DarkMatter root certificate inclusion request
This case is a request by DarkMatter LLC to add four root certificates to Mozilla/NSS: DarkMatter Root CA G3, DarkMatter Root CA G4, UAE Global Root CA G3, and UAE Global Root CA G4. DarkMatter opened the bug and provided root certificate details, CA information, audit materials, and a BR self-assessment. Mozilla reviewed the submission and identified several items needing clarification or correction, including BR section 2.2 test websites chaining to each requested root, CP/CPS clarity on CAA handling, certificate validity periods, private key escrow language, possible .ae constraints, and future audit statement content. During the discussion, participants also raised a separate misissuance involving two certificates issued by DarkMatter under a QuoVadis root, and Mozilla staff said that issue should be handled in a separate incident bug. A substantial part of this thread focused on whether DarkMatter had provided the required valid, revoked, and expired interoperability certificates chaining to each submitted root, with DarkMatter later stating it had created issuing CAs and updated the interoperability certificates for all four roots. The bug remained under review with Mozilla still requesting updated CPS information and clarification of the term "Bridge CA" in the CP/CPS. The case is now closed with resolution WONTFIX.
- DarkMatter requested inclusion of four root certificates in NSS/Mozilla products.
- DarkMatter submitted a corrected CA information document and a BR self-assessment.
- Mozilla posted a verification summary identifying outstanding issues, including BR section 2.2 test websites and CP/CPS clarifications.
- Two non-compliant certificates issued by DarkMatter under a QuoVadis subordinate CA were reported and DarkMatter said they were revoked and replaced.
- DarkMatter said it would create issuing CAs and the required valid, revoked, and expired interoperability certificates for each submitted root.
- DarkMatter said it had updated the interoperability certificates for all four submitted roots.
- Mozilla requested clarification of the term "Bridge CA" in the CP and CPS.
- DarkMatter LLC — Opened the bug requesting addition of four DarkMatter/UAE root certificates to NSS and Mozilla products.
- DarkMatter LLC — Attached the completed root inclusion template, WebTrust assertions and auditor report, and a self-audit checklist.
- Mozilla representative — Said the BR self-assessment might still be needed and linked Mozilla's information checklist.
- DarkMatter LLC — Uploaded a corrected CA information document and attached the BR self-assessment in the requested format.
- Mozilla representative — Attached a verification summary highlighting unresolved issues including CAA documentation, section 2.2 test sites, validity periods, escrow language, possible .ae constraints, and audit statement requirements.
- DarkMatter LLC — Responded point-by-point to Mozilla's listed issues and explained DarkMatter's SOP and CPS update approach.
- DarkMatter LLC — Provided repository and test-site URLs for valid, revoked, and expired certificates and asked what test output Mozilla wanted.
- Mozilla representative — Said the provided test websites did not meet BR section 2.2 because the certificates did not chain to the corresponding requested roots, and asked for future CP/CPS updates.
- DarkMatter LLC — Uploaded multiple addendum attachments related to Mozilla verification and test results.
- Mozilla representative — Said Mozilla only needed confirmation that each test website certificate chained to the corresponding root and that errors had been resolved.
- Sectigo — Reported two certificates whose Subject CN was not also present in SAN:dNSName and linked crt.sh records.
- Quovadis representative — Said QuoVadis had identified the certificates in linting, informed DarkMatter, and that the certificates would be revoked.
- DarkMatter LLC — Said DarkMatter had mis-issued two certificates, revoked them about 9.5 hours earlier, replaced them, and planned remediation including retraining and automated linting.
- Community commenter — Said the misissuance should probably be handled in a separate bug with a full incident report.
- Rossde representative — Suggested deferring public review until corrective actions were implemented, documented in CP/CPS, and verified by outside audit.
- DarkMatter LLC — Asked about CT log account expectations for interoperability certificates and future issuance.
- Community commenter — Replied that CT log questions should be taken to log operators and said Mozilla policy did not require the recommendations being requested.
- Sectigo — Suggested public non-browser-policy CT logs for testing and provided two references.
- DarkMatter LLC — Explained that DarkMatter's SOPs required successful CT log submission before issuance and described this as a difficulty for requested interoperability certificates chaining to the submitted roots.
- Community commenter — Said the current approach did not meet BR section 2.2 and that DarkMatter had designed a policy creating extra work for itself.
- DarkMatter LLC — Argued that the submitted roots were not yet publicly trusted and therefore the BR section 2.2 requirement did not yet apply in the way Ryan described.
- Community commenter — Disagreed with DarkMatter's interpretation, said certificates from the root were publicly trusted for BR purposes, and asked DarkMatter to demonstrate the required section 2.2 certificates.
- DarkMatter LLC — Said DarkMatter would create issuing CAs under each submitted root, create the three required interoperability certificates for each root, and update the web pages.
- DarkMatter LLC — Acknowledged that DarkMatter lacked correctly chained interoperability certificates from BR section 2.2 and said this would be rectified that week.
- DarkMatter LLC — Said DarkMatter had updated the interoperability certificates for all four submitted roots and that Mozilla was now waiting for an updated CPS.
- Mozilla representative — Asked DarkMatter to explain the term "Bridge CA" as used in the CP and CPS.