← Internet Security Research Group cases
Bugzilla #1230797 · Policy Compliance
Distrust ISRG Subordinate Certificate and Remove It Until the CA is Compliant with Mozilla Policies
Internet Security Research Group · RESOLVED
AI Summary
The case addresses the distrust of the ISRG subordinate certificate due to non-compliance with Mozilla's CA Certificate Inclusion Policy. A formal audit was missing, although a readiness assessment was announced. The discussion highlights the timeline for audits and the requirements for issuing certificates. Ultimately, the case was resolved with the decision to distrust the certificate until compliance is achieved.
Chronology
- Initial report of distrust due to audit issues
- Case resolved
Participants
Christian Heutger
Kathleen Wilson
Gervase Markham
Eddy Nigg
External References
Similar Local Cases
SwissSign: BRs require full annual audits
SHA-1 issuance by GlobalSign root
Verify GlobalSign's continued conformance to EV guidelines
StartCom: Certificates using secp256k1
GoDaddy: Valid 1024 certificates
DigiCert: Inconsistent EV audits
DigiCert: Verizon CPS lacks CPR problem reporting instructions
DigiCert: Late background refreshment check