← Internet Security Research Group cases
Bugzilla #1230797
Policy Compliance
Distrust ISRG Subordinate Certificate and Remove It Until the CA is Compliant with Mozilla Policies
RESOLVED
Internet Security Research Group
AI Summary
The case addresses the distrust of the ISRG subordinate certificate due to non-compliance with Mozilla's CA Certificate Inclusion Policy. A formal audit was missing, although a readiness assessment was announced. The discussion highlights the timeline for audits and the requirements for issuing certificates. Ultimately, the case was resolved with the decision to distrust the certificate until compliance is achieved.
Chronology
- Initial report of distrust due to audit issues
- Case resolved
Participants
Christian Heutger
Kathleen Wilson
Gervase Markham
Eddy Nigg
External References
Similar Local Cases
SwissSign: BRs require full annual audits
SHA-1 issuance by GlobalSign root
Izenpe: Non-BR-Compliant Certificate Issuance
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
SwissSign: Non-BR-Compliant Certificate Issuance
Verify GlobalSign's continued conformance to EV guidelines
Firmaprofesional: Insufficient Audit Statements
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance