← HARICA cases
Bugzilla #1201423 Ca Certificate Root Program

HARICA root renewal request for two 2015 rollover roots

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA requested Mozilla trust inclusion for two new rollover root certificates: the RSA-based "Hellenic Academic and Research Institutions RootCA 2015" and the ECC-based "Hellenic Academic and Research Institutions ECC RootCA 2015." The request included HARICA’s CA details, audit information, certificate metadata, and the stated intent that these SHA-256 roots would eventually replace the older SHA-1 RootCA 2011. During review, Mozilla asked HARICA to address certlint findings and other questions, including key usage, serial number handling, and certificate policy text. HARICA responded to the review comments, explained its configuration and certificate profile choices, and later said it would remove the keyEncipherment bit for ECDSA certificates. Mozilla then opened public discussion, and after the discussion period ended, approved inclusion of both roots for websites and email trust bits. Mozilla also filed NSS bug 1256494 for the actual changes.

Model: gpt-5.4-mini Generated: 2026-06-13 14:01 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.97 33 comments
Chronology
  1. HARICA requested inclusion of two new rollover root certificates to replace RootCA 2011.
  2. Mozilla opened public discussion for the HARICA root renewal request.
  3. Mozilla approved inclusion of the two HARICA roots for websites and email.
  4. Mozilla filed NSS bug 1256494 for the implementation changes.
Thread Activity
  1. HARICA — HARICA opened the request and provided CA details, audit information, and metadata for the RSA and ECC 2015 roots.
  2. Mozilla representative — Mozilla said the request had been added to the queue for public discussion.
  3. Mozilla representative — Mozilla reported that the www3.harica.gr certificate chain issue was due to the server sending certificates in the wrong order.
  4. HARICA — HARICA said www3.harica.gr was served through SNI and that it had corrected the certificate order on its web server.
  5. Mozilla representative — Mozilla asked HARICA to run certlint tests and comment back when errors were resolved.
  6. Community commenter — HARICA responded to certlint findings and explained its positions on key usage, policy text encoding, RFC822Name constraints, and root serial numbers.
  7. Mozilla representative — Mozilla said certlint had been updated and noted that the key usage issue remained for EC keys.
  8. Mozilla representative — Mozilla said already-included CA certificates were grandfathered, but new CA certificates must meet the Baseline Requirements and pass certlint without error.
  9. Mozilla representative — Mozilla stated that the public comment period was over and summarized its assessment under the inclusion policy.
  10. HARICA — HARICA said it would not use the keyAgreement bit for ECDSA and would remove the keyEncipherment bit.
  11. Mozilla representative — Mozilla approved inclusion of both HARICA roots for websites and email and said it would file the NSS bug for the changes.
Participants
HARICA Mozilla representative Community commenter DigiCert
Related Bugzilla IDs Mentioned
Similar Local Cases
#581901 RESOLVED Ca Certificate Root Program Opened 2010-07-26 · Closed 2022-11-14 · 92% similar
Add HARICA root certificate
#478418 RESOLVED Ca Certificate Root Program Opened 2009-02-13 · Closed 2022-11-14 · 76% similar
Please add US FPKI Common Policy CA certificate
#926029 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2013-10-12 · Closed 2022-11-14 · 73% similar
CFCA (China Financial Certification Authority) root CA
#520557 RESOLVED Ca Certificate Root Program Opened 2009-10-05 · Closed 2022-11-14 · 73% similar
Add Actalis Authentication Root CA certificate
#711366 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2011-12-16 · Closed 2022-11-14 · 72% similar
Add Atos Trustcenter CA cert to trusted root CA cert list
#1313982 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2016-10-31 · Closed 2025-04-02 · 72% similar
Add SECOM root certificates
#359069 RESOLVED Ca Certificate Root Program Opened 2006-11-01 · Closed 2022-11-14 · 72% similar
Request to add two additional IdenTrust root CA certificates
#455878 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-09-18 · Closed 2022-11-14 · 72% similar
Add CA Disig root certificate into browser

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action