{"id":2074,"date":"2016-03-29T15:52:54","date_gmt":"2016-03-29T22:52:54","guid":{"rendered":"https:\/\/blog.mozilla.org\/security\/?p=2074"},"modified":"2016-09-30T02:48:15","modified_gmt":"2016-09-30T09:48:15","slug":"march-2016-ca-communication","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/","title":{"rendered":"March 2016 CA Communication"},"content":{"rendered":"<p>Mozilla has sent a <a href=\"https:\/\/wiki.mozilla.org\/CA:Communications#March_2016\" target=\"_blank\">Communication<\/a> to the <a href=\"https:\/\/wiki.mozilla.org\/CA:FAQ#What_are_CAs.3F\" target=\"_blank\">Certification Authorities (CAs)<\/a> who have root certificates <a href=\"https:\/\/wiki.mozilla.org\/CA:IncludedCAs\" target=\"_blank\">included in Mozilla\u2019s program<\/a>. Mozilla\u2019s CA Certificate Program governs inclusion of root certificates in <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Mozilla\/Projects\/NSS\" target=\"_blank\">Network Security Services (NSS)<\/a>, a set of open source libraries designed to support cross-platform development of security-enabled client and server applications. The NSS root certificate store is not only used in Mozilla products such as the Firefox browser, but is also used by other companies and open-source projects in a variety of applications.<\/p>\n<p>The <a href=\"https:\/\/wiki.mozilla.org\/CA:Communications#March_2016\" target=\"_blank\">CA Communication<\/a> has been emailed to the <a href=\"https:\/\/wiki.mozilla.org\/CA:Information_checklist#CA_Primary_Point_of_Contact_.28POC.29\" target=\"_blank\">Primary Point of Contact (POC)<\/a> for each CA in Mozilla\u2019s program, and they have been asked to respond to 7 action items:<\/p>\n<ol>\n<li>Update us on their progress in <a href=\"https:\/\/blog.mozilla.org\/security\/2015\/10\/20\/continuing-to-phase-out-sha-1-certificates\/\" target=\"_blank\">eliminating use of SHA-1<\/a> as a certificate signature algorithm;<\/li>\n<li>Enter <a href=\"https:\/\/wiki.mozilla.org\/CA:SalesforceCommunity#Which_intermediate_certificate_data_should_CAs_add_to_Salesforce.3F\" target=\"_blank\">intermediate certificate data<\/a> into the <a href=\"https:\/\/wiki.mozilla.org\/CA:SalesforceCommunity\" target=\"_blank\">CA Community in Salesforce<\/a>;<\/li>\n<li>Enter <a href=\"https:\/\/wiki.mozilla.org\/CA:SalesforceCommunity#Add_Revoked_Intermediate_Certificate_Data_to_Salesforce\" target=\"_blank\">revoked intermediate certificate data<\/a> into the <a href=\"https:\/\/wiki.mozilla.org\/CA:SalesforceCommunity\" target=\"_blank\">CA Community in Salesforce<\/a>;<\/li>\n<li>Stop issuing certificates with the problems listed <a href=\"https:\/\/wiki.mozilla.org\/SecurityEngineering\/mozpkix-testing#Things_for_CAs_to_Fix\" target=\"_blank\">here<\/a>, because we are going to remove the workarounds from <a href=\"https:\/\/blog.mozilla.org\/security\/2014\/08\/20\/mozillapkix-ships-in-firefox\/\" target=\"_blank\">mozilla::pkix<\/a>;<\/li>\n<li>Tell us their plans for removing root certificates that they have retired or are migrating their customers away from;<\/li>\n<li>Confirm their understanding that all certificates, including test certificates, must conform to <a href=\"https:\/\/www.mozilla.org\/en-US\/about\/governance\/policies\/security-group\/certs\/policy\/\" target=\"_blank\">Mozilla\u2019s stated policies<\/a>; and<\/li>\n<li>Update us on changes involving transfer of ownership of root certificates, according to our <a href=\"https:\/\/wiki.mozilla.org\/CA:RootTransferPolicy\" target=\"_blank\">Root Transfer Policy<\/a>.<\/li>\n<\/ol>\n<p>The full action items can be read <a href=\"https:\/\/mozillacaprogram.secure.force.com\/Communications\/CACommunicationSurveySample?CACommunicationId=a05o000000iHdtx\" target=\"_blank\">here<\/a>. Responses to the survey will be <a href=\"https:\/\/wiki.mozilla.org\/CA:Communications#March_2016_Responses\" target=\"_blank\">automatically and immediately published<\/a> using <a href=\"https:\/\/www.salesforce.com\/\" target=\"_blank\">Salesforce<\/a>.<\/p>\n<p>With this <a href=\"https:\/\/wiki.mozilla.org\/CA:Communications#March_2016\" target=\"_blank\">CA Communication<\/a>, we re-iterate that participation in Mozilla\u2019s CA Certificate Program is at our sole discretion, and we will take whatever steps are necessary to keep our users safe. Nevertheless, we believe that the best approach to safeguard that security is to work with CAs as partners, to foster open and frank communication, and to be diligent in looking for ways to improve.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mozilla has sent a Communication to the Certification Authorities (CAs) who have root certificates included in Mozilla\u2019s program. Mozilla\u2019s CA Certificate Program governs inclusion of root certificates in Network Security &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/\">Read more<\/a><\/p>\n","protected":false},"author":581,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45538,69],"tags":[],"coauthors":[45544],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>March 2016 CA Communication - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kathleen Wilson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/\",\"name\":\"March 2016 CA Communication - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2016-03-29T22:52:54+00:00\",\"dateModified\":\"2016-09-30T09:48:15+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/5cc0f3b46b6626ffb6e3b7c24fbf5063\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"March 2016 CA Communication\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/5cc0f3b46b6626ffb6e3b7c24fbf5063\",\"name\":\"Kathleen Wilson\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/8d4547801f543f8990aecbcfc9c18eca\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/faede0fc9d625b79b41f567407337db6?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/faede0fc9d625b79b41f567407337db6?s=96&d=identicon&r=g\",\"caption\":\"Kathleen Wilson\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"March 2016 CA Communication - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/","twitter_misc":{"Written by":"Kathleen Wilson","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/","url":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/","name":"March 2016 CA Communication - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2016-03-29T22:52:54+00:00","dateModified":"2016-09-30T09:48:15+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/5cc0f3b46b6626ffb6e3b7c24fbf5063"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2016\/03\/29\/march-2016-ca-communication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"March 2016 CA Communication"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/5cc0f3b46b6626ffb6e3b7c24fbf5063","name":"Kathleen Wilson","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/8d4547801f543f8990aecbcfc9c18eca","url":"https:\/\/secure.gravatar.com\/avatar\/faede0fc9d625b79b41f567407337db6?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/faede0fc9d625b79b41f567407337db6?s=96&d=identicon&r=g","caption":"Kathleen Wilson"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2074"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/581"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=2074"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2074\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=2074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=2074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=2074"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=2074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}