Hongkong Post Root CA 3 inclusion request for websites trust and EV treatment
This case was a request by Hongkong Post Certification Authority (HKPCA), operated by Certizen, to include the new root certificate "Hongkong Post Root CA 3" in Mozilla with the websites trust bit enabled and EV treatment. The request was triggered by Hongkong Post's planned rollover from its existing root, which was approaching expiry, and by its plan to separate client and SSL issuance into different PKIs. Hongkong Post provided CA information, a BR self-assessment, audit materials, and CPS documents, and later published a pre-production CPS and an EV SSL WebTrust report. Mozilla reviewers asked for clarifications and updates to the CPS, including revocation reasons, suspension language, external RA/domain validation language, and EV audit timing. After public discussion and a recommendation to approve, Mozilla approved the request and filed follow-up NSS and PSM bugs for the actual changes.
- Hongkong Post requested inclusion of the new root certificate Hongkong Post Root CA 3 for websites and EV use.
- Mozilla began the public discussion of the root inclusion request.
- Mozilla approved inclusion of Hongkong Post Root CA 3 with websites trust and EV treatment.
- Certizen representative — Hongkong Post opened the request and explained the planned rollover from Root CA 1 to Root CA 2 and Root CA 3.
- Mozilla representative — Mozilla acknowledged receipt and said the request was added to the review queue.
- Mozilla representative — Mozilla asked whether the request covered two new roots or only Root CA 3.
- Certizen representative — Hongkong Post clarified that the request only included Root CA 3 for website trust and EV treatment.
- Fastly representative — Wayne Thayer began review and raised questions about the EV audit, CPS publication, external RAs, suspension, and revocation reasons.
- Certizen representative — Hongkong Post responded to the review questions and said it would update the CPS.
- Fastly representative — Wayne Thayer said a period-of-time EV audit should be obtained and would not delay public discussion for that issue.
- Fastly representative — Wayne Thayer said the draft CPS still lacked all required revocation reasons and asked why Hongkong Post could not publish it.
- Certizen representative — Hongkong Post said it had published a pre-production CPS and provided a period-of-time WebTrust EV SSL report.
- Fastly representative — Wayne Thayer started the public discussion on mozilla.dev.security.policy and summarized the request and review findings.
- Fastly representative — Wayne Thayer recommended approval of the inclusion request.
- Mozilla representative — Mozilla approved the request and said NSS and PSM bugs would be filed for the changes.