Telia: Qualified BR Audit Statement 2020
Telia reported a Webtrust BR audit observation affecting its older root CA certificates. Telia said it became aware of the problem when it applied EV permissions for its roots in March 2017, and later saw the issue referenced as a qualification in BR audit reports starting in June 2018. Telia stated that the problematic root certificates were not fully compatible with current BR requirements because the Key Usage extension in the root certificates was not marked critical and one certificate’s subject information did not include subject:countryName. Telia said it created a new root CA in November 2018 that is fully compliant, and that auditors witnessed the creation; it also reported that a PIT audit report in January 2019 showed the new root CA is compliant. Telia indicated that it needed Mozilla to continue trusting the old Telia roots until the new root is widely accepted, and that its next step in 3Q2020 was to apply the new root to be trusted in all browsers. The bug was resolved as FIXED, and Mozilla staff discussed that the case could likely be closed with the plan noted.
- Telia applied EV permissions for its roots, after which it became aware of the BR-related issues later referenced in audits.
- BR audit reports first listed the older root CA issue as a qualification/observation.
- Telia created a new root CA that Telia stated is fully compliant, witnessed by auditors.
- A PIT audit report showed Telia’s new root CA is compliant.
- Telia filed the bug with its Qualified BR Audit Statement 2020 describing the remaining observation for the older roots and the transition plan to adopt the new root.
- Teliasonera representative — Filed the bug describing Telia’s Webtrust BR audit observation and stating the new root CA is compliant while old roots need continued trust until widely adopted.
- Mozilla representative — Noted that the severity field was not set and asked for review.
- Community commenter — Commented that the case seems easy to close and that it is consistent with Mozilla’s expectation to fix pre-BR issues before inclusion.