Add National Certification Authority of Sri Lanka TLS Root CA - G1
This case is a new request to include the “National Certification Authority of Sri Lanka TLS Root CA - G1” in the Mozilla Root Store. The CA operator (Sri Lanka CERT / National Certification Authority of Sri Lanka) provided CCADB information, a root certificate URL, a SHA-256 fingerprint, hierarchy details (offline root with subordinate/intermediate CAs), and audit information (WebTrust audit period 05/15/2025–08/31/2025 with report URLs). Mozilla performed an initial review and requested clarifications and additional information before proceeding, citing that the application indicates externally operated subordinate CAs and that the request includes Mozilla websites trust bit enablement without providing required TLS-related materials (e.g., TLS domain validation methods, automated issuance information, public test infrastructure, and test websites) plus a Value Statement. The CA clarified that the hierarchy includes a registered subordinate CA under the NCA root framework, but that the subordinate CA is intended for document signing only and is not yet operating for publicly trusted TLS certificate issuance; therefore, TLS issuance infrastructure and public test websites are not yet operational. Mozilla recommended that NCA create purpose-specific roots and maintain separate hierarchies for different purposes, and the CA reiterated that the TLS root under review is dedicated to TLS services while no publicly trusted TLS subordinate CA has been activated yet. The bug remains in ASSIGNED status, with the CA asking what information should be provided at this pre-operational stage and whether TLS operational requirements can be submitted once the TLS subordinate CA becomