LAWtrust Root CA2 inclusion request for NSS email trust bit
This case is LAWtrust’s request to include its new Root CA2 in NSS with the email trust bit enabled. LAWtrust opened the bug and attached its root certificate request, WebTrust assurance report, CPS, and CP documents, stating that the new root had passed a WebTrust audit. Mozilla reviewed the submission, asked LAWtrust to complete CCADB fields, and then raised several compliance issues, including missing EKUs on two intermediate CAs, document licensing concerns, and other CPS updates needed for Mozilla requirements. LAWtrust updated its CPS documents and provided replacement CA material, and Mozilla later noted that the remaining tasks included revocation of the two mis-issued intermediate CAs and a value-vs-risk justification. Public discussion concluded in June 2023, Mozilla recommended approval, and the request was approved for LAWtrust Root CA2 (4096) with email trust enabled; an NSS bug was then filed for the actual changes.
- LAWtrust requested inclusion of Root CA2 in NSS with email trust bit support.
- Mozilla identified compliance issues in the LAWtrust CPSes and intermediate CA certificates, including missing EKUs.
- Mozilla stated remaining tasks included revocation of the two mis-issued intermediate CAs.
- Mozilla approved inclusion of LAWtrust Root CA2 (4096) with email trust enabled.
- Mozilla filed NSS bug 1840437 for the approved changes.
- Lawtrust representative — LAWtrust opened the request and attached the root certificate, WebTrust report, CPS, and CP documents.
- Mozilla representative — Mozilla asked LAWtrust to review empty CCADB fields and complete the needed information.
- Mozilla representative — Mozilla said the CPS language appeared to satisfy email verification requirements but noted other issues needing fixes.
- Lawtrust representative — LAWtrust asked whether the EKU requirement on the issuing CAs was critical and whether the application could proceed without it.
- Mozilla representative — Mozilla said LAWtrust should replace the CA certificates in question, even though it would delay inclusion.
- Altron representative — LAWtrust uploaded updated CPS documents and updated CA certificate material.
- Mozilla representative — Mozilla said the remaining tasks included revocation of the two mis-issued intermediate CAs and attaching a value-vs-risk justification.
- Mozilla representative — Mozilla said public discussion had concluded, recommended approval, and announced a 7-day last call.
- Mozilla representative — On behalf of Mozilla, the request to include LAWtrust Root CA2 (4096) with email trust was approved.
- Mozilla representative — Mozilla filed bug 1840437 against NSS for the actual changes.