TurkTrust: Non-audited, non-technically-constrained intermediate certs
The case concerns three TurkTrust intermediate certificates that were described as not audited and not technically constrained (including missing EKU and domain constraints) even though they chain up to a Mozilla root store root. The reporter listed the specific intermediate certificates and provided crt.sh links for each. The reporter discussed options such as including the intermediates in audits, revoking them, providing an annual audit statement, or adding them to OneCRL. The reporter later stated that Bug 1381863 had been filed per the CA’s request to add these three non-audited intermediate certificates to OneCRL even though they were not revoked. Mozilla subsequently noted that the intermediates had been added to OneCRL and that they chain to a root certificate with only the Websites trust bit enabled, so no further action was required by Mozilla for this issue. The bug was marked RESOLVED with resolution FIXED.
- A report was filed about three TurkTrust intermediate certificates that were not audited and not technically constrained despite chaining to a Mozilla root.
- The intermediates were requested to be added to OneCRL via a related bug (1381863).
- Mozilla confirmed the intermediates were added to OneCRL and that no further Mozilla action was required for this issue.
- Community commenter — Reported three TurkTrust intermediate certificates that were not audited and not technically constrained (no EKU/domain constraints) and listed crt.sh links and possible remediation options.
- Community commenter — Corrected the earlier discussion about adding certificates to OneCRL, stating it would be OK for two intermediates not intended for TLS/SSL issuance.
- Community commenter — Stated Bug 1381863 was filed per the CA’s request to add the three non-audited intermediate certificates to OneCRL even though they are not revoked.
- Community commenter — Noted that Bug 13811863 was resolved as remediation and that it was unclear what additional process/issuance-flow information Mozilla wanted.
- Community commenter — Confirmed the intermediates were added to OneCRL and that, because they chain to a root with only the Websites trust bit enabled, no further Mozilla action was required for this issue.