-0-3_3-15-2007.pdf">DigiCert 
      Certificate Policy and Certification Practice Statement (CP and CPS for OV), v3.0.3
      </document>
      <document url="http://www.digicert.com/EV_CPS_V-1-0-1_3-19-2007.pdf">DigiCert 
      Certification Practice Statement for Extended Validation Certificates (CPS for EV), v1.0.1
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=364568</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378162</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="QuoVadis" url="http://www.quovadis.bm/"              >
    <summary>QuoVadis is a commercial CA, based in Bermuda and operating globally. 
    QuoVadis is a Qualified Certification Services Provider in Switzerland.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst &amp; Young 
      (Technology and Security Risk Services)</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=612&amp;file=pdf">Audit Report 
      and Management's Assertions</document>
    </audit>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document url="http://www.seco.admin.ch/sas/00229/00251/00254/index.html?lang=en">Swiss Accreditation Service statement</document>
    </audit>

    <certificate name="QuoVadis Root CA 2" status="included">
      <summary>This root will be used for SSL/device certificates, including
      standard "organisation validated" certificates as well as EV certificates.</summary>
      <data url="http://www.quovadis.bm/public/qvrca2.crt"
            version="3" 
            sha1="CA:3A:FB:CF:12:40:36:4B:44:B2:16:20:88:80:48:39:19:93:7C:F7" 
            modulus="4096" 
            from="2006-11-24" 
            to="2031-11-24"
            ev-oid="1.3.6.1.4.1.8024.0.2.100.1.2"/>
      <crl url="http://crl.quovadisglobal.com/qvrca2.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV, EV</type>
      <document url="http://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.7.pdf">QuoVadis 
      Root CA2 CP/CPS v1.7</document>
      <document url="http://www.quovadis.bm/policies/QV_RCA2_CPCPS_v1.7.pdf">QuoVadis 
      Root CA2 CP/CPS v1.7</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=365281</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378161</technical>
      </inclusion>
    </certificate>
    
    <certificate name="QuoVadis Root CA 3" status="included">
      <summary>This root will operate under a similar CP/CPS to our existing "qualified" Root CA 1,
      primarily used for end user certificates.</summary>
      <data url="http://www.quovadis.bm/public/qvrca3.crt"
            version="3" 
            sha1="1F:49:14:F7:D8:74:95:1D:DD:AE:02:C0:BE:FD:3A:2D:82:75:51:85" 
            modulus="4096" 
            from="2006-11-24" 
            to="2031-11-24"/>
      <crl url="http://crl.quovadisglobal.com/qvrca3.crl">CRL</crl>
      <ocsp>http://ocsp.quovadisglobal.com/</ocsp>
      <type>OV</type>
      <document url="http://www.quovadis.bm/policies/QV_CPCPS_V4_3.pdf">QuoVadis Root CA CP/CPS 4.3</document>
      <document url="http://www.quovadis.bm/policies/QV_CPCPS_V4_3.pdf">QuoVadis Root CA CP/CPS 4.3</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=365281</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378161</technical>
      </inclusion>
    </certificate>    
  </authority>

  <authority name="GlobalSign" url="http://www.globalsign.com/"         >
    <summary>GlobalSign is a commercial CA based in Portsmouth NH and
      serving customers worldwide. 
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.dk">Deloitte (Denmark)</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=327&amp;file=pdf">Audit Report 
      and Management's Assertions</document>
    </audit>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/be/">Ernst &amp; Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=761&amp;file=pdf">Report of Independent Accountants and Assertion of Management</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/be">Ernst &amp; Young</auditor>
      <document url="http://www.globalsign.com/repository/webtrust_for_ev_ssl.pdf">Report of Independent Accountants and Assertion of Management</document>
    </audit>

    <certificate name="GlobalSign Root CA - R2" status="included">
      <summary>Root CA with one subordinate CA.</summary>
      <data url="https://secure.globalsign.net/cacert/root-r2.crt"
            version="3" 
            sha1="75:E0:AB:B6:13:85:12:27:1C:04:F8:5F:DD:DE:38:E4:B7:24:2E:FE" 
            modulus="2048" 
            from="2006-12-15" 
            to="2021-12-15"/>
      <crl url="http://crl.globalsign.net/root-r2.crl">CRL</crl>
      <ocsp>http://evssl-ocsp.globalsign.com/responder</ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.4146.1.1)</type>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v6.0.pdf">GlobalSign Certification Practice Statement, version 6.0</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CA_CP_v3.0.pdf">GlobalSign CA Certificate Policy, version 3.0</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CP_v_2_1.pdf">GlobalSign CP v2.1</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v_5_3.pdf">GlobalSign CPS v5.3</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=367245</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=378163</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=406796</ev>
      </inclusion>
    </certificate>
    <certificate name="GlobalSign Root CA" status="included">
      <summary>Root CA with two subordinate CAs.
      </summary>
      <data url="http://secure.globalsign.net/cacert/Root-R1.crt"
            version="3"
            sha1="B1:BC:96:8B:D4:F4:9D:62:2A:A8:9A:81:F2:15:01:52:A4:1D:82:9C"
            modulus="2048"
            from="1998-09-01"
            to="2028-01-28"/>
      <crl url="http://crl.globalsign.net/root.crl">CRL</crl>
      <ocsp>http://evssl-ocsp.globalsign.com/responder</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.4146.1.1)</type>
      <document url="http://www.globalsign.com/repository/GlobalSign_CPS_v6.0.pdf">GlobalSign Certification Practice Statement, version 6.0</document>
      <document url="http://www.globalsign.com/repository/GlobalSign_CA_CP_v3.0.pdf">GlobalSign CA Certificate Policy, version 3.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=406794</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=449883</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=446407</ev>
      </inclusion>
      <comments>Note that a version of this root CA certificate with
        the same public key but an earlier expiration date
        (2014-01-28) is already included in the Mozilla list. This
        request is to replace the older certificate with this
        certificate and then enable this CA certificate for EV.
      </comments>
    </certificate>
  </authority>
  
  <authority name="Keynectis/Certplus" url="http://www.keynectis.com/"  >
    <summary>Keynectis is a French company, created by merging 2 previous French
    certification operators, Certplus and PK7.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.lsti.fr/">LSTI - La Sécurité des Technologies de l'Information</auditor>
      <document url="http://www.keynectis.com/PC/Certificat_conformite_ETSI_101-456.pdf">ETSI Certificate</document>
    </audit>

    <certificate name="Certplus Class 2 Primary CA" status="included">
      <summary></summary>
      <data url="http://www.certplus.com/PC/certplus_class2.pem"
            version="3" 
            sha1="74:20:74:41:72:9C:DD:92:EC:79:31:D8:23:10:8D:C2:81:92:E2:BB" 
            modulus="2048" 
            from="1999-07-07" 
            to="2019-07-06"/>
      <crl url="http://www.certplus.com/CRL/class2.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>DV</type>
      <document url="http://www.keynectis.com/PC/DSQ_CP_SSL_RCA_CP_1%200.pdf">Root CA Certification Policy for SSL Services</document>
      <document url="http://www.keynectis.com/PC/CPS_KEYNECTIS_120407v1.1.pdf">Declaration des Pratiques de Certification (CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-05">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=335392</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=379032</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="StartCom" url="http://www.startssl.com/" status="included">
    <summary>
     StartCom is a commercial corporation with customers worldwide, and is 
     the producer and vendor of the StartCom Linux operating systems, operates 
     the StartCom Certification Authority and MediaHost. 
     </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366567">
      Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=366568">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="StartCom Certification Authority" status="included">
      <summary></summary>
      <data url="https://www.startssl.com/certs/ca.crt"
            version="3" 
            sha1="3E:2B:F7:F2:03:1B:96:F3:8C:E6:C4:D8:A8:5D:3E:2D:58:47:6A:0F" 
            modulus="4096" 
            from="2006-09-17" 
            to="2036-09-17"/>
      <crl url="http://cert.startcom.org/sfsca-crl.crl">CRL</crl>
      <ocsp>http://ocsp.startcom.org/sub/class2/server/ca</ocsp>
      <type>DV, OV, EV (policy OID 1.3.6.1.4.1.23223.2)</type>
      <document url="https://www.startssl.com/policy.pdf ">StartCom Certification Authority Policy and Practice Statements</document>
      <document url="https://www.startssl.com/extended.pdf">StartCom Certification Authority Extended Validation Certificates Policy Appendix</document>
      <document url="https://www.startssl.com/certs/">Index of Certs</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>  
      <inclusion date="2007-06-15">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=362304</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=383722</technical>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=490495</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=490492</ev>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TURKTRUST" url="http://www.turktrust.com.tr/" status="included">
    <summary>TÜRKTRUST is a Turkish CA issuing qualified certificates in Turkey.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tk.gov.tr/">Turkish Telecommunications Authority</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=264748">Letter of Official CA Statement</document>
      <document url="http://www.tk.gov.tr/eimza/eshs.htm">List of accredited CAs</document>
      <document url="http://www.tk.gov.tr/eimza/doc/aciklama/tt.doc">Audit statement on auditor website</document>
    </audit>

