IdenTrust root renewal request for Commercial Root CA 1 and Public Sector Root CA 1
IdenTrust asked Mozilla to renew its root certificates by adding "IdenTrust Commercial Root CA 1" and "IdenTrust Public Sector Root CA 1" to replace the older "DST Root X3" and "DST ACES X6" roots. Mozilla reviewed the request, requested additional information and updated audit statements, and then opened public discussion. During the review, IdenTrust provided answers about subordinate CAs, third-party issuers, validation practices, and audit links. Mozilla later approved the request for the two new roots with websites and email trust bits. In a later follow-up, a third party raised concern that a cross-certificate under the IdenTrust hierarchy was publicly trusted; IdenTrust said it would revoke that cross-certificate and later reported that revocation was completed on February 17, 2016. The bug is resolved as FIXED.
- IdenTrust requested renewal of its root certificates with new Commercial and Public Sector roots.
- Mozilla opened public discussion for inclusion of the two new IdenTrust roots with websites and email trust bits.
- Mozilla approved inclusion of IdenTrust Commercial Root CA 1 and IdenTrust Public Sector Root CA 1.
- IdenTrust reported that the cross-certificate revocation had been completed.
- IdenTrust Services, LLC — IdenTrust filed the renewal request and said the new roots would replace DST ACES X6 and DST Root X3.
- Mozilla representative — Mozilla accepted the bug and said it would move through information verification.
- IdenTrust Services, LLC — IdenTrust answered questions about subordinate CAs, third-party issuers, and domain validation under the existing roots.
- IdenTrust Services, LLC — IdenTrust posted new audit statements and provided URLs for the WebTrust and baseline requirements audits.
- Mozilla representative — Mozilla opened the first public discussion period for the request.
- Mozilla representative — Mozilla summarized the assessment and said it intended to approve the request.
- Mozilla representative — Mozilla approved the request and said it would file the NSS bug for the changes.
- IdenTrust Services, LLC — IdenTrust said a cross-certificate under the DST ACES X6 chain would be revoked as it was not needed.
- Ipv representative — Richard Barnes asked IdenTrust to revoke the cross-certificate and add it to OneCRL after revocation.
- IdenTrust Services, LLC — IdenTrust said the certificate had been revoked and that chaining no longer worked.