The program then analyses the extent to which the certificates were signed using keys from browsers’ trusted roots, using trusted root certificates distributed by Mozilla (FF) and Microsoft (MS), as of November 2011.
Note: this program analyses only signatures. Correct signatures are a prerequisite to trust, but they don't imply trust. The program ignores other trust-related parts of the certificates, and doesn’t even have access to browser-specific trust settings. This version of the program does not check Elliptic Curve signatures.