National Certification Authority of Sri Lanka root inclusion request closed after long-delayed application was abandoned
This case was an application to add the National Certification Authority of Sri Lanka root certificates to Mozilla. Sri Lanka CERT opened the bug in May 2019 asking what steps were needed to embed its root certificate in Mozilla browsers, and Mozilla directed them to the root inclusion process and CCADB access. Over time, the thread focused on the applicant’s audit progress, CCADB case setup, and a correction to the SHA256 hash in the point-in-time audit reports from the PEM version to the DER version. Mozilla also asked for updates on the audit and whether the applicant still intended to pursue inclusion. In January 2024, the applicant asked to close the ticket because a new root CA was being set up for the requirement, and the bug was resolved INVALID.
- Sri Lanka CERT opened a request to include the National Certification Authority of Sri Lanka root certificates in Mozilla.
- The applicant said the point-in-time audit was completed and CCADB access had been requested.
- Updated point-in-time audit reports were attached with the DER SHA256 hash.
- The applicant asked Mozilla to close the ticket because a new root CA was being set up.
- Cert representative — Priyankara Perera said Sri Lanka CERT was setting up the National Certification Authority of Sri Lanka and wanted to know how to get the root certificate embedded in Mozilla browsers.
- Mozilla representative — Mozilla pointed the applicant to the CA application process, CCADB access, and instructions for creating a root inclusion case.
- Mozilla representative — Ben Wilson asked for an update on the root and audit status.
- Cert representative — The applicant said root key generation had been completed on 2020-02-14 and asked to keep the ticket open while the WebTrust seal was still pending.
- Mozilla representative — Ben Wilson asked about a SHA256 hash mismatch between the audit report and the certificate downloaded from the NCA website.
- Cert representative — The applicant explained that the audit report had used the PEM version of the root certificate while the website hosted the DER version.
- Cert representative — The applicant attached updated point-in-time reports containing the SHA256 hash of the DER version.
- Cert representative — The applicant said a POT audit was in progress and that they would open a Bugzilla ticket to explain the delay with the auditor's help.
- Cert representative — The applicant asked to close the ticket because a new root CA was being set up for the requirement.