SECOM request to add two new root certificates for email and website trust
SECOM Trust Systems opened this case to request inclusion of two new root certificates: Security Communication RootCA3 and Security Communication ECC RootCA1. The request included CA details, audit information, CP/CPS links, and later English translations and test websites for valid, revoked, and expired certificate chains. Mozilla reviewers asked for additional information, including BR self-assessment materials, CP/CPS updates, and corrections to test-site and policy details, and SECOM provided multiple follow-up responses and updated repositories. In 2021 and 2022, Mozilla continued reviewing the PKI hierarchy and CP/CPS compliance, and SECOM confirmed that some subordinate CA certificates were already revoked and that there were no externally operated CAs under these roots. On 2022-08-15, Mozilla recommended approval for inclusion with website and email trust bits and no EV, and on 2022-08-17 Mozilla approved the request; bug 1785297 was then filed in NSS for the actual changes.
- SECOM requested inclusion of Security Communication RootCA3 and Security Communication ECC RootCA1.
- SECOM provided valid, revoked, and expired test websites for both roots.
- SECOM said the test websites including OCSP setup had been finished.
- SECOM confirmed the subordinate CA information was accurate and said there were no externally operated CAs under the roots.
- Mozilla approved inclusion of the two SECOM roots for email and website trust.
- Secom representative — SECOM opened the bug with CA and certificate details for the requested root certificates.
- Mozilla representative — Mozilla asked whether the bug would be used for a root inclusion/change request.
- Mozilla representative — Mozilla noted by email that the bug would be used to request inclusion of two new root certificates.
- Mozilla representative — Mozilla requested responses to recommended-practices and problematic-practices items.
- Mozilla representative — Mozilla asked SECOM to perform the BR self-assessment and attach the resulting document.
- Mozilla representative — Mozilla said it could not continue information verification until updated CP/CPS, BR self-assessment, and English translations were provided.
- Mozilla representative — Mozilla reported errors in the test websites, including expired intermediate and leaf certificates and a key-usage issue on one site.
- Mozilla representative — Mozilla asked SECOM to review and update the PKI Hierarchy section for each root.
- Mozilla representative — Mozilla posted a detailed CP/CPS compliance review for SECOM documents.
- Mozilla representative — Mozilla recommended approval of the SECOM roots for inclusion with website and email trust bits, no EV.
- Mozilla representative — Mozilla approved inclusion of Security Communication RootCA3 and Security Communication ECC RootCA1.
- Mozilla representative — Mozilla filed bug 1785297 in NSS for the actual changes.