    <certificate name="TURKTRUST Certificate Services Provider Root 1" status="included">
      <summary>Root 1 is a "legacy" root included for compatibility
      with previously-issued certificates. The English version of the
      CPS applies to both roots.</summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/TURKTRUST_Elektronik_Sertifika_Hizmet_Saglayicisi.crt"
            version="3"
            sha1="79:98:A3:08:E1:4D:65:85:E6:C2:1E:15:3A:71:9F:BA:5A:D3:4A:D9"
            modulus="2048"
            from="2005-05-13"
            to="2015-03-22"/>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_KOK1NES.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_SSL_SIL_s1.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr/</ocsp>
      <type>DV, IV</type>

      <document url="http://www.turktrust.com.tr/pdf/cps_third.pdf">CPS v03 (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380635</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=410821</technical>
      </inclusion>
    </certificate>

    <certificate name="TURKTRUST Certificate Services Provider Root 2" status="included">
      <summary>Root 2 is the new root that replaced Root 1; Root 2 is
      used for certificates currently being issued. The English
      version of the CPS applies to both roots.</summary>
      <data url="http://www.turktrust.com.tr/sertifikalar/kok_s2.crt"
            version="3"
            sha1="B4:35:D4:E1:11:9D:1C:66:90:A7:49:EB:B3:94:BD:63:7B:A7:82:B7"
            modulus="2048"
            from="2005-07-11"
            to="2015-09-16"/>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Kok_SIL_s2.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_Nitelikli_SIL_s2.crl">CRL</crl>
      <crl url="http://www.turktrust.com.tr/sil/TURKTRUST_SSL_SIL_s2.crl">CRL</crl>
      <ocsp>http://ocsp.turktrust.com.tr/</ocsp>
      <type>DV, IV</type>

      <document url="http://www.turktrust.com.tr/pdf/cps_third.pdf">CPS v03 (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=380635</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=410821</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Comodo" url="http://www.comodo.com/" status="included">
    <summary>Comodo CA Ltd is a commercial CA based in the UK and
      serving customers worldwide. Comodo has a total of 12 root CA
      certs included in Mozilla, and altogether 124 subordinate CAs
      signed by those root CAs.  Some of them exist to differentiate
      between different Comodo brands or products and some are used to
      re-brand products for its partners. In each case Comodo retains
      the private key for the subordinate CA within its
      infrastructure.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=636&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.co.uk/">KPMG</auditor>
      <document url="http://www.comodo.com/repository/ev_audit_report_and_management_assertions.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation Criteria</document>
    </audit>

    <certificate name="COMODO Certification Authority" status="included">
      <summary>Root CA certificate with subordinate CAs issuing SSL
        certificates, email certificates, and code signing
        certificates.</summary>
      <data url="http://crt.comodoca.com/COMODOCertificationAuthority.crt"
            version="3"
            sha1="66:31:BF:9E:F7:4F:9E:B6:C9:D5:A6:0C:BA:6A:BE:D1:F7:BD:EF:7B"
            modulus="2048"
            from="2006-12-01"
            to="2029-12-31"/>
      <crl url="http://crl.comodoca.com/COMODOCertificationAuthority.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement, Version 3.0</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo Extended Validation (EV) Certification Practice Statement, Version 1.03</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=401587</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=426568</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=426572</ev>
      </inclusion>
      <comments></comments>
    </certificate>
    <certificate name="COMODO ECC Certification Authority" status="included">
      <summary>Root ECC certificate with internal subordinate CA issuing EV SSL
        certificates, email certificates, and code signing certificates.</summary>
      <data url="http://crt.comodoca.com/COMODOECCCertificationAuthority.crt"
            version="3"
            sha1="9F:74:4E:9F:2B:4D:BA:EC:0F:31:2C:50:B6:56:3B:8E:2D:93:C3:11"
            modulus="SECG elliptic curve secp384r1 (aka NIST P-384)"
            from="2008-03-06"
            to="2038-01-18"/>
      <crl url="http://crl.comodoca.com/COMODOECCCertificationAuthority.crl">CRL</crl>
      <ocsp>http://ocsp.comodoca.com/</ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.6449.1.2.1.5.1)</type>
      <document url="http://www.comodo.com/repository/09_22_2006_Certification_Practice_Statement_v.3.0.pdf">Comodo Certification Practice Statement</document>
      <document url="http://www.comodo.com/repository/EV_CPS_Amendment-ECC_Certificates.pdf">ECC Amendment to Comodo EV CPS</document>
      <document url="http://www.comodo.com/repository/EV_CPS_4_JUN_07.pdf">Comodo EV Certification Practice Statement</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=421946</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=450427</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=450429</ev>
      </inclusion>
      <comments>This is a new EV request.</comments>
    </certificate>
  </authority>

  <authority name="VeriSign" url="http://www.verisign.com/" status="included">
    <summary>VeriSign is a major commercial CA with worldwide
    operations and customer base.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=304&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://bugzilla.mozilla.org/attachment.cgi?id=287877">CA-supplied
      auditor's letter re WebTrust EV audit</document>
    </audit>

    <certificate name="VeriSign Class 3 Public Primary Certification Authority - G5" status="included">
      <summary>This CA issues a CA certificate to the subordinate CA
        "VeriSign Class 3 Extended Validation SSL SGC CA", which in
        turn issues Extended Validation certificates for SSL-enabled
        servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=304810"
            version="3"
            sha1="4E:B6:D5:78:49:9B:1C:CF:5F:58:1E:AD:56:BE:3D:9B:67:44:A5:E5"
            modulus="2048"
            from="2006-11-07"
            to="2036-07-16"/>
      <crl url="http://evintl-crl.verisign.com/EVIntl2006.crl">CRL</crl>
      <ocsp>http://evintl-ocsp.verisign.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.23.6)</type>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPSv3.5.pdf">VeriSign
      Certification Practice Statement, Version 3.5</document>
      <document
      url="http://www.verisign.com/repository/CPS/VeriSignCPv2.5.pdf">VeriSign
      Trust Network Certificate Policies, Version 2.5</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=402947</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=422918</technical>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=422921</technical>
      </inclusion>
      <comments>Note that for compatibility reasons VeriSign has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter VeriSign EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing VeriSign Class 3 Public Primary CA
        root.</comments>
    </certificate>

  </authority>

  <authority name="Trustwave" url="http://www.trustwave.com/" status="included">
    <summary>Trustwave is a commercial CA serving customers worldwide;
      it includes the former SecureTrust and XRamp CAs. At this time
      there are no subordinate CAs for any of these roots; instead end
      entity certificates are issued directly from the roots as noted
      below, with different classes of certificates under different
      certificate policies.  Note that each root CA is not associated
      with a single CPS, rather end entity certs are associated with
      policies that link to the CPS that the certificate was issued
      under: an EV CPS, an OV CPS, etc.
    </summary>
    <audit type="WebTrust and WebTrust EV">
      <auditor url="">Boysen &amp; Miller PLLC</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=359&amp;file=pdf">Audit Report
      and Management's Assertions</document>
    </audit>

    <certificate name="SecureTrust CA" status="included">
      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV) and code signing certificates.
      </summary>
      <data url="https://www.securetrust.com/legal/STCA.txt"
            version="3"
            sha1="87:82:C6:C3:04:35:3B:CF:D2:96:92:D2:59:3E:7D:44:D9:34:FF:11"
            modulus="2048"
            from="2006-11-07"
            to="2029-12-31"/>
      <crl url="http://crl.securetrust.com/STCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409837</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418907</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=418910</ev>
      </inclusion>
    </certificate>

