Let's Encrypt: intent to issue root and intermediate certificates with organizationName and CABF DV OID
The case concerns Let’s Encrypt (ISRG) planning to create new root and intermediate keys and certificates. ISRG stated it wanted to limit intermediate certificates to Domain Validation by including the CABF DV OID, while also including organizationName in the Subject as required by the Baseline Requirements. ISRG referenced a prior discussion indicating this approach might not be technically allowed by the BRs, but said it expected the language would be rectified via an upcoming ballot. ISRG also explained it planned to proceed without waiting for a clarification ballot because waiting would delay work needed to minimize disruption to websites and would be difficult to schedule due to COVID-19 restrictions. Mozilla acknowledged receipt and referenced a related Bugzilla discussion where Mozilla’s interpretation was that organizational identification is allowed in DV-issuing CAs, and encouraged clarification of BR section 7.1.6.1 with the CA/Browser Forum. The bug is marked RESOLVED with resolution WORKSFORME.
- ISRG communicated its intent to issue new root and intermediate certificates with organizationName and the CABF DV OID for DV-limited intermediates.
- Mozilla acknowledged the communication and pointed to an interpretation and a request to clarify BR section 7.1.6.1 with the CA/Browser Forum.
- Kflag representative — ISRG (Let’s Encrypt) said it planned new root/intermediate certificates, intended DV-limited intermediates by including the CABF DV OID, and would include organizationName in the Subject as required by the BRs.
- Mozilla representative — Mozilla acknowledged receipt, cited Bug 1650018#c2 for an interpretation that organizational identification is allowed in DV-issuing CAs, and urged clarification of BR section 7.1.6.1 with the CA/Browser Forum.