NAVER Cloud Trust Services root inclusion request for NAVER Global Root Certification Authority
This case was NAVER Business Platform’s request to have its root certificate included in Mozilla’s root store. The request began with NAVER saying it had established a Root CA for issuing SSL certificates and wanted inclusion under Mozilla Root Store Policy. Mozilla asked for the CA information checklist, CPS, and later a BR self-assessment, and then performed detailed CP/CPS review and follow-up checks. During review, Mozilla raised questions about CPS clarity, domain validation, revocation, CRL/OCSP behavior, audit timing, and test-site errors; NAVER responded by revising its CPS multiple times and addressing the requested items. Mozilla later said the changes looked good, opened public discussion, and after that discussion concluded, approved inclusion of the NAVER Global Root Certification Authority for websites trust bit enablement. The bug was resolved as FIXED.
- NAVER Business Platform requested Mozilla root inclusion for its Root CA.
- Mozilla moved the request into detailed CP/CPS review.
- Public discussion began for the root inclusion request.
- Mozilla approved inclusion of the NAVER Global Root Certification Authority for websites.
- Navercorp representative — NAVER said it had established a Root CA for SSL certificates and was applying for Mozilla root inclusion.
- Mozilla representative — Mozilla asked why NAVER should be directly included rather than cross-signed and requested the CA information checklist.
- Mozilla representative — Mozilla attached verified CA information and listed multiple CPS and testing issues needing clarification or further work.
- Navercorp representative — NAVER said it had revised its English CPS and that the relevant CRL issue had been fixed.
- Mozilla representative — Mozilla said the request was ready for detailed CP/CPS review and assigned it onward.
- Navercorp representative — NAVER said it had added one intermediate certificate record, explained the audit timing, and said two non-compliant certificates had been immediately revoked.
- Community commenter — Ryan posted an initial CP/CPS review and said more documentation was needed.
- Mozilla representative — Ben posted additional CP/CPS review comments, including wording and process issues.
- Navercorp representative — NAVER uploaded CPS v1.4.2 and responded to the second review comments.
- Mozilla representative — Ben asked NAVER to look into CRL provisioning errors.
- Navercorp representative — NAVER said it would replace the OCSP responder certificate with one valid for 90 days.
- Mozilla representative — Mozilla said the changes looked very good and that it would prepare the inclusion application for public discussion.
- Mozilla representative — Mozilla approved the request to include the NAVER Global Root Certification Authority for websites.