Distrust ISRG subordinate certificate until CA completes Mozilla Baseline Requirements audit
This case concerns Mozilla CA Baseline Requirements audit expectations for a not technically constrained subordinate CA under the Mozilla CA Certificate Inclusion Policy. The submitter stated that a formal audit was missing, noting it had been announced for November 2015, and that only a readiness assessment was available at the time. Mozilla staff responded that a point-in-time readiness assessment (PITRA) is sufficient to begin issuing if the formal audit follows in a timely fashion, and explained that a formal audit of the issuance process cannot be done before issuance begins. Other commenters discussed the Mozilla wiki guidance that a CA may use a point-in-time readiness assessment before a full audit, and debated what “timely fashion” means, including references to completing a full audit within a specified period after issuing the first publicly trusted certificate. Later comments indicated that the audit had been finished, providing links to WebTrust reports for BR and CA and a community post about the completed audits. The bug was resolved with resolution set to INVALID.
- Bug opened requesting distrust/removal of an ISRG subordinate certificate until the CA is compliant with Mozilla policies due to missing formal audit evidence.
- Thread notes that the relevant WebTrust audit documents were available, indicating the audit had been completed.
- Psw representative — The submitter argued that Mozilla requires a publicly disclosed and audited not technically constrained subordinate CA, and said only a readiness assessment existed while a formal audit was still missing.
- Mozilla representative — Mozilla staff stated that a PITRA is sufficient to begin issuing if the formal audit follows timely, and that a formal audit of issuance cannot occur before issuance starts.
- Psw representative — The submitter asked what timeframe qualifies as “timely fashion” and referenced a beta phase for evidence of the issuance process.
- Ipv representative — A commenter cited Mozilla wiki guidance that a first BR audit may be a point-in-time audit and suggested the CA may have up to a year for a full audit.
- Startcom representative — Another commenter quoted a requirement that a point-in-time readiness assessment must be completed before issuing publicly trusted certificates and that a complete audit must follow within 90 days of issuing the first publicly trusted certificate.
- Community commenter — A commenter noted the first issued certificate was valid for 90 days and that there were days remaining to complete the audit before expiry.
- Opayq representative — The commenter provided links to WebTrust audit documents and a community post stating the audits were finished.