Microsec request to include the e-Szigno Root CA 2017 root and enable websites/email trust bits
Microsec requested Mozilla inclusion of its new ECC root, "e-Szigno Root CA 2017," and asked that it be added to the Mozilla root program and CCADB. The request also expanded to EV treatment for both the new root and the existing root, and Mozilla reviewers asked for checklist information, BR self-assessment material, audit statements, CAA details, revocation-check fixes, EV test results, and CCADB intermediate records. Microsec provided audit letters, self-assessment files, checklist information, updated public CP/CPS documents, and explanations or fixes for the issues raised. Mozilla later clarified that approval would cover inclusion of the 2017 root with websites and email trust bits, but not EV treatment. On 2020-06-11, Mozilla approved inclusion of the e-Szigno Root CA 2017 certificate with Email and Websites trust bits, and noted that an NSS bug would be filed for the change.
- Microsec requested inclusion of the new ECC root certificate e-Szigno Root CA 2017.
- Mozilla requested checklist information, BR self-assessment material, and other review items before detailed review.
- Microsec reported fixes to revocation-check issues and updated OCSP responder behavior.
- Mozilla said the request was ready for the Detailed CP/CPS Review phase.
- Mozilla approved inclusion of e-Szigno Root CA 2017 with Email and Websites trust bits.
- Microsec representative — Microsec opened the request and asked Mozilla to include the new e-Szigno Root CA 2017 certificate in the root program and CCADB.
- Mozilla representative — Mozilla acknowledged the request and asked Microsec to provide checklist information and a BR self-assessment.
- Mozilla representative — Mozilla listed remaining items, including audit URLs, CAA domain information, revocation-check errors, EV testing, CCADB intermediate records, and lint explanations.
- Microsec representative — Microsec said it had resolved the revocation-check problems and updated root OCSP responders to include NextUpdate.
- Microsec representative — Microsec explained several lint findings as applying to OCSP responder, timestamping, or other non-TLS certificates, and said it would modify TLS certificate profiles to include the CABF policy OID.
- Mozilla representative — Mozilla said the request was ready for the Detailed CP/CPS Review phase and assigned it onward.
- Mozilla representative — Mozilla said the discussion period had ended and recommended approval of the inclusion request, while recommending denial of EV treatment.
- Mozilla representative — Mozilla approved inclusion of the e-Szigno Root CA 2017 certificate with Email and Websites trust bits and said an NSS bug would be filed.