    <certificate name="Secure Global CA" status="included">
      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV), S/MIME certificates, and (in future)
        code signing certificates.
      </summary>
      <data url="https://www.securetrust.com/legal/SGCA.txt"
            version="3"
            sha1="3A:44:73:5A:E5:81:90:1F:24:86:61:46:1E:3B:9C:C4:5F:F5:3A:1B"
            modulus="2048"
            from="2006-11-07"
            to="2029-12-31"/>
      <crl url="http://crl.securetrust.com/SGCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_SMIME_CPS_1_6_0.pdf">SecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409838</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418907</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=418910</ev>
      </inclusion>
    </certificate>

    <certificate name="XRamp Global CA" status="included">

      <summary>Root CA certificate utilized for issuing SSL
        certificates (OV and EV), S/MIME certificates, and code
        signing certificates.
      </summary>
      <data url="http://www.securetrust.com/legal/XGCA.txt"
            version="3"
            sha1="B8:01:86:D1:EB:9C:86:A5:41:04:CF:30:54:F3:4C:52:B7:E5:58:C6"
            modulus="2048"
            from="2004-11-01"
            to="2035-01-01"/>
      <crl url="http://crl.xrampsecurity.com/XGCA.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV/OV, EV (policy OID 2.16.840.1.114404.1.1.2.4.1)</type>
      <document url="https://www.securetrust.com/legal/evCPS.pdf">SecureTrust Corporation Certificate Practice Statement for Extended Validation Certificates, Version 1.0.1</document>
      <document url="https://www.securetrust.com/legal/securetrust%20cps%20for%20ov.pdf">SecureTrust Corporation Certificate Practice Statement for Organizationally Validated Standard Assurance Certificates, Version 1.5.1</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_SMIME_CPS_1_6_0.pdf">SecureTrust Certification Practice Statement for S/MIME Certificates, Version 1.6.0</document>
      <document url="https://www.securetrust.com/legal/SecureTrust_Code_Signing_CPS.pdf">SecureTrust Certification Practice Statement for Code Signing Certificates, Version 1.6.0</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=409840</authorisation>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=418902</ev>
      </inclusion>
      <comments>Note that this root CA certificate is already included
      in the Mozilla list. The present request is to enable this CA
      certificate for EV.</comments>
    </certificate>
  </authority>

  <authority name="DigiNotar" url="http://www.diginotar.nl/" status="included">
    <summary>DigiNotar is a Dutch trusted third party, mainly
      operating in the Netherlands.  They issue certificates based on
      notary verification of applicants. They service the business,
      government and consumer markets.</summary>
    <audit type="ETSI 101.456">
      <auditor url="http://www.pwc.nl/">Price Waterhouse Coopers</auditor>
      <document url="http://www.diginotar.nl/Portals/7/ETSI/Certificate.pdf">ETSI Certificate</document>
      <document url="http://www.ecp.nl/download/Reg._Cert._op_basis_van_TTP.NL,_3dec08.pdf?PHPSESSID=f23ec42c909cc2bf1107372430d46d08">Statement of ETSI Compliance</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.pwc.nl/">Price Waterhouse Coopers</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=357961">Assertion of Management and Audit Report</document>
    </audit>
    <certificate name="DigiNotar Root CA" status="included">
      <summary>This is the top root, used only to issue CA
        certificates for five application-specific subordinate CAs:
        DigiNotar Public CA 2025 (non-qualified personal
        certificates), DigiNotar Qualified CA (qualified personal
        certificates), DigiNotar Services CA (SSL and object signing
        certificates), DigiNotar Extended Validation CA (EV
        certificates), and DigiNotar Private CA (CA certificates for
        organizational CAs).</summary>
        <data url="http://www.diginotar.nl/files/Rootcertificaten/DigiNotar%20root%20CA2007.crt"
        version="3"
        sha1="C0:60:ED:44:CB:D8:81:BD:0E:F8:6C:0B:A2:87:DD:CF:81:67:47:8C"
        modulus="4096" from="2007-05-16" to="2025-03-31"/>
      <crl url="http://service.diginotar.nl/crl/root/latestCRL.crl">CRL</crl>
      <ocsp>http://validation.diginotar.nl</ocsp>
      <type>OV, EV (policy OID 2.16.528.1.1001.1.1.1.12.6.1.1.1)</type>
      <document url="http://www.diginotar.com/Portals/0/General%20terms/DigiNotar_CPS_3.5_-_EN.pdf">CPS DigiNotar 30 October 2007, Version 3.5</document>
      <document url="https://www.diginotar.nl/Klantenservice/Rootcertificaten/tabid/308/Default.aspx">Overview of DigiNotar Root Certificates</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=369357</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=431621</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=493265</ev>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="GeoTrust" url="http://www.geotrust.com/" status="included">
    <summary>GeoTrust is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust/WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=650&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="GeoTrust Primary Certification Authority" status="included">
      <summary>This CA issues a CA certificate to the subordinate CA
        GeoTrust Extended Validation SSL CA, which in turn issues
        Extended Validation certificates for SSL-enabled
        servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=306731"
            version="3"
            sha1="32:3C:11:8E:1B:F7:B8:B6:52:54:E2:E2:10:0D:D6:02:90:37:F0:96"
            modulus="2048"
            from="2006-11-26"
            to="2036-07-16"/>
      <crl url="http://EVSSL-crl.geotrust.com/crls/gtextvalca.crl">CRL</crl>
      <ocsp>http://EVSSL-ocsp.geotrust.com/</ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.14370.1.6)</type>
      <document url="http://www.geotrust.com/resources/cps/pdfs/GeoTrustCPS-Version1.pdf">GeoTrust Certification Practice Statement, Version 1.0 (January 31, 2008)</document>
      <document url="http://www.geotrust.com/resources/repository/legal.asp">Other documents</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=407168</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=424169</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=424171</ev>
      </inclusion>
      <comments>Note that for compatibility reasons GeoTrust has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter GeoTrust EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing Equifax Secure CA root.</comments>
    </certificate>
  </authority>

  <authority name="Go Daddy" url="http://www.godaddy.com/" status="included">
    <summary>Go Daddy operates a commercial CA based in the US and
      serving customers worldwide.
    </summary>
    <audit type="WebTrust and WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=355&amp;file=pdf">Independent Accountants' Report</document>
    </audit>

    <certificate name="Valicert Class 2 Policy Validation Authority" status="included">
      <summary>Root  CA  certificate  with  a  single  subordinate  CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.starfieldtech.com/repository/valicert_class2_root.crt"
            version="1"
            sha1="31:7A:2A:D0:7F:2B:33:5E:F5:A1:C3:4E:4B:57:E8:B7:D8:F1:FC:A6"
            modulus="1024"
            from="1999-06-25"
            to="2019-06-25"/>
      <crl url="https://certificates.starfieldtech.com/repository/root.crl">CRL</crl>
      <ocsp>http://ocsp.startfieldtech.com/</ocsp>
      <type>DV, IV/OV, EV (policy OIDs 2.16.840.1.114413.1.7.23.3 and 2.16.840.1.114414.1.7.23.3)</type>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</ev>
      </inclusion>
      <comments>Both of the CA certificates below are cross-signed to
        the Valicert Class 2 Policy Validation Authority root for
        legacy support, so this root is configured to enable EV with
        both of the EV OIDs associated with the other certificates.
      </comments>
    </certificate>

    <certificate name="Go Daddy Class 2 CA" status="included">
      <summary>Root CA certificate  with  a  single  subordinate  CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.godaddy.com/repository/gd-class2-root.crt"
            version="3"
            sha1="27:96:BA:E6:3F:18:01:E2:77:26:1B:A0:D7:77:70:02:8F:20:EE:E4"
            modulus="2048"
            from="2004-06-29"
            to="2034-06-29"/>
      <crl url="https://certificates.godaddy.com/repository/gdroot.crl">CRL</crl>
      <ocsp>http://ocsp.godaddy.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 2.16.840.1.114413.1.7.23.3)</type>
      <document url="https://certs.godaddy.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</ev>
      </inclusion>
      <comments></comments>
    </certificate>

