← SI-TRUST cases
Bugzilla #1583464 Root Inclusion Incident

Add SI-TRUST root certificate

RESOLVED WONTFIX SI-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a root inclusion request to add the “SI-TRUST Root” certificate (CN=SI-TRUST Root; O=Republika Slovenija; C=SI) to Mozilla’s root program. The request was reviewed against Mozilla Root Store Policy and the CA/B Forum Baseline Requirements, and the reviewer asked the CA to provide specific audit statements and BR-related audit statements, English translations of CP/CPS, and to resolve multiple revocation and linting errors. The CA responded with updated audit statement URLs, explanations for revocation-check findings (including CRL/OCSP behavior), and additional details about audit standards and CP/CPS translations, and it stated it would correct the remaining non-conformity related to keeping an email as an additional Subject Alternate Name. The reviewer identified show-stopper problems and denied inclusion, citing continued issuance of non-BR-compliant TLS certificates and a lack of awareness of revocation requirements, as well as intermediate certificates capable of issuing TLS certificates that were not audited according to the required audit criteria. The bug was closed by the reviewer with the decision to deny this root inclusion request, and the CA was invited to re-apply with a new root certificate and hierarchy that is fully compliant from creation. The bug resolution is listed as WONTFIX.

Model: gpt-5.4-nano Generated: 2026-06-13 20:00 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 7 comments
Chronology
  1. Aleš Pelan opened a Mozilla CA Program bug to request inclusion of the SI-TRUST root certificate.
  2. Mozilla’s root program reviewer requested additional information and specific compliance items for the SI-TRUST root inclusion request.
  3. SI-TRUST provided responses, including updated audit statement URLs and explanations for revocation-check and linting findings.
  4. Mozilla’s root program reviewer denied the SI-TRUST root inclusion request due to show-stopper compliance issues and indicated the corresponding root inclusion case would be closed.
  5. SI-TRUST reiterated that the remaining non-conformity would be corrected and provided additional explanation about intermediate certificate auditing.
  6. Mozilla’s reviewer closed the denial decision, citing unresolved BR commitment concerns and intermediate certificate constraint enforcement issues.
Thread Activity
  1. Community commenter — Kathleen Wilson said the CA update backlog would delay review and that she would add another comment after performing the review.
  2. Community commenter — Kathleen Wilson provided a verified-information link and requested specific clarifications, including audit statements, BR audit statement, English CP/CPS translations, and resolution of revocation and lint errors.
  3. Gov representative — Aleš Pelan provided explanations and updated audit statement URLs, addressed revocation-check items, and described how certain lint findings were interpreted.
  4. Community commenter — Kathleen Wilson stated there were two show-stopper problems (non-BR-compliant TLS issuance with revocation-awareness concerns, and intermediate certificates not audited to required criteria) and denied inclusion, closing the corresponding root inclusion case and inviting re-application with a compliant new hierarchy.
  5. Gov representative — Aleš Pelan responded that the remaining non-conformity (email in additional SAN) would be corrected and discussed why certain intermediate certs were not audited to ETSI EN 319 411-2 QCP-w.
  6. Community commenter — Kathleen Wilson reiterated the denial, stating the CP/CPS lacked a required BR commitment to comply and explaining why intermediate-certificate intended usage cannot replace technical constraints like EKU.
Participants
Gov representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390803 RESOLVED Root Inclusion Ev Enablement Incident Opened 2017-08-16 · Closed 2022-11-14 · 71% similar
Add "GlobalSign Root CA - R6" root certificate
#1427262 RESOLVED Ca Certificate Root Program Root Inclusion Audit Document Self Assessment Opened 2017-12-28 · Closed 2022-11-14 · 68% similar
Add DarkMatter Root Certificates
#1381406 RESOLVED Root Inclusion Opened 2017-07-17 · Closed 2022-11-14 · 67% similar
Add StartCom CA root certificates
#1695487 RESOLVED Root Inclusion Opened 2021-02-28 · Closed 2022-11-14 · 67% similar
Add HARICA 2021 TLS Root CA Certificates to Mozilla Root store program
#1435691 RESOLVED Root Inclusion Opened 2018-02-05 · Closed 2022-11-14 · 65% similar
Add "BYTE Root Certification Authority" root certificate to NSS
#854384 RESOLVED Root Inclusion Opened 2013-03-25 · Closed 2022-11-14 · 62% similar
E-Guven S2 and S3 Root inclusion to Mozilla browser
#1479040 RESOLVED Root Inclusion Ca Certificate Root Program Opened 2018-07-27 · Closed 2024-12-03 · 62% similar
CERTISIGN ROOT CERTIFICATE AUTHORITY REQUEST
#1040072 RESOLVED Root Inclusion Opened 2014-07-17 · Closed 2022-11-14 · 61% similar
Add MULTICERT Root Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action