DocuSign (OpenTrust/Keynectis/Certplus) root renewal request for five new roots
This case was a request from OpenTrust, later DocuSign (OpenTrust/Keynectis/Certplus), to include five new root CA certificates in Mozilla and to enable Websites, Email, and EV trust for them. The request was opened by the CA operator and included the new Certplus Root CA G1 and G2, plus OpenTrust Root CA G1, G2, and G3. Mozilla reviewed the CA information, policy documents, audits, subordinate CA information, and EV testing details, and the CA provided updated URLs, audit material, and test websites during the review. The thread also covered the CA’s explanation of EV policy OIDs and the test results for the root-specific EV websites. Mozilla approved the request on 2016-05-20 and later filed follow-up NSS and PSM bugs for the actual changes. In 2018, the CA asked to remove the Websites trust bit for the same five roots, and Mozilla opened a separate bug for that request.
- OpenTrust requested inclusion of five new root CA certificates.
- Mozilla approved inclusion of the five roots with Websites, Email, and EV trust.
- DocuSign requested removal of the Websites trust bit for the five roots.
- Opentrust representative — OpenTrust opened the bug to request inclusion of new root CA certificates and provided policy, audit, and root certificate information.
- Mozilla representative — Mozilla accepted the bug and said it would move through the information verification phase.
- Opentrust representative — OpenTrust provided EV checker results for the five roots and test websites for each root.
- Mozilla representative — Mozilla opened public discussion for inclusion of the five roots and EV treatment.
- Mozilla representative — Mozilla approved the request to include the five roots with Websites, Email, and EV trust.
- Docusign representative — DocuSign requested removal of the Websites trust bit for the five roots.