    <certificate name="Starfield Class 2 CA" status="included">
      <summary>Root CA certificate with a single subordinate CA
        issuing SSL certificates (DV, OV and EV), email certificates,
        and code signing certificates.</summary>
      <data url="https://certs.starfieldtech.com/repository/sf-class2-root.crt"
            version="3"
            sha1="AD:7E:1C:28:B0:64:EF:8F:60:03:40:20:14:C3:D0:E3:37:0E:B5:8A"
            modulus="2048"
            from="2004-06-29"
            to="2034-06-29"/>
      <crl url="https://certificates.starfieldtech.com/repository/sfroot.crl">CRL</crl>
      <ocsp>http://ocsp.starfieldtech.com/</ocsp>
      <type>DV, IV/OV, EV (policy OID 2.16.840.1.114414.1.7.23.3)</type>
      <document url="https://certs.starfieldtech.com/repository/StarfieldCP-CPS.pdf">Starfield Technologies, Inc. Certificate Policy and Certification Practice Statement (CP/CPS)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=418958</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=403437</ev>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Network Solutions" url="http://www.networksolutions.com/" status="included">
    <summary>Network Solutions is a US-based commercial CA with
      worldwide customer base.</summary>
    <audit type="WebTrust for CAs">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=705&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://www.networksolutions.com/SSL-certificates/kpmg-ev.pdf">Report in relation to the WebTrust for Certification Authorities Extended Validation 
Criteria</document>
    </audit>
    <certificate name="Network Solutions Certificate Authority" status="included">
      <summary>This CA has a subordinate CA, Network Solutions EV SSL
        CA, which issues Extended Validation certificates for
        SSL-enabled servers. At present there are no other subordinate
        CAs under this root; however in the future Network Solutions
        may establish additional subordinate CAs to issue non-EV
        certificates..</summary>
      <data url="ftp://ftp.networksolutions.com/certs/netsolevroot.crt"
            version="3"
            sha1="74:F8:A3:C3:EF:E7:B3:90:06:4B:83:90:3C:21:64:60:20:E5:DF:CE"
            modulus="2048"
            from="2006-12-01"
            to="2029-12-31"/>
      <crl url="http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl">CRL</crl>
      <ocsp></ocsp>
      <type>IV/OV, EV (policy OID 1.3.6.1.4.1.782.1.2.1.8.1)</type>
      <document url="http://www.networksolutions.com/legal/SSL-legal-repository-cps.jsp">Network Solutions Certification Practice Statement, Version 1.4.1</document>
      <document url="https://www.networksolutions.com/legal/SSL-legal-repository-ev-cps.jsp">Certification Practice Statement (CPS) for Extended Validation (EV) Certification, Version 1.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=403915</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=431381</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=431384</ev>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="thawte" url="http://www.thawte.com/" status="included">
    <summary>thawte is a commercial CA with worldwide operations and
      customer base; it is a subsidiary of VeriSign, Inc.</summary>
    <audit type="WebTrust/WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document
      url="https://cert.webtrust.org/SealFile?seal=527&amp;file=pdf">Audit
      Report and Management's Assertions</document>
    </audit>
    <certificate name="thawte Primary Root CA" status="included">
      <summary>This CA issues a CA certificate to the subordinate CAs
        thawte Extended Validation SSL CA and thawte Extended
        Validation SSL SGC CA, which in turn issue Extended Validation
        certificates for SSL-enabled servers.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=306736"
            version="3"
            sha1="91:C6:D6:EE:3E:8A:C8:63:84:E5:48:C2:99:29:5C:75:6C:81:7B:81"
            modulus="2048"
            from="2006-11-17"
            to="2036-07-16"/>
      <crl url="http://crl.thawte.com/ThawteEVCA2006.crl">CRL</crl>
      <ocsp>http://ocsp.thawte.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.113733.1.7.48.1)</type>
      <document url="http://www.thawte.com/guides/pdf/Thawte_CPS_3_5.pdf">thawte Certification Practice Statement, Version 3.5 (January 2008)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=407163</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=424152</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=424154</ev>
      </inclusion>
      <comments>Note that for compatibility reasons thawte has
        implemented a cross-signing scheme involving this CA.  In this
        scheme, if applications not supporting EV functionality (e.g.,
        Firefox 2 and earlier) encounter thawte EV certificates then
        they will end up treating this CA as a subordinate CA under
        the existing Thawte Premium Server CA root.</comments>
    </certificate>
  </authority>

  <authority name="Entrust" url="http://www.entrust.net/" status="included">
    <summary>Entrust is a commercial CA serving the global market for
      SSL web certificates. Entrust also issues certificates to
      subordinate CAs for enterprise and commercial use.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.ca/">Deloitte and Touche LLP</auditor>
      <document url="https://entrust.webtrust.org/SealFile?seal=328&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.deloitte.ca/">Deloitte and Touche LLP</auditor>
      <document url="http://www.entrust.net/ssl-resources/pdf/webtrust-ev.pdf">
Audit Report and Management's Assertions</document>
    </audit>

    <certificate name="Entrust Root Certification Authority" status="included">
      <summary>This root was primarily created as the trust root for Entrust EV SSL
        certificates. EV certificates are issued using the
        Entrust Certification Authority - L1A subordinate CA.</summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=267983"
            version="3"
            sha1="B3:1E:B1:B7:40:E3:6C:84:02:DA:DC:37:D4:4D:F5:D4:67:49:52:F9"
            modulus="2048"
            from="2006-11-27"
            to="2026-11-27"/>
      <crl url="http://crl.entrust.net/rootca1.crl">CRL</crl>
      <ocsp>http://ocsp.entrust.net</ocsp>
      <type>OV, EV (policy OID 2.16.840.1.114028.10.1.2)</type>
      <document url="http://www.entrust.net/CPS/pdf/webcps051404.pdf">Entrust SSL Web Server Certification Practice Statement, Version 2.06</document>
      <document url="http://www.entrust.net/CPS/pdf/evssl_cps_english080107.pdf">Entrust Certificate Services Certification Practice Statement for Extended Validation (EV) SSL Certificates, Version 1.01</document>
      <document url="http://www.entrust.net/ev/business_practice.htm">Entrust Extended Validation Business Practices</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=382352</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=387892</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=416544</ev>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="SwissSign" url="http://www.swisssign.com/" status="included">
    <summary>SwissSign AG is a commercial CSP that provides certification services for
    individual and corporate customers. SwissSign operates the certificate authority
    for the Swiss Post and is mostly focused on Switzerland but Registration Services
    may be used internationally.
    The "Platinum G2" Root CA currently has 3 subordinate CAs,
    the "Gold G2" Root CA has 2 and the "Silver G2" Root CA has 3.
</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document url="http://www.seco.admin.ch/sas/00229/00251/index.html?lang=en">Swiss Accreditation Service Certified Bodies List</document>
      <document url="http://www.seco.admin.ch/sas/00229/00251/00281/index.html?lang=en">SAS details for SwissSign</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.ch/">KPMG</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=346440">Confirmation Notice of WebTrust EV Audit</document>
    </audit>
    <certificate name="SwissSign Platinum CA - G2" status="included">
      <summary>The SwissSign Platinum CA - G2 root has three
subordinate CAs. The SwissSign Qualified Platinum CA - G2 issues
"qualified" certificates according to Swiss digital signature law
(ZertES). The SwissSign Personal Platinum CA - G2 issues certificates
for natural persons and organizations. The Swiss Post Platinum CA - G2
issues the "Postzertifikat", a product of the Swiss Post. (Note that
each of the subordinate CAs has its own CP/CPS separate from the
CP/CPS of the root.) The Platinum CAs require that keys be generated
on Secure Signature Creation Devices (SSCDs); since such devices are
not used with servers, this hierarchy is enabled for email and object
signing uses only.</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=50AFCC078715476F38C5B465D1DE95AAE9DF9CCC&amp;into=browser"
            version="3"
            sha1="56:E0:FA:C0:3B:8F:18:23:55:18:E5:D3:11:CA:E8:C2:43:31:AB:66"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/34C58C2353ADD6DEE70092B06BFA269451CA07E4">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/34C58C2353ADD6DEE70092B06BFA269451CA07E4</ocsp>
      <type>IV</type>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Root-CP-CPS-R1.pdf">SwissSign Platinum Root CP/CPS</document>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Qualified-CP-CPS-R1.pdf">SwissSign Qualified Platinum CP/CPS</document>
      <document url="http://repository.swisssign.com/SwissSign-Platinum-Personal-CP-CPS-R1.pdf">SwissSign Personal Platinum CP/CPS</document>
      <document url="http://repository.swisssign.com/Swiss-Post-Platinum-CP-CPS-R1.pdf">Swiss Post Platinum CP/CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
      </inclusion>
    </certificate>

