← PostSignum cases
Bugzilla #1602415 Ca Certificate Root Program Root Inclusion Information Request Remediation Tracking Opened By Ca

PostSignum request to add Root QCA 4 and Root QCA ECC R1, with ongoing Mozilla review of inclusion prerequisites

ASSIGNED PostSignum
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is PostSignum’s request to add the PostSignum Root QCA 4 and PostSignum Root QCA ECC R1 roots to Mozilla’s CA program. Mozilla initially directed PostSignum to complete the root inclusion checklist and, if Websites trust was requested, to provide a BR self-assessment and updated CP/CPS materials. The thread later included Mozilla review of audit-verification items, certificate-profile and OCSP issues, and CPS/self-assessment updates, which were discussed in the context of the inclusion review. In April 2025, Mozilla stated that the inclusion request was being tracked in CCADB Case 526 for PostSignum Root QCA 4 and CCADB Case 1726 for PostSignum Root QCA ECC R1, and that both requests would be limited to the email trust bit. In February and March 2026, the thread also revisited Mozilla’s earlier position that organizationName values over 64 characters are non-compliant, and PostSignum said it had suspended issuance of TLS certificates for companies whose names exceed 64 characters. In May 2026, Mozilla said CCADB Case 1726 was missing the ECC root under the Mozilla tab. In August 2026, PostSignum replied that Case 1726 could not be edited because it was submitted for review, and that a new CCADB case, 00003381, had been created. The bug remains open and assigned, with inclusion work still dependent on the related CCADB case handling and Mozilla’s ongoing review.

Model: gpt-5.4 Generated: 2026-06-13 21:01 UTC Revised: 2026-09-06 06:00 UTC Confidence: 0.91 42 comments
Chronology
  1. PostSignum opened a request to add PostSignum Root QCA 4 and PostSignum Root QCA ECC R1.
  2. PostSignum provided a Czech NAB confirmation document regarding TayllorCox accreditation.
  3. Mozilla identified multiple TLS certificate-profile issues under PostSignum Public CA 5 and asked for correction by revocation and replacement.
  4. PostSignum attached a compliance self-assessment and said its CP/CPS had been published.
  5. Mozilla said the inclusion requests were limited to the email trust bit and tracked in CCADB Cases 526 and 1726.
  6. PostSignum said it had stopped issuing certificates with longer Organization Name values until the situation was clarified.
  7. PostSignum said it had suspended issuance of TLS certificates for companies whose names exceed 64 characters.
  8. Mozilla said CCADB Case 1726 was missing PostSignum Root QCA ECC R1 under the Mozilla tab.
  9. PostSignum said CCADB Case 1726 could not be edited and that it created new CCADB Case 00003381.
Thread Activity
  1. Cpost representative — PostSignum opened the bug and linked the Root QCA 4 certificate.
  2. Mozilla representative — Mozilla asked PostSignum to complete the inclusion checklist and a BR self-assessment if Websites trust would be requested.
  3. Mozilla representative — Mozilla identified audit verification issues involving audit report hosting and NAB accreditation wording.
  4. Cpost representative — PostSignum attached the requested NAB confirmation document.
  5. Mozilla representative — Mozilla said the accreditation information had been updated and requested a BR self-assessment and updated CP/CPS for Websites trust.
  6. Mozilla representative — Mozilla asked PostSignum to review and correct multiple TLS certificate issuance errors by revoking and replacing affected certificates.
  7. Mozilla representative — Mozilla reported OCSP warnings and errors from a PostSignum test website.
  8. Cpost representative — PostSignum said certificates were being replaced gradually, one internal-server-name certificate had been revoked, and it disputed some of Mozilla’s interpretations.
  9. Mozilla representative — Mozilla requested a Compliance Self-Assessment attachment and an updated CPS meeting Mozilla policy requirements.
  10. Mozilla representative — Mozilla reiterated that organizationName is limited to 64 characters and said certificates exceeding that limit would need to be revoked.
  11. Mozilla representative — Mozilla said it believed PostSignum’s responses in comment 22 were satisfactory explanations and raised the priority to P3.
  12. Cpost representative — PostSignum attached a compliance self-assessment and said its CP/CPS had been published.
  13. Mozilla representative — Mozilla posted additional CPS review comments and recommendations.
  14. Cpost representative — PostSignum replied to the CPS review comments, described edits, and linked its repository.
  15. Mozilla representative — Mozilla clarified that the inclusion requests were limited to the email trust bit and tracked in CCADB Cases 526 and 1726.
  16. Community commenter — A commenter asked Mozilla to confirm that earlier comments had not authorized PostSignum to continue issuing certificates with organizationName values over 64 characters.
  17. Cpost representative — PostSignum said it had stopped issuing certificates with longer Organization Name values until the matter was clarified.
  18. Mozilla representative — Mozilla restated that its prior comments did not authorize continued issuance and that the 64-character organizationName limit applies.
  19. Cpost representative — PostSignum said it had suspended issuance of TLS certificates for companies whose names exceed 64 characters.
  20. Sectigo — A commenter said standards must be followed and that if a company name cannot fit within the BR rules, the CA should not issue the certificate.
  21. Mozilla representative — Mozilla said CCADB Case 1726 was missing the ECC root under the Mozilla tab and needed the Add/Select Root Certificates step.
  22. Cpost representative — PostSignum said Case 1726 could not be edited because it was submitted for review and that new CCADB Case 00003381 had been created.
Participants
Cpost representative Mozilla representative Community commenter Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1313982 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2016-10-31 · Closed 2025-04-02 · 87% similar
Add SECOM root certificates
#1710831 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2021-05-12 · Closed 2023-08-01 · 86% similar
Add LAWtrust Root CA2 to NSS
#1799533 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2022-11-07 · Closed 2024-03-15 · 85% similar
Add SSL.com 2022 TLS Root CA Certificates
#1565871 RESOLVED Ca Certificate Root Program Root Inclusion Historical Reference Opened By Ca Opened 2019-07-14 · Closed 2026-07-13 · 85% similar
Add CCA ROOT CA India
#711366 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2011-12-16 · Closed 2022-11-14 · 80% similar
Add Atos Trustcenter CA cert to trusted root CA cert list
#1658793 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2020-08-12 · Closed 2025-01-24 · 79% similar
Add Cybertrust Japan SecureSign Roots (CA12, CA14 and CA15)
#944783 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2013-11-29 · Closed 2022-11-14 · 78% similar
Add LuxTrust Global Root CA Certificate
#817994 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2012-12-04 · Closed 2022-11-14 · 78% similar
KIR S.A.'s application for inclusion in Mozilla Root Certificate Program

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action