HARICA root renewal request for two 2015 rollover roots
HARICA requested Mozilla trust inclusion for two new rollover root certificates: the RSA-based "Hellenic Academic and Research Institutions RootCA 2015" and the ECC-based "Hellenic Academic and Research Institutions ECC RootCA 2015." The request included HARICA’s CA details, audit information, certificate metadata, and the stated intent that these SHA-256 roots would eventually replace the older SHA-1 RootCA 2011. During review, Mozilla asked HARICA to address certlint findings and other questions, including key usage, serial number handling, and certificate policy text. HARICA responded to the review comments, explained its configuration and certificate profile choices, and later said it would remove the keyEncipherment bit for ECDSA certificates. Mozilla then opened public discussion, and after the discussion period ended, approved inclusion of both roots for websites and email trust bits. Mozilla also filed NSS bug 1256494 for the actual changes.
- HARICA requested inclusion of two new rollover root certificates to replace RootCA 2011.
- Mozilla opened public discussion for the HARICA root renewal request.
- Mozilla approved inclusion of the two HARICA roots for websites and email.
- Mozilla filed NSS bug 1256494 for the implementation changes.
- HARICA — HARICA opened the request and provided CA details, audit information, and metadata for the RSA and ECC 2015 roots.
- Mozilla representative — Mozilla said the request had been added to the queue for public discussion.
- Mozilla representative — Mozilla reported that the www3.harica.gr certificate chain issue was due to the server sending certificates in the wrong order.
- HARICA — HARICA said www3.harica.gr was served through SNI and that it had corrected the certificate order on its web server.
- Mozilla representative — Mozilla asked HARICA to run certlint tests and comment back when errors were resolved.
- Community commenter — HARICA responded to certlint findings and explained its positions on key usage, policy text encoding, RFC822Name constraints, and root serial numbers.
- Mozilla representative — Mozilla said certlint had been updated and noted that the key usage issue remained for EC keys.
- Mozilla representative — Mozilla said already-included CA certificates were grandfathered, but new CA certificates must meet the Baseline Requirements and pass certlint without error.
- Mozilla representative — Mozilla stated that the public comment period was over and summarized its assessment under the inclusion policy.
- HARICA — HARICA said it would not use the keyAgreement bit for ECDSA and would remove the keyEncipherment bit.
- Mozilla representative — Mozilla approved inclusion of both HARICA roots for websites and email and said it would file the NSS bug for the changes.