← Internet Security Research Group cases
Bugzilla #1230797 Audit Related

Distrust ISRG subordinate certificate until CA completes Mozilla Baseline Requirements audit

RESOLVED INVALID Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Mozilla CA Baseline Requirements audit expectations for a not technically constrained subordinate CA under the Mozilla CA Certificate Inclusion Policy. The submitter stated that a formal audit was missing, noting it had been announced for November 2015, and that only a readiness assessment was available at the time. Mozilla staff responded that a point-in-time readiness assessment (PITRA) is sufficient to begin issuing if the formal audit follows in a timely fashion, and explained that a formal audit of the issuance process cannot be done before issuance begins. Other commenters discussed the Mozilla wiki guidance that a CA may use a point-in-time readiness assessment before a full audit, and debated what “timely fashion” means, including references to completing a full audit within a specified period after issuing the first publicly trusted certificate. Later comments indicated that the audit had been finished, providing links to WebTrust reports for BR and CA and a community post about the completed audits. The bug was resolved with resolution set to INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 11:59 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.86 8 comments
Chronology
  1. Bug opened requesting distrust/removal of an ISRG subordinate certificate until the CA is compliant with Mozilla policies due to missing formal audit evidence.
  2. Thread notes that the relevant WebTrust audit documents were available, indicating the audit had been completed.
Thread Activity
  1. Psw representative — The submitter argued that Mozilla requires a publicly disclosed and audited not technically constrained subordinate CA, and said only a readiness assessment existed while a formal audit was still missing.
  2. Mozilla representative — Mozilla staff stated that a PITRA is sufficient to begin issuing if the formal audit follows timely, and that a formal audit of issuance cannot occur before issuance starts.
  3. Psw representative — The submitter asked what timeframe qualifies as “timely fashion” and referenced a beta phase for evidence of the issuance process.
  4. Ipv representative — A commenter cited Mozilla wiki guidance that a first BR audit may be a point-in-time audit and suggested the CA may have up to a year for a full audit.
  5. Startcom representative — Another commenter quoted a requirement that a point-in-time readiness assessment must be completed before issuing publicly trusted certificates and that a complete audit must follow within 90 days of issuing the first publicly trusted certificate.
  6. Community commenter — A commenter noted the first issued certificate was valid for 90 days and that there were days remaining to complete the audit before expiry.
  7. Opayq representative — The commenter provided links to WebTrust audit documents and a community post stating the audits were finished.
Participants
Psw representative Mozilla representative Ipv representative Startcom representative Community commenter Opayq representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1341718 RESOLVED Ca Documents Opened 2017-02-22 · Closed 2022-12-08 · 52% similar
ISRG / Let's Encrypt WebTrust audits
#1204656 RESOLVED Root Inclusion Opened 2015-09-14 · Closed 2022-11-14 · 47% similar
Add ISRG / Let's Encrypt root certificate
#1441413 RESOLVED Audit Document Opened 2018-02-27 · Closed 2022-12-08 · 45% similar
Audit documents for ISRG / Let's Encrypt
#1802059 RESOLVED Audit Related Opened 2022-11-23 · Closed 2022-11-29 · 44% similar
Let's Encrypt 2022 WebTrust Audit Documents
#1863635 RESOLVED Audit Document Opened 2023-11-07 · Closed 2025-11-10 · 42% similar
Let's Encrypt Draft WebTrust Audit Documents
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 39% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 39% similar
Let's Encrypt: CAA Misissuances
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 39% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action