Add several ICAs of Firmaprofesional to OneCRL
This case requests adding several Firmaprofesional intermediate CA (ICA) certificates to Mozilla’s OneCRL. The request was made to align with Firmaprofesional’s plans referenced in other bugs (1649943 and 1651637) and includes multiple specific intermediate certificates, with the stated intent that they are not intended to issue TLS. Kathleen Wilson indicated she planned to close the bug as WONTFIX, stating that the listed intermediate certificates are technically constrained via EKU to not issue TLS certificates, and that OneCRL is only used by Firefox for TLS, so adding non-TLS intermediates would have zero effect other than adding data. Ryan Sleevi responded that the context was OCSP, noting the intermediates could potentially issue OCSP responses, but that Mozilla code already rejects these due to checks, and that Mozilla clients like Thunderbird would not be protected by adding them to OneCRL. The bug was resolved as WONTFIX.
- A bug was filed to add multiple Firmaprofesional intermediate certificates to OneCRL.
- Mozilla staff discussed closing the request as WONTFIX due to EKU constraints and OneCRL’s TLS-only use.
- The bug was resolved as WONTFIX.
- Isigma representative — Requested adding several Firmaprofesional intermediate certificates to OneCRL to align with Firmaprofesional’s plans, listing the specific ICA certificates and their details.
- Mozilla representative — Planned to close the bug as WONTFIX, arguing the intermediates are EKU-constrained to not issue TLS and that OneCRL is only used by Firefox for TLS.
- Community commenter — Responded that the discussion relates to OCSP, but stated Mozilla code already rejects these OCSP responses and that Thunderbird would not be protected by adding them to OneCRL.