The Opera Rootstore

The Roots of Internet trust

Introducing the Opera Rootstore

, , , , , , , , ,

Welcome to the new home page of the Opera Root Certificate Store.

Root Certificates are used in several security areas to get assurance of identity, by establishing a relationship between the control of the private key associated with the public key in a certificate signed by the Root Certificate, and the entity identified by the certificate. The keypair can then be used to establish various forms of secure communication with that party, such as digital signatures and encrypted connections.

The area where certificates are most widely used is to set up and secure SSL/TLS connections, for example, to secure your online banking transactions and online shopping.

To use certificates signed by a Root properly, the application needs a copy of the Root provided by the owner of the Root via a different route than from the web site presenting the certificate, so that we can be assured that the Root is the real Root, and not a look-alike.

That is why we have the Rootstore database. The Rootstore is where we store the list of Roots that are either pre-checked by us and shipped with Opera, or installed by the user.

In Opera 9.50 we changed the design of the Rootstore. In the new system, only the most frequently used Roots are shipped with the Opera executable, while the other Roots are stored in our online root repository at https://certs.opera.com/ and will be automatically downloaded and installed, as needed.

"The Rootstore" home page will be where we will announce all updates of the online Root repository, as well as other public information about this part of the Opera browser.

If you represent a CA that wants to have its certificate added to Opera's rootstore, please see http://www.opera.com/docs/ca/ for information about the procedure.

Rootstore newsletter

Comments

cakruege Wednesday, September 24, 2008 2:35:31 PM

Hi,

is it possible to stop loading ca certificates from https://certs.opera.com/?
How is this system secured against compromising certs.opera.com?

greetings
Carsten

Yngve Nysæter Pettersenyngve Wednesday, September 24, 2008 3:24:32 PM

The system is described in the Newletter.

http://my.opera.com/rootstore/blog/2008/07/03/rootstore-newsletter.

certs.opera.com is also just a front end, it does not generate the files.

GrinGrin Wednesday, June 30, 2010 10:02:04 PM

Originally posted by bugmenot15:

What about the StartCom cert? It seems that StartCom already applied some time ago (http://groups.google.com/group/opera.linux/browse_thread/thread/df0456be2858b396/12e0de0c45fb0fc9)

Is there an ETA for including it on certs.opera.com?



It seems Opera not interested in including StartCom CA in their "RootStore" (StartCom submited his request nearly one year ago !!)

Microsoft, Google, Apple and so on already included StartCom CA Root for their browsers, *Opera don't and probably don't want to* furious

Yngve Nysæter Pettersenyngve Wednesday, June 30, 2010 11:12:26 PM

Actually, Startcom is nearing the end of the process; a few hours ago we received updated electronic copies of documents we've been waiting for. Once those documents have been checked, we should be ready for the final steps.

Write a comment

New comments have been disabled for this post.