Add SHA256 Santander Digital Signature Firmaprofesional SubCAs to OneCRL
The bug requests adding SHA-256 Santander Digital Signature Firmaprofesional SubCAs to OneCRL, referencing an earlier incident report (bug 1464359) and another related bug (1455119). The requester provided details for the intermediate certificate, including its issuer commonName and the SHA-256 fingerprint. Kathleen Wilson stated that the request should be closed as WONTFIX because adding the certificate to OneCRL would not help for TLS/SSL trust: OneCRL is only used by Firefox for TLS/SSL, and the certificate lacks id-kp-serverAuth and does not have the required EKU. She also explained that, per Mozilla’s Root Store Policy section 5.3.1, the certificate is no longer considered technically constrained and therefore would need to be added to CCADB and audited instead. The CA representative agreed to withdraw activity and stated that the CA certificate would be revoked within June. Kathleen asked that, once revocation occurs and the corresponding CRL is updated, the “Revocation Status” field in the corresponding CCADB record be updated, and that no further bug updates or separate bug filing were needed.
- A CA Program bug was filed requesting OneCRL inclusion for specific Santander Digital Signature Firmaprofesional SubCAs.
- The CA representative indicated the CA certificate would be revoked within June.
- Isigma representative — Filed the request to add the Santander Digital Signature SHA-256 intermediate certificate to OneCRL, linking it to bug 1464359 and bug 1455119 and providing certificate identifiers and the SHA-256 fingerprint.
- Softvision representative — Noted that requests for inclusion in the default certificate store belong to the NSS: CA Certificate Root Program component.
- Mozilla representative — Recommended closing as WONTFIX, stating OneCRL is only for Firefox TLS/SSL and the certificate’s EKU does not make it trusted for TLS/SSL; she also explained the technical-constrained policy implications and that CCADB/auditing would be required instead.
- Isigma representative — Acknowledged the guidance and stated the CA is withdrawing its activity, with the CA certificate to be revoked within June.
- Mozilla representative — Asked that after revocation and CRL update, the CCADB record’s “Revocation Status” be updated, and said no further bug update or separate bug filing is needed.