    <certificate name="SwissSign Gold CA - G2" status="included">
      <summary>The "Gold G2" root CA currently has two subordinate
CAs: "Personal" issues certificates for natural persons and
organizations, while "Server" issues certificates for systems.  This
root CA may also operate other customer-specific Issuing CAs if and
only if they fully comply with all the stipulations of the "Gold G2"
CP/CPS.</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=5B257B96A465517EB839F3C078665EE83AE7F0EE&amp;into=browser"
            version="3"
            sha1="D8:C5:38:8A:B7:30:1B:1B:6E:D4:7A:E6:45:25:3A:6F:9F:1A:27:61"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/0E414F33ED1FEE8DAF6A1916B706D286B253008A">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/0E414F33ED1FEE8DAF6A1916B706D286B253008A</ocsp>
      <type>IV, OV, EV (policy OID 2.16.756.1.89.1.2.1.1)</type>
      <document url="http://repository.swisssign.com/SwissSign-Gold-CP-CPS-R4.pdf">SwissSign Gold CP/CPS R4</document>
      <document url="http://repository.swisssign.com/SwissSign-Gold-EUA-R4.pdf">End User Agreement R4</document>
      <document url="http://repository.swisssign.com/">SwissSign Document Repository</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=492077</ev>
      </inclusion>
    </certificate>
    <certificate name="SwissSign Silver CA - G2" status="included">
      <summary>The "Silver G2" root CA currently has three subordinate
CAs: "Personal" issues certificates for natural persons and
organizations, "Server" issues certificates for systems, and "Switch"
is operated for a customer that issues certificates for the academic
community</summary>
      <data url="https://swisssign.net/cgi-bin/authority/download?ca=17A0CDC1E441B63A5B3BCB459DBD1CC298FA8658&amp;into=browser"
            version="3"
            sha1="9B:AA:E5:9F:56:EE:21:CB:43:5A:BE:25:93:DF:A7:F0:40:D1:1D:CB"
            modulus="4096"
            from="2006-10-25"
            to="2036-10-25"/>
      <crl url="http://crl.swisssign.net/A5045DFC48B74304F31B3B90ACB036034D6AC84F">CRL</crl>
      <ocsp>http://ocsp.swisssign.net/A5045DFC48B74304F31B3B90ACB036034D6AC84F</ocsp>
      <type>IV</type>
      <document url="http://repository.swisssign.com/SwissSign-Silver-CP-CPS-R2.pdf">SwissSign Silver CP/CPS</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=343756</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=407396</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="IdenTrust" url="http://www.identrust.com/"  status="included">
    <summary>IdenTrust is a for-profit corporation serving the private, commercial and government sectors.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.ey.com/">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=574&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>

    <certificate name="DST Root CA X3" status="included">
      <summary></summary>
      <data url="http://apps.identrust.com/roots/DSTROOTCAX3.cer"
            version="3"
            sha1="DA:C9:02:4F:54:D8:F6:DF:94:93:5F:B1:73:26:38:CA:6A:D7:7C:13"
            modulus="2048"
            from="2000-09-30"
            to="2021-09-30"/>
      <crl url="http://crl.identrust.com/DSTROOTCAX3.crl">CRL</crl>
      <ocsp>http://ocsp.digsigtrust.com</ocsp>
      <type>DV</type>
      <document url="https://secure.identrust.com/certificates/policy/ts/TrustID_CP_v1.3.1_20060127.pdf">TrustID CP v1.3.1</document>
      <document url="https://secure.identrust.com/certificates/policy/ts/identrust_trustid_cps_v2.2_20070514.pdf">IdenTrust CPS v2.2</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=359069</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=394733</technical>
      </inclusion>
    </certificate>

    <certificate name="DST ACES CA X6" status="included">
      <summary></summary>
      <data url="https://bugzilla.mozilla.org/attachment.cgi?id=277051"
            version="3"
            sha1="40:54:DA:6F:1C:3F:40:74:AC:ED:0F:EC:CD:DB:79:D1:53:FB:90:1D"
            modulus="2048"
            from="2003-11-20"
            to="2017-11-20"/>
      <crl url="http://crl.trustdst.com/DSTACESX6.crl">CRL</crl>
      <ocsp>https://ocspaces.trustdst.com</ocsp>
      <type>DV</type>
      <document url="https://secure.identrust.com/certificates/policy/aces/revised_aces_cp_v20040506_1.pdf">Certificate Policy v20040506_1</document>
      <document url="https://secure.identrust.com/certificates/policy/aces/dst-aces-cps-v20040617.pdf">Certificate Practice Statement v4.1</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=359069</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=394733</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="DCSSI" url="http://www.ssi.gouv.fr/en/dcssi/index.html" status="included">
    <summary>DCSSI is part of the French Government. It issues certificates to French
    Government websites which are used by the general public. Each department has a sub CA; there
    are at least 20 at the moment, and potentially up to 60.</summary>
    <audit type="Government -- WebTrust CA Equivalent">
      <auditor url="http://www.ssi.gouv.fr/fr/RGS/index.html">French Secretariat Général de la Défense Nationale</auditor>
      <document url="http://www.ssi.gouv.fr/fr/sigelec/igca/igca-homologation.pdf">Official decision for IGC/A homologation</document>
    </audit>
    <certificate name="IGC/A" status="included">
      <summary>
       This is the root certificate of the French Government CA. The IGC/A root issues a 
       subordinate CA for each organization, which can be only a government or an 
       administrative organization. Each of these subordinate CAs may issue end-entity 
       certificates or additional subordinate CAs to be used for divisions within that 
       organization. Each organization is required to follow the CP and the Government 
       RGS/PRIS, and be audited.
      </summary>
      <data url="http://www.ssi.gouv.fr/fr/sigelec/igca/cert_igca_rsa.crt"
            version="3"
            sha1="60:D6:89:74:B5:C2:65:9E:8A:0F:C1:88:7C:88:D2:46:69:1B:18:2C"
            modulus="2048"
            from="2002-12-13"
            to="2020-10-17"/>
      <crl url="http://www.ssi.gouv.fr/fr/sigelec/igca/revocation/igca.crl">CRL</crl>
      <ocsp></ocsp>
      <type>OV</type>
      <document url="http://www.ssi.gouv.fr/fr/sigelec/igca/">Policies and other useful information specific to this root</document>
      <document url="http://www.ssi.gouv.fr/fr/sigelec/igca/igca-pc-v2.pdf">Certificate Policy</document>
      <document url="http://www.ssi.gouv.fr/fr/RGS/index.html">Repository General Security (RGS)  Website</document>
      <document url="http://www.synergies-publiques.fr/article.php?id_article=945">Politique de Référencement Intersectorielle de Sécurité (PRIS)</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/061129_PRIS_US_ENISA.pdf">Summary of PRIS</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS_Variables_de_temps_V2.1.pdf">Variables de temps (for CRL frequency update)</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS_Service_Authentification_Serveur_V2.2.pdf">PC-Type authentification servers (for SSL)</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS_PC-Type_Authentification_V2.2.pdf">PC-Type authentification </document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS_Profils_Certificat_LCR_OCSP_V2_2.pdf">Profiles de certificats, LCR et OCSP</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS__PC-Type_Cachet_Serveur_V2.2.pdf">PC-Type cachet server</document>
      <document url="http://www.synergies-publiques.fr/IMG/pdf/RGS_PC-Type_Signature_V2.2.pdf">PC-type signature</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=368970</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=477147</technical>
      </inclusion>
      <comments></comments>
    </certificate>
  </authority>

  <authority name="Microsec" url="http://www.e-szigno.hu/" status="included">
    <summary>Microsec Ltd. is a Hungarian certificate authority.</summary>
    <audit type="Government">
      <auditor url="http://www.nhh.hu/">Hungarian Government National Communications Authority</auditor>
      <document url="http://www.e-szigno.hu/docs/NhhSupervision2008.pdf">Authority statement</document>
    </audit>

