WoSign: Action Items
This case involves WoSign CA Limited's proactive disclosure of compliance failures related to their root certificates. Following a prior bug report, WoSign was informed that new certificates issued after October 21, 2016, would not be trusted in Mozilla products. The CA outlined a series of action items to rectify these issues, including implementing changes to their processes and obtaining external audits. As of the last update, WoSign had completed a security audit by Cure53 and was preparing for further compliance audits. The case is currently resolved but remains under monitoring for WoSign's future compliance.
- WoSign CA Limited disclosed compliance failures and outlined action items for future trust.
- Requirements communicated to WoSign; case deemed not actionable until reapplication for inclusion.
- WoSign completed a security audit and submitted the report to Mozilla.
- Mozilla representative — Outlined the conditions under which WoSign could regain trust in Mozilla products.
- Assecods representative — Reported on the revocation of subordinate CAs issued to Certification Authority of WoSign G2.
- Mozilla representative — Confirmed that the requirements have been communicated to WoSign.
- WoSign CA Limited — Submitted the security audit report summary to Mozilla.