TunTrust Root CA inclusion request for ANCE/NDCA of Tunisia
Agence Nationale de Certification Electronique (ANCE/NDCA) of Tunisia opened this case to request inclusion of its new TunTrust Root CA in Mozilla’s root store. The initial submission included audit reports, a BR self-assessment, and a description of the new PKI hierarchy and key generation ceremony. Mozilla asked for clarification about two TunTrust Root CA certificates listed in CCADB, and ANCE/NDCA explained that only the second certificate was being requested for inclusion because it omitted the digitalSignature key usage. Mozilla then reviewed the CP/CPS, requested additional fixes, and later confirmed those items were addressed. The case moved into public discussion, after which Mozilla approved the request for inclusion of TunTrust Root CA (Websites); Not EV and filed an NSS bug for the actual changes.
- ANCE/NDCA requested Mozilla inclusion of the new TunTrust Root CA.
- ANCE/NDCA clarified that only the second TunTrust Root CA certificate was requested for inclusion.
- Mozilla marked CP/CPS review items as fixed after TunTrust updated its documentation.
- The request was moved into public discussion.
- Mozilla approved inclusion of TunTrust Root CA (Websites); Not EV.
- Certification representative — ANCE/NDCA opened the bug, requested inclusion of TunTrust Root CA, and linked the CCADB case and audit reports.
- Mozilla representative — Mozilla asked why two TunTrust Root CA certificates existed and why both were being requested.
- Certification representative — ANCE/NDCA explained the difference between the two root certificates and said only Root Case Record #2 was requested for inclusion.
- Mozilla representative — Mozilla said it would remove the first instance of the root cert from CCADB to avoid confusion.
- Mozilla representative — Mozilla said the request was ready for detailed CP/CPS review and asked for WebTrust seals when available.
- Certification representative — ANCE/NDCA provided links to the WebTrust period-of-time audit reports and seals.
- Certification representative — ANCE/NDCA said it had updated the CP/CPS and attached an updated version.
- Mozilla representative — Mozilla marked several CP/CPS issues as fixed, including problem reporting, CAA checking, MFA for issuance-capable accounts, revocation timing, key-compromise notice, and CN/SAN handling.
- Mozilla representative — Mozilla moved the case into public discussion and scheduled the close of public discussion for 30-Apr-2021.
- Certification representative — ANCE/NDCA said it wanted to move forward with the inclusion request and attached a CA quantifying value document.
- Mozilla representative — Mozilla closed public discussion and stated an intent to approve the inclusion request, starting a 7-day last call.
- Mozilla representative — Mozilla approved the request to include TunTrust Root CA (Websites); Not EV and said it would file the NSS bug for the actual changes.
- Mozilla representative — Mozilla filed bug 1728394 against NSS for the actual changes.