Certisign root certificate inclusion request and CP/CPS review
Certisign requested to operate as a Root CA under the Mozilla Root Program. The request was opened by Certisign staff and then moved through Mozilla’s root inclusion review process, including verification of CP/CPS documents, audit statements, test websites, OCSP behavior, and CCADB data. Mozilla asked Certisign to clarify several policy and operational items, including audit evidence, SHA-1 language, CAA domains, email control verification, and revocation/OCSP test failures. Certisign responded with updated documents, WebTrust seal links, re-issued test certificates, and explanations for the OCSP and cache-related errors. By May 2019, Mozilla noted that intermediate certificate data had been entered into CCADB and that EV testing passed, but some revocation and certificate policy issues still needed resolution or explanation. In April 2020, Mozilla began a detailed CP/CPS review of updated documents, and in late 2020 and early 2021 Mozilla noted the request had been inactive for months and warned it might be closed.
- Certisign requested root CA inclusion under the Mozilla Root Program.
- Mozilla reviewed Certisign CP/CPS documents, audit statements, and test website materials.
- Certisign replied to Mozilla’s requested clarifications and provided answers and updated materials.
- Certisign re-issued test website certificates to address a certificate policy lint error.
- Mozilla started a detailed CP/CPS review of updated Certisign policy documents.
- Mozilla asked Certisign to respond or the inclusion request would be closed.
- Certisign representative — Certisign opened the root inclusion request and described its CA history and market presence.
- Mozilla representative — Mozilla acknowledged receipt and said the request was added to the review queue.
- Mozilla representative — Mozilla asked for clarifications on CP/CPS scope, email trust-bit verification, CAA domains, and audit statements, and requested updated test website setup.
- Certisign representative — Certisign said it had attached answers and was waiting for period-of-time audit reports before responding.
- Mozilla representative — Mozilla linked the verified CA information and listed remaining needs, including WebTrust seal URLs, OCSP fixes, and lint issues.
- Certisign representative — Certisign answered Mozilla’s requests, including contact information, WebTrust seal links, policy updates, and CCADB/intermediate-certificate discussion.
- Mozilla representative — Mozilla said the intermediate certificate data had been entered into CCADB, EV testing passed, and some revocation and lint issues still needed resolution.
- Certisign representative — Certisign said it had re-issued the test website certificates to correct the policy lint error and explained the revocation timing issues.
- Certisign representative — Certisign said it had identified an internal error and asked Mozilla to check again.
- Mozilla representative — Mozilla said the request was ready for the detailed CP/CPS review phase and assigned it onward.
- Mozilla representative — Mozilla posted a detailed CP/CPS review with numerous document comments and requested updates.
- Certisign representative — Certisign said it was changing the requested information.
- Mozilla representative — Mozilla noted the CPS was nearly two years old, the last audit was over two years old, and inactivity suggested the request might be closed.
- Mozilla representative — Mozilla asked Certisign to respond or the inclusion request would be closed around 2021-03-05.