    <certificate name="Microsec e-Szigno Root CA" status="included">
      <summary></summary>
      <data url="http://www.e-szigno.hu/RootCA.crt"
            version="3"
            sha1="23:88:C9:D3:71:CC:9E:96:3D:FF:7D:3C:A7:CE:fC:D6:25:EC:19:0D"
            modulus="2048"
            from="2005-04-06"
            to="2017-04-06"/>
      <crl url="http://www.e-szigno.hu/RootCA.crl">CRL for this root</crl>
      <crl url="http://srv.e-szigno.hu/menu/index.php?lap=english_crl">List of CRLs</crl>
      <ocsp><!-- none that is public --></ocsp>
      <type>OV</type>
      <document url="http://srv.e-szigno.hu/menu/index.php?lap=english_ca_hierarchy">Certificate 
      Hierarchy in English</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--altalanos--v1.6--EN.doc">CPS in English</document>

      <document url="http://www.e-szigno.hu/docs/szsz--hsz--minositett--v4.1.pdf">Qualified
      Certificate CPS</document>
      <document url="http://www.e-szigno.hu/docs/hitelesitesiRend--v3.1.pdf">ETSI TS
      101.456, QCP public CP</document>
      <document url="http://www.e-szigno.hu/docs/mhr_v14_e.pdf">ETSI TS
      101.456, SSCD CP</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--fokozott--v1.1.pdf">Non-qualified
      Certificates CPS (electronic signatures)</document>
      <document url="http://www.e-szigno.hu/docs/ehr+_v14_e.pdf">ETSI TS 102.042, NCP+ CP</document>
      <document url="http://www.e-szigno.hu/docs/ehr_v14_e.pdf">ETSI TS 102.042, NCP CP</document>
      <document url="http://www.e-szigno.hu/docs/hrf--v1.2.pdf">ETSI TS 102.042, NCP
      and ETSI TS 102.042, LCP CP</document>
      <document url="http://www.e-szigno.hu/docs/szsz--hsz--altalanos--v1.0.pdf">Non-qualified
      Certificates CPS (other uses)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370505</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=483852</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="S-TRUST" url="https://www.s-trust.de/" status="complete">
    <summary>Deutscher Sparkassen Verlag GmbH is the world's largest
      smartcard provider and the central certification service
      provider for all German savings banks. This CA exists to enable
      up to 40 million German customers (end-users) to use their
      banking card as a certificate based signature, encryption and
      authentication device.</summary>
    <audit type="ETSI TS 101.456">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6701UE.pdf">
      ETSI TS 101.456 Certificate</document>
    </audit>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6702UE.pdf">
      ETSI TS 102.042 Certificate</document>
    </audit>

    <certificate name="S-TRUST Authentication and Encryption Root CA 2005:PN" status="approved">
      <summary>This root will provide all customers of the German
        Savings Bank Financial Group with client certificates for
        their signature-enabled debit cards (smartcards).</summary>
      <data url="http://www.s-trust.de/service_support/zertifikatsmanagement/verzeichnisdienste/download_wurzelzertifikate/ordner_crt_dateien/authentication.crt"
            version="3"
            sha1="BE:B5:A9:95:74:6B:9E:DF:73:8B:56:E6:DF:43:7A:77:BE:10:6B:81"
            modulus="2048"
            from="2005-06-21"
            to="2030-06-21"/>
      <crl url="http://onsitecrl.s-trust.de/DeutscherSparkassenVerlagGmbHSTRUSTQualifiedRootCA2005001PN/LatestCRL.crl">CRL</crl>
      <ocsp>http://ocsp-q.s-trust.de</ocsp>
      <type>IV</type>
      <document url="http://www.s-trust.de/stn-cps/stn_cps.pdf">Certification Practice Statement for the S-TRUST Network</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=370627</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=478573</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="WISeKey" url="http://www.wisekey.com/" status="included">
    <summary>WISeKey operates the CertifyID Trust Service, which
      supports customer-specific CAs under a CA hierarchy rooted at
      the WISeKey Global Root GA CA and containing Policy CAs
      (subordinate to the root) and Issuing CAs (subordinate to the
      Policy CAs). Note that all end-entity certificates are issued by
      the Issuing CAs under policies set by WISeKey.
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.webtrust.es/">WTE y E. Álvarez Auditores, S.L.</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=643&amp;file=pdf">Audit Report
      and Management's Assertions</document>
    </audit>
    <audit type="WebTrust">
      <auditor url="http://www.webtrust.es/">WTE y E. Álvarez Auditores, S.L.</auditor>
      <document url="http://www.wisekey.com/documents/pkiRepository/WebTrustReport2008.pdf">2008 Audit Report and Management's Assertions</document>
    </audit>

    <certificate name="OISTE WISeKey Global Root GA CA" status="included">

      <summary>As noted above, the Global Root GA CA is the one and
        only root for the entire CertifyID system. It issues CA
        certificates to Policy CAs, which in turn issue CA
        certificates to Issuing CAs. There are three types of Policy
        CAs (Standard, Advanced, and Qualified) and three types of
        Issuing CAs corresponding to these, each issuing a different
        class of certificates; verification requirements for
        applicants vary by class.
      </summary>
      <data url="http://public.wisekey.com/crt/owgrgaca.crt"
            version="3"
            sha1="59:22:A1:E1:5A:EA:16:35:21:F8:98:39:6A:46:46:B0:44:1B:0F:A9"
            modulus="2048"
            from="2005-12-11"
            to="2037-12-11"/>
      <crl url="http://public.wisekey.com/crl/owgrgaca.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>IV</type>

      <document url="http://www.wisekey.com/documents/pkiRepository/OISTEWISEKEYROOTCPS101Jan162007.pdf">OISTE WISeKey Root CPS 1.01</document>
      <document url="http://www.wisekey.com/documents/pkiRepository/CertifyIDValidationVerificationOverview.pdf">CertifyID Identity Validation Overview, Version 1.0</document>
      <document url="http://www.wisekey.com/documents/pkiRepository/WD0011TECHNICALSECURITYCONTROLS.pdf">Technical Security Controls WD0011 - Version 1.0.1</document>
      <document url="http://www.wisekey.com/documents/pkiRepository/cidclassed.pdf">Table comparing the three different classes of end-entity certificates issued by Issuing CAs.</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=371362</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=467138</technical>
      </inclusion>
    </certificate>

    <comments>Note that the CPS for the root CA addresses only
      procedures related to issuance of certificates for its
      subordinate CAs. Issues related to issuance of end entity
      certificates are addressed in the other two documents
      references, in particular the CPS for the Advanced Services
      Issuing CA.</comments>
  </authority>

  <authority name="T-Systems" url="http://pki.telesec.de/service/certificates/" status="included">
    <summary>T-Systems is a wholly-owned subsidiary of Deutsche Telekom AG.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.de.ey.com/">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=853&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <audit type="ETSI 101.456">
      <auditor url="http://www.t-systems-zert.com/">T-Systems GEI</auditor>
      <document url="http://www.t-systems-zert.com/pdf/ein_03_sig_zda/zf_03a180_e.pdf">ETSI 101.456 Certificate of Compliance</document>
    </audit>

