← IdenTrust Services, LLC cases
Bugzilla #1339292 Ev Enablement

IdenTrust request to enable EV for Identrust Commercial Root CA 1 was reviewed and closed

RESOLVED WONTFIX IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was an IdenTrust request to enable EV treatment for the "IdenTrust Commercial Root CA 1" root certificate. The request was opened by IdenTrust after it attached EV checker results and audit materials, and Mozilla asked for a CA information verification review and a BR self-assessment. During review, Mozilla raised questions about the CA hierarchy, audit scope, CPS language, and whether the Booz Allen Hamilton BA CA 01 intermediate was properly covered. IdenTrust provided clarifications, updated its CPS, and supplied additional audit statements and self-assessment attachments. In public discussion, Wayne Thayer noted remaining concerns, including a liability-limit issue and a reported .INT domain certificate in bug 1500593, and recommended denial. Mozilla then closed the request to enable EV treatment and stated that IdenTrust could re-apply with a new request.

Model: gpt-5.4-mini Generated: 2026-06-13 14:11 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.93 34 comments
Chronology
  1. IdenTrust requested EV treatment for the Identrust Commercial Root CA 1 root certificate.
  2. Mozilla moved the request into detailed CP/CPS review.
  3. Public discussion began on the EV-enablement request.
  4. Mozilla closed the request to enable EV treatment for the root certificate.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust opened the bug, attached EV checker test results and an EV SSL audit report, and pointed to the original inclusion request and CP/CPS URLs.
  2. Mozilla representative — Aaron requested responses to Mozilla's recommended practices and problematic practices questions.
  3. Mozilla representative — Aaron asked IdenTrust to complete a BR self-assessment and attach it to the bug.
  4. IdenTrust Services, LLC — IdenTrust attached a self-assessment for the IdenTrust Commercial Root CA A1 to resume SSL/TLS EV certificates.
  5. Mozilla representative — Kathleen Wilson attached a status document and asked for clarification on the CA hierarchy, cross-certification, and delegated third parties.
  6. IdenTrust Services, LLC — IdenTrust said it would review the feedback and provide the required clarifications.
  7. Mozilla representative — Kathleen Wilson said the request was ready for the Detailed CP/CPS Review phase and assigned it to Wayne.
  8. Fastly representative — Wayne Thayer raised questions about prior audit statements, CPS domain validation language, and EV audit scope for the Booz Allen Hamilton BA CA 01 intermediate.
  9. IdenTrust Services, LLC — IdenTrust said it would review and respond, then provided prior audit reports and said it would update the CPS.
  10. Fastly representative — Wayne asked for the CPS link and for 2013-2014 audit statements because the root was created in January 2014.
  11. IdenTrust Services, LLC — IdenTrust provided the CPS link and said the 2013-2014 WebTrust audit reports had been added.
  12. Fastly representative — Wayne started public discussion and listed his assessment, including concerns about audit scope, CPS language, and several compliance issues.
  13. IdenTrust Services, LLC — IdenTrust replied to Wayne's comments and agreed to update CPS language on domain validation, CPS update timing, and a typo.
  14. Fastly representative — Wayne said most CPS concerns were addressed in the newer version but asked for an explanation of the section 9.8 liability language.
  15. Fastly representative — Wayne recommended denying the request due to bug 1500593 and linked the public discussion.
  16. IdenTrust Services, LLC — IdenTrust proposed revised liability wording for CP section 9.8.
  17. Mozilla representative — Kathleen Wilson closed the request and said IdenTrust could re-apply by creating a new request.
Participants
IdenTrust Services, LLC Mozilla representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1165472 RESOLVED Ev Enablement Opened 2015-05-15 · Closed 2022-11-14 · 86% similar
EV-Enable DigiCert Assured ID Root CA and DigiCert Global Root CA
#1551703 RESOLVED Ev Enablement Opened 2019-05-14 · Closed 2022-11-14 · 76% similar
Enable EV for the "IdenTrust Commercial Root CA 1"
#794036 RESOLVED Ev Enablement Opened 2012-09-25 · Closed 2022-11-14 · 71% similar
Enable EV for Firmaprofesional
#1277336 RESOLVED Root Inclusion Trust Bit Enablement Ev Enablement Opened 2016-06-01 · Closed 2022-11-14 · 66% similar
Add SSL.com root certificate(s)
#1390803 RESOLVED Root Inclusion Ev Enablement Incident Opened 2017-08-16 · Closed 2022-11-14 · 58% similar
Add "GlobalSign Root CA - R6" root certificate
#403644 RESOLVED Ev Enablement Opened 2007-11-13 · Closed 2022-11-14 · 57% similar
Request for CA Root Certificate be enabled for EV (DigiCert High Assurance EV Root CA)
#986854 RESOLVED Root Inclusion Opened 2014-03-22 · Closed 2022-11-14 · 52% similar
Add Renewed AC Camerfirma root certificate.
#403915 RESOLVED Root Inclusion Ev Enablement Opened 2007-11-15 · Closed 2022-11-14 · 50% similar
Add Network Solutions EV root cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action