Add KISA RootCA 4 to Mozilla Trusted Root Store
KISA opened this bug to request inclusion of its new root certificate, KISA RootCA 4, into the Mozilla Trusted Root Store. KISA stated that it decided to use KISA RootCA 4 to issue certificates of an issuing CA for SSL, and that users saw warning messages when visiting sites using SSL certificates chaining to the untrusted root. Kathleen Wilson referenced Mozilla guidance on “Super-CAs,” noting that some signing CAs require subordinate CAs to apply for inclusion until accreditation/licensing is established and demonstrated. KISA asked whether subordinate CAs under KISA RootCA 4 would need to apply separately for inclusion of their CA certificates linked to KISA RootCA 4, and also asked whether KISA RootCA 4 would sign the subCAs currently signed by the old KISA root. The thread indicates that the subCAs were currently signed by KISA RootCA1 and RootCA4. The bug was later closed with resolution “WONTFIX,” and Kathleen Wilson stated she intended to close the inclusion request because it did not appear to be actively pursued.
- KISA requested inclusion of the KISA RootCA 4 certificate in the Mozilla Trusted Root Store.
- KISA and Mozilla discussed how subordinate CAs under KISA RootCA 4 relate to inclusion requirements and signing.
- Mozilla indicated it intended to close the inclusion request because it was not actively pursued.
- Bug status was resolved as WONTFIX.
- Kisa representative — KISA requested adding KISA RootCA 4 to the Mozilla Trusted Root Store because sites using SSL certificates chained to it produced browser warning messages.
- Mozilla representative — Kathleen Wilson pointed to Mozilla guidance on Super-CAs and subordinate CA inclusion requirements.
- Kisa representative — KISA asked whether subordinate CAs under KISA RootCA 4 must apply separately for inclusion of their CA certificates linked to KISA RootCA 4.
- Mozilla representative — Kathleen Wilson asked whether KISA RootCA 4 would sign the subCAs currently signed by the old KISA root certificate.
- Kisa representative — KISA responded that the subjects are the same and stated the subCAs are currently signed by KISA RootCA1 and RootCA4.
- Mozilla representative — Kathleen Wilson stated the request should be for inclusion of KISA RootCA1 and RootCA4 as trust anchors and referenced the wiki information checklist for direct consideration.
- Kjsman representative — A commenter raised concerns about KISA and asked KISA to confirm it would never cooperate with a government MITM attempt.
- Mozilla representative — Mozilla stated it intended to close the inclusion request bug around 1 September 2020 because it did not appear to be actively pursued.