    <certificate name="Deutsche Telekom Root CA 2" status="included">
      <summary></summary>
      <data url="http://wwwca.telesec.de/cgi-bin/caservice/Common/InstallRoot/DT-Root-CA-2.cer"
            version="3"
            sha1="85:A4:08:C0:9C:19:3E:5D:51:58:7D:CD:D6:13:30:FD:8C:DE:37:BF"
            modulus="2048"
            from="1999-07-09"
            to="2019-07-10"/>
      <crl url="http://pki.telesec.de/cgi-bin/service/af_DownloadARL.crl?-crl_format=X_509?-issuer=DT_ROOT_CA_2">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>OV</type>
      <document url="http://pki.telesec.de/service/DT_ROOT_CA_2/cps.pdf">CPS (German)</document>
      <document url="http://pki.telesec.de/service/DT_ROOT_CA_2/cp.pdf">CP (German)</document>
      <document url="https://www.telesec.de/pki/service/DT_ROOT_CA_2/Leistungsbeschreibung_T-Systems-Root-Signing-V1.3.pdf">Service Description (German)</document>
      <document url="http://pki.telesec.de/service/documents/T-Systems-CPS-CA-2-English-v11.pdf">CPS (English)</document>
      <document url="http://pki.telesec.de/service/documents/T-Systems-Root-CP_V1.5_en.pdf"> CP (English)</document> 
      <document url="http://pki.telesec.de/service/documents/service-spec_T-Systems-Root-Signing_V1.3_en.pdf">Service Description (English)</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=378882</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=487647</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="TC TrustCenter" url="http://www.trustcenter.de/"     
             status="included">
    <summary>
    TC TrustCenter GmbH  is a commercial company based in Germany, 
    with customers in all major regions of the world. TC TrustCenter 
    offers a variety of products and services including SSL Server 
    certificates and Email certificates.
    </summary>
    <audit type="ETSI 102.042">
      <auditor url="http://www.tuvit.de/">TÜV-IT Germany</auditor>
      <document url="http://www.tuvit.de/certuvit/pdf/6707UE_s.pdf">ETSI TS 102.042 LCP Certificate</document>
    </audit>
    <certificate name="TC TrustCenter Class 2 CA II" status="included">
      <summary>
       This root has two internally-operated subordinate CAs which issue 
       certificates for SSL, email, and code signing. This root also has an 
       externally-operated subordinate CA which is used to issue device 
       certificates and email certificates for internal use only. The device 
       name and the email address belong to a company internal domain, so the 
       ownership is guaranteed.
      </summary>
      <data url="http://www.trustcenter.de/media/class_2_ii.der"
            version="3"
            sha1="AE:50:83:ED:7C:F4:5C:BC:8F:61:C6:21:FE:68:5D:79:42:21:15:6E"
            modulus="2048"
            from="2006-01-12"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass2-ii.trustcenter.de</ocsp>
      <type>OV</type>
      <ocsp>http://ocsp.tcclass1.trustcenter.de/</ocsp>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=486759</technical>
      </inclusion>
    </certificate>
    <certificate name="TC TrustCenter Class 3 CA II" status="included">
      <summary>
       This root has one internally-operated subordinate CA which issues 
       certificates for SSL, email, and code signing.
      </summary>
      <data url="http://www.trustcenter.de/media/class_3_ii.der"
            version="3"
            sha1="80:25:EF:F4:6E:70:C8:D4:72:24:65:84:FE:40:3B:8A:8D:6A:DB:F5"
            modulus="2048"
            from="2006-01-12"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_class_3_ca_II.crl">CRL</crl>
      <ocsp>http://ocsp.tcclass3-ii.trustcenter.de</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=486759</technical>
      </inclusion>
    </certificate>
    <certificate name="TC TrustCenter Universal CA I" status="included">
      <summary>
      This root has been introduced to reduce the number of root certificates 
      in the trusted root stores. This root will have internally-operated 
      subordinate CAs for each registration strength. “Class 1”, “Class 2”,
      “Class 3” and “Class 4” represent the registration strength. This root 
      currently has one Class 3 subordinate CA. Over time this root will have
      more “TC Class x” subordinate CA certificates.
      </summary>
      <data url="http://www.trustcenter.de/media/Universal_CA-I.der"
            version="3"
            sha1="6B:2F:34:AD:89:58:BE:62:FD:B0:6B:5C:CE:BB:9D:D9:4F:4E:39:F3"
            modulus="2048"
            from="2006-03-22"
            to="2025-12-31"/>
      <crl url="http://www.trustcenter.de/crl/v2/tc_universal_root_I.crl">CRL</crl>
      <ocsp>http://ocsp.tcuniversal-i.trustcenter.de</ocsp>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=362215">Hierarchy Diagram</document>
      <document url="http://www.trustcenter.de/media/CPS-TCTrustCenter-080904-en.pdf">TC TrustCenter GmbH Certification Practice Statement (CPS)</document>
      <document url="http://www.trustcenter.de/media/CPD-TCTrustCenter-061023-en.pdf">TC TrustCenter Certificate Policy Definitions (CPD)</document>
      <document url="http://www.trustcenter.de/en/infocenter/root_certificates.htm">TC TrustCenter CA Certificates</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=392024</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=486759</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Certigna of Dhimyotis" url="http://www.certigna.fr"  status="included">
    <summary>
      Dhimyotis services include Certigna ID and Certigna SSL. Certigna is a 
      French CA for the European market and expects to expand to serve other 
      countries (India, USA, South America ... ) soon.
    </summary>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.lsti.fr">LSTI - La Sécurité des Technologies de l'Information
      </auditor>
      <document url= "http://www.lsti-certification.fr/images/stories/dhimyotis.pdf">Statement of Compliance with ETSI TS 102.042</document>
    </audit>
    <audit type="ETSI TS 102.042">
      <auditor url="http://www.lsti.fr">LSTI - La Sécurité des Technologies de l'Information
      </auditor>
      <document url= "http://www.certigna.fr/downloads/attestation_lsti.pdf">2008 Statement of Compliance with ETSI TS 102.042</document>
    </audit>
    <certificate name="Certigna" status="included">
      <summary>
       The Certigna root has three internally operated subordinated CA’s:  
       Certigna SSL is for SSL-enabled servers, Certigna ID is for 
       authentication and digitally-signed email, and Certigna Chiffrement 
       is for encrypting email.
      </summary>
      <data url="http://www.certigna.fr/ca/ACcertigna.crt"
            version="3"
            sha1="B1:2E:13:63:45:86:A4:6F:1A:B2:60:68:37:58:2D:C4:AC:FD:94:97"
            modulus="2048"
            from="2007-06-29"
            to="2027-06-29">
      </data>
      <crl url="http://www.certigna.fr/crl/certignassl.crl">CRL for the SSL Subordinate CA</crl>
      <crl url="http://www.certigna.fr/crl/certignaid.crl">CRL for the ID Subordinate CA</crl>
      <type>IV/OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=364343">Public Portion of CPS</document> 
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=364146">Translated Portion of CPS</document> 
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=365278">Translated Portion of Code Signing CPS</document> 
      <document url="http://www.certigna.fr/documents/pc_certigna_ssl.php">Certificate Policy for SSL Subordinate CA</document> 
      <document url="http://www.certigna.fr/documents/pc_certigna_id.php">Certificate Policy for ID Subordinate CA</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=393166</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=483889</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="SECOM Trust" url="http://www.secomtrust.net/" status="included">
    <summary>SECOM Trust Services Co., Ltd are a commercial CA based in Japan.</summary>
    <audit type="WebTrust">
      <auditor url="http://www.pwc.com/Extweb/home.nsf/docid/CC9D4B80132947F8CA2571E2002A1B75">PricewaterhouseCoopers Aarata</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=599&amp;file=pdf">Report of Independent Certified Public Accountant</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="http://people.mozilla.com/~gen/secomtrust/SECOM-WTEV-Report.pdf">Audit Report and Management's Assertion</document>
    </audit>
    <certificate name="Security Communication EV RootCA1" status="included">
      <summary>This request is to add a newly constructed EV root to the NSS database. Note that there is currently a non-EV CA called Security Communication RootCA1 in the NSS database.</summary>
      <data url="https://repository.secomtrust.net/EV-Root1/EVRoot1ca.cer"
            version="3"
            sha1="FE:B8:C4:32:DC:F9:76:9A:CE:AE:3D:D8:90:8F:FD:28:86:65:64:7D"
            modulus="2048"
            from="2007-06-06"
            to="2037-06-06"/>
      <crl url="https://repository.secomtrust.net/EV-Root1/EVRoot1CRL.crl">CRL</crl>
      <ocsp><!-- none --></ocsp>
      <type>EV (policy OID 1.2.392.200091.100.721.1)</type>
      <document url="https://repository.secomtrust.net/EV-Root1/EVRoot1CPS.pdf">Security Communication EV RootCA1 Certification Practice Statement, Version 1.00 (Japanese)</document>
      <document url="https://repository.secomtrust.net/EV-Root1/EVRoot1CP1.pdf">Security Communication EV RootCA1 Subordinate CA Certificate Policy, Version 1.00 (Japanese)</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=394419</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=477134</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=477145</ev>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Certicamara S.A." url="http://www.certicamara.com"  status="complete">
    <summary>
      Sociedad Cameral de Certificación Digital - Certicámara S.A. is a 
      commercial CA primarily serving Colombia and Andean Region
    </summary>
    <audit type="WebTrust">
      <auditor url="http://www.deloitte.com">Deloitte and Touche
      </auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=750&amp;file=pdf">Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="AC Raíz Certicámara S.A." status="approved">
      <summary>
       This is a new root CA certificate authorized by Industry and 
       Commerce Department of Colombia, to replace the Certificado Empresarial Clase-A 
       certificate. It has one internally operated subordinate CA.
      </summary>
      <data url="http://www.certicamara.com/ac_offline_raiz_certicamara.crt"
            version="3"
            sha1="CB:A1:C5:F8:B0:E3:5E:B8:B9:45:12:D3:F9:34:A2:E9:06:10:D3:36"
            modulus="4096"
            from="2006-11-27"
            to="2030-04-02">
      </data>
      <crl url="http://www.certicamara.com/repositoriorevocaciones/ac_raiz_certicamara.crl">CRL</crl>
      <type>OV</type>
      <document url="http://www.certicamara.com/certificate_hierarchy_diagram.jpg">Certificate Hierarchy
      </document> 
      <document url="http://www.certicamara.com/templates/cc/images/dpc/DPCMarzo_09.pdf">Certification Practices Statement (CPS) – in Spanish
      </document>
      <document url="http://www.certicamara.com/index.php?option=com_content&amp;task=category&amp;sectionid=22">Declaration of Practices
      </document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=401262</authorisation>
        <technical>http://bugzilla.mozilla.org/show_bug.cgi?id=486424</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="ComSign" url="http://www.comsign.co.il/eng/default.asp" status="included">
    <summary>
     ComSign is a private company owned by Comda, Ltd., a company specializing 
     in information protection products and solutions. In 2003, ComSign was 
     appointed by the Justice Ministry as a certificate authority in Israel in 
     accordance with the Electronic Signature Law 5761-2001, and is currently 
     the only entity issuing legal authorized electronic signatures according to 
     the Israel law. ComSign has issued electronic signatures to thousands of 
     business people in Israel.
    </summary>
    <audit type="Israel Electronic Signature Law">
      <auditor url="http://www.justice.gov.il/MOJEng/Certification+Authorities+Registrar">The State of Israel – Ministry of Justice</auditor>
      <document url="http://www.justice.gov.il/MOJEng/Certification+Authorities+Registrar/Registered+CAs/">Registered CA</document>
    </audit>
    <audit type="ETSI TS 101 456">
      <auditor url="https://bugzilla.mozilla.org/attachment.cgi?id=348789">Sharony-Shefler</auditor>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=371697">Audit Statement 2009</document>
    </audit>
    <certificate name="ComSign CA" status="approved">
      <summary>
      This root has six internally-operated subordinate CAs that are used for 
      issuing digital IDs to individuals and corporations in accordance with 
      the Israeli Electronic Signature Law. 
      </summary>
      <data url="http://fedir.comsign.co.il/cacert/ComsignCA.crt"
            version="3"
            sha1="E1 A4 5B 14 1A 21 DA 1A 79 F4 1A 42 A9 61 D6 69 CD 06 34 C1"
            modulus="2048"
            from="2004-03-24"
            to="2029-03-19"/>
      <crl url="http://fedir.comsign.co.il/crl/ComSignCA.crl">CRL</crl>
      <type>IV, OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=346012">Cert Hierarchy Diagram</document>
      <document url="http://www.comsign.co.il/main.asp?id=125">Links to CPSs in Hebrew and English</document>
      <document url="http://www.comsign.co.il/Images/Doc/English_CPS_final.doc">CPS in English</document>
      <trust>
        <flag type="email" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=420705</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=490487</technical>
      </inclusion>
    </certificate>
    <certificate name="ComSign Secured CA" status="included">
      <summary>
      This root has two internally-operated subordinate CAs that are used 
      for issuing certificates for SSL and for code-signing.
      </summary>
      <data url="http://fedir.comsign.co.il/cacert/ComsignSecuredCA.crt"
            version="3"
            sha1="F9 CD 0E 2C DA 76 24 C1 8F BD F0 F0 AB B6 45 B8 F7 FE D5 7A"
            modulus="2048"
            from="2004-03-24"
            to="2029-03-16"/>
      <crl url="http://fedir.comsign.co.il/crl/ComSignSecuredCA.crl">CRL</crl>
      <type>OV</type>
      <document url="https://bugzilla.mozilla.org/attachment.cgi?id=346012">Cert Hierarchy Diagram</document>
      <document url="http://www.comsign.co.il/main.asp?id=125">Links to CPSs in Hebrew and English</document>
      <document url="http://www.comsign.co.il/Images/Doc/English_CPS_final.doc">CPS in English</document>
      <document url="http://www.comsign.co.il/Images/Doc/CPS__SSL_EN.pdf">Security Certificate Approval Regulations For SSL Websites in English</document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
        <flag type="code" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>https://bugzilla.mozilla.org/show_bug.cgi?id=420705</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=490487</technical>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Wells Fargo" url="http://www.wellsfargo.com/"  status="included">
    <summary>
      Wells Fargo is a public CA based in San Francisco, California, and serving customers worldwide. This EV CA was created for the purpose of creating an online/intermediate EV SSL issuing authority which will be managed internally, and follow the WellsSecure CPS.
    </summary>
    <audit type="WebTrust EV pre-audit">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url= "https://bugzilla.mozilla.org/attachment.cgi?id=326739">Audit Report
      and Management's Assertions</document>
    </audit>
    <audit type="WebTrust CA">
      <auditor url="http://www.kpmg.com/">KPMG</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=528&amp;file=pdf">Audit Report
      and Management's Assertions</document>
    </audit>
    <certificate name="WellsSecure Public Root Certificate Authority" status="included">
      <summary>
        Root CA with one internal subordinate CA issuing EV SSL certificates.
      </summary>
      <data url="http://crl.pki.wellsfargo.com/wsprca.crt"
            version="3"
            sha1="e7:b4:f6:9d:61:ec:90:69:db:7e:90:a7:40:1a:3c:f4:7d:4f:e8:ee"
            modulus="2048"
            from="2007-12-13"
            to="2022-12-13">
      </data>
      <crl url="http://crl.pki.wellsfargo.com/ev.crl">CRL</crl>
      <ocsp>http://validator.wellsfargo.com/</ocsp>
      <type>EV (policy OID 2.16.840.1.114171.500.9)</type>
      <document url="http://www.wellsfargo.com/cps"> WellsSecure PKI Certificate Policy
      </document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=428390</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=449393</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=449394</ev>
      </inclusion>
    </certificate>
  </authority>

