IdenTrust - Updated 2016 WebTrust Reports
This case concerns IdenTrust submitting updated WebTrust audit reports for its Mozilla-included root CAs. The bug was opened by IdenTrust (r**********s@identrust.com) stating that IdenTrust completed its WebTrust audit and that auditors have complete reports. The roots listed as audited and in the Mozilla program are DST ACES CA X6, DST Root CA X3, IdenTrust Public Sector Root CA 1, and IdenTrust Commercial Root CA 1, with links to WebTrust for CA version 2.0 and WebTrust for Baseline Requirements. Mozilla staff asked whether issues referenced in another bug (1037590#c22 and #c23) should have been called out in this audit report. IdenTrust’s assigned contact responded that it was not clear what subCAs were audited and suggested that expectations should be set via the CA/Browser Forum for audit statements to clearly identify which root and intermediate certificates were covered. The assigned contact also updated the Common CA Database with the 2016 audit information. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust submitted updated 2016 WebTrust audit report information for its Mozilla-included root CAs.
- Mozilla questioned whether previously noted issues should have been reflected in the submitted audit report.
- IdenTrust clarified concerns about which subCAs were covered and updated CA Community/CCADB with the 2016 audit info.
- IdenTrust Services, LLC — Opened the bug stating IdenTrust completed its WebTrust audit and provided links, listing the audited roots in the Mozilla program.
- Community commenter — Asked whether the issues from bug 1037590#c22 and #c23 should have been called out in this audit report.
- Mozilla representative — Responded that it was unclear what subCAs were audited and proposed setting CA/Browser Forum expectations for audit statements to identify covered roots and intermediates.
- Mozilla representative — Stated that the Common CA Database (CA Community in Salesforce) was updated with the 2016 audit information.