Certigna Root CA inclusion request for Email, Websites, and code signing trust bits
Certigna (Dhimyotis) requested Mozilla inclusion of the Certigna Root CA and asked for Email, Websites, and code signing trust bits. The request began with audit and policy documents, then moved through Mozilla information verification, BR self-assessment review, and public discussion. During review, Mozilla asked for clarifications on SSL and email verification procedures, and Certigna updated its CP/CPS documents and self-assessment materials several times. Certigna also reported one DNS CAA-related certificate incident, stated that the certificate had been revoked, and said new practices were in place to block similar requests. Mozilla later approved the request for the Certigna Root CA with Email and Websites trust bits, and filed NSS bug 1505614 for the actual changes.
- Certigna submitted a root inclusion request for Certigna Root CA.
- Mozilla completed information verification for the request.
- Mozilla opened the public discussion period for the Certigna Root CA request.
- Certigna reported a DNS CAA-related incident, said the certificate was revoked, and described updated controls.
- Mozilla approved the request for Certigna Root CA with Email and Websites trust bits.
- Dhimyotis representative — Certigna opened the request and attached audit and initial information documents for the Certigna Root CA.
- Mozilla representative — Mozilla said Aaron and Francis had started information verification for the request.
- Dhimyotis representative — Certigna answered Mozilla's questions about its practices and noted that CP/CPS translation was in progress.
- Dhimyotis representative — Certigna said updated English CPs were published and that email and FQDN verification details had been added.
- Mozilla representative — Mozilla marked information verification as completed.
- Mozilla representative — Mozilla asked Certigna to perform and attach a BR self-assessment.
- Dhimyotis representative — Certigna attached its BR Self Assessment v1.2.
- Mozilla representative — Mozilla opened public discussion and said the discussion thread would be 'Certigna Root Renewal Request'.
- Dhimyotis representative — Certigna said it had audited SSL requests since September 8, found one DNS CAA failure, revoked the affected certificate, and updated its CP/CPS.
- Fastly representative — Mozilla said the discussion period had ended and recommended approval.
- Mozilla representative — Mozilla approved the request for Certigna Root CA with Email and Websites trust bits and said it would file the NSS bug for the changes.