  <authority name="Verizon / Cybertrust" url="http://www.verizonbusiness.com/us/products/security/identity/"                   status="included">
    <summary>
      Verizon Business Security Solutions Powered by Cybertrust
      operates a commercial certificate authority service for
      businesses and governments internationally.
    </summary>
    <audit type="WebTrust CA">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cert.webtrust.org/SealFile?seal=799&amp;file=pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <audit type="WebTrust EV">
      <auditor url="http://www.ey.com/be">Ernst and Young</auditor>
      <document url="https://cybertrust.omniroot.com/repository/WT_EV_2008_SealFile.pdf">
      Audit Report and Management's Assertions</document>
    </audit>
    <certificate name="Cybertrust Global Root" status="included">
      <summary>
        This root was created to provide a service to customers
        desiring a root based outside the United States. Relying on
        the GTE CyberTrust Global Root for ubiquity through
        cross-certification, this root is used for issuance of EV SSL
        certificates. There is currently only one internally-operated
        subordinate CA called Cybertrust SureServer EV CA.  The CPS
        allows for this root to have other subordinate CAs in the
        future. The sub-CAs are required to follow the CPS and to have
        regular audits.
      </summary>
      <data url="http://cacert.omniroot.com/ct_root_ss.crt"
            version="3"
            sha1="5f:43:e5:b1:bf:f8:78:8c:ac:1c:c7:ca:4a:9a:c6:22:2b:cc:34:c6"
            modulus="2048"
            from="2006-12-15"
            to="2021-12-15">
      </data>
      <crl url="http://www2.public-trust.com/crl/ct/ctroot.crl">CRL</crl>
      <ocsp><!-- None --></ocsp>
      <type>EV (policy OID 1.3.6.1.4.1.6334.1.100.1)</type>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CP_v_2_3_cl.pdf"> Cybertrust CA Certificate Policy
      </document>
      <document url="http://cybertrust.omniroot.com/repository/Cybertrust_CPS_v_5_4.pdf"> Certification Practice Statement
      </document>
      <trust>
        <flag type="web" startdate="" enddate=""/>
      </trust>
      <inclusion date="">
        <authorisation>http://bugzilla.mozilla.org/show_bug.cgi?id=430700</authorisation>
        <technical>https://bugzilla.mozilla.org/show_bug.cgi?id=493258</technical>
        <ev>https://bugzilla.mozilla.org/show_bug.cgi?id=493259</ev>
      </inclusion>
    </certificate>
  </authority>

</certificates>
