bug 1303383 - enable 5 Amazon root CAs for EV r?jcj draft
authorDavid Keeler <dkeeler@mozilla.com>
Tue, 31 Jan 2017 16:05:35 -0800
changeset 468881 3c288a9bec39fb662d8914978df3b7397168bc85
parent 468498 ee975d32deb9eaa5641f45428cd6a4b5b555a8f5
child 544035 6d583b9cc756cb8f9e4e4ce1f7f44e22c7f05d68
push id43557
push userdkeeler@mozilla.com
push dateWed, 01 Feb 2017 00:13:08 +0000
reviewersjcj
bugs1303383
milestone54.0a1
bug 1303383 - enable 5 Amazon root CAs for EV r?jcj MozReview-Commit-ID: JRs7CWwafSK
security/certverifier/ExtendedValidation.cpp
--- a/security/certverifier/ExtendedValidation.cpp
+++ b/security/certverifier/ExtendedValidation.cpp
@@ -1168,16 +1168,78 @@ static struct nsMyTrustedEVInfo myTruste
       0xC4, 0x54, 0xFC, 0x75, 0x8B, 0x2A, 0x26, 0xCF, 0x7F, 0x79 },
     "MIHKMQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNV"
     "BAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAyMDA3IFZl"
     "cmlTaWduLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMT"
     "PFZlcmlTaWduIENsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBB"
     "dXRob3JpdHkgLSBHNA==",
     "L4D+I4wOIg9IZxIokYessw==",
   },
+  {
+    // CN=Amazon Root CA 1,O=Amazon,C=US
+    "2.23.140.1.1",
+    "CA/Browser Forum EV OID",
+    SEC_OID_UNKNOWN,
+    { 0x8E, 0xCD, 0xE6, 0x88, 0x4F, 0x3D, 0x87, 0xB1, 0x12, 0x5B, 0xA3,
+      0x1A, 0xC3, 0xFC, 0xB1, 0x3D, 0x70, 0x16, 0xDE, 0x7F, 0x57, 0xCC,
+      0x90, 0x4F, 0xE1, 0xCB, 0x97, 0xC6, 0xAE, 0x98, 0x19, 0x6E },
+    "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpv"
+    "biBSb290IENBIDE=",
+    "Bmyfz5m/jAo54vB4ikPmljZbyg==",
+  },
+  {
+    // CN=Amazon Root CA 2,O=Amazon,C=US
+    "2.23.140.1.1",
+    "CA/Browser Forum EV OID",
+    SEC_OID_UNKNOWN,
+    { 0x1B, 0xA5, 0xB2, 0xAA, 0x8C, 0x65, 0x40, 0x1A, 0x82, 0x96, 0x01,
+      0x18, 0xF8, 0x0B, 0xEC, 0x4F, 0x62, 0x30, 0x4D, 0x83, 0xCE, 0xC4,
+      0x71, 0x3A, 0x19, 0xC3, 0x9C, 0x01, 0x1E, 0xA4, 0x6D, 0xB4 },
+    "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpv"
+    "biBSb290IENBIDI=",
+    "Bmyf0pY1hp8KD+WGePhbJruKNw==",
+  },
+  {
+    // CN=Amazon Root CA 3,O=Amazon,C=US
+    "2.23.140.1.1",
+    "CA/Browser Forum EV OID",
+    SEC_OID_UNKNOWN,
+    { 0x18, 0xCE, 0x6C, 0xFE, 0x7B, 0xF1, 0x4E, 0x60, 0xB2, 0xE3, 0x47,
+      0xB8, 0xDF, 0xE8, 0x68, 0xCB, 0x31, 0xD0, 0x2E, 0xBB, 0x3A, 0xDA,
+      0x27, 0x15, 0x69, 0xF5, 0x03, 0x43, 0xB4, 0x6D, 0xB3, 0xA4 },
+    "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpv"
+    "biBSb290IENBIDM=",
+    "Bmyf1XSXNmY/Owua2eiedgPySg==",
+  },
+  {
+    // CN=Amazon Root CA 4,O=Amazon,C=US
+    "2.23.140.1.1",
+    "CA/Browser Forum EV OID",
+    SEC_OID_UNKNOWN,
+    { 0xE3, 0x5D, 0x28, 0x41, 0x9E, 0xD0, 0x20, 0x25, 0xCF, 0xA6, 0x90,
+      0x38, 0xCD, 0x62, 0x39, 0x62, 0x45, 0x8D, 0xA5, 0xC6, 0x95, 0xFB,
+      0xDE, 0xA3, 0xC2, 0x2B, 0x0B, 0xFB, 0x25, 0x89, 0x70, 0x92 },
+    "MDkxCzAJBgNVBAYTAlVTMQ8wDQYDVQQKEwZBbWF6b24xGTAXBgNVBAMTEEFtYXpv"
+    "biBSb290IENBIDQ=",
+    "Bmyf18G7EEwpQ+Vxe3ssyBrBDg==",
+  },
+  {
+    // CN=Starfield Services Root Certificate Authority - G2,O="Starfield Technologies, Inc.",L=Scottsdale,ST=Arizona,C=US
+    "2.23.140.1.1",
+    "CA/Browser Forum EV OID",
+    SEC_OID_UNKNOWN,
+    { 0x56, 0x8D, 0x69, 0x05, 0xA2, 0xC8, 0x87, 0x08, 0xA4, 0xB3, 0x02,
+      0x51, 0x90, 0xED, 0xCF, 0xED, 0xB1, 0x97, 0x4A, 0x60, 0x6A, 0x13,
+      0xC6, 0xE5, 0x29, 0x0F, 0xCB, 0x2A, 0xE6, 0x3E, 0xDA, 0xB5 },
+    "MIGYMQswCQYDVQQGEwJVUzEQMA4GA1UECBMHQXJpem9uYTETMBEGA1UEBxMKU2Nv"
+    "dHRzZGFsZTElMCMGA1UEChMcU3RhcmZpZWxkIFRlY2hub2xvZ2llcywgSW5jLjE7"
+    "MDkGA1UEAxMyU3RhcmZpZWxkIFNlcnZpY2VzIFJvb3QgQ2VydGlmaWNhdGUgQXV0"
+    "aG9yaXR5IC0gRzI=",
+    "AA==",
+  },
 };
 
 static SECOidTag
 RegisterOID(const SECItem& oidItem, const char* oidName)
 {
   SECOidData od;
   od.oid.len = oidItem.len;
   od.oid.data = oidItem.data;