e-Guven version 1 certificate
The case concerns an e-Guven “version 1” certificate. The reporter provided a crt.sh link to the certificate and asked whether Mozilla should be informed about other potential problems with that root. Kathleen Wilson stated that the E-Guven root certificate had already been removed via Bug #1145270 in NSS 3.18.1 / Firefox 38, and that Mozilla did not need to take further action, so the bug should be closed as “wontfix.” She also noted that other root store operators had been notified. The reporter later asked whether additional issues should be reported and referenced another crt.sh result that appeared to claim a policy OID and contained placeholder text. An e-Guven representative replied that they had conveyed audit results from ETSI in 2015, that the audit was held again in 2016 (with a link), and that non-compliance was determined after the audit related to their RSA system upgrade, stating they had taken technical measures and informed staff.
- A bug was filed regarding an e-Guven version 1 certificate.
- Mozilla indicated the e-Guven root had already been removed via a prior bug and marked the current case for wontfix closure.
- The reporter asked whether additional issues with the root should be reported and shared another crt.sh example.
- An e-Guven representative responded with audit-related context and stated technical measures were taken.
- Roeckx representative — Provided a crt.sh link and noted the certificate is a version 1 certificate.
- Mozilla representative — Said the E-Guven root cert was removed via Bug #1145270 in NSS 3.18.1 / Firefox 38, and closed the bug as wontfix because Mozilla needed no further action; noted other root store operators were notified.
- Roeckx representative — Asked whether other problems with that root should be reported and shared a crt.sh link showing a claimed policy OID and placeholder text.
- E-guven representative — Responded that they conveyed ETSI audit results (2015) and that an audit was held again in 2016 (linked), with non-compliance determined after the audit related to an RSA system upgrade; stated technical measures were taken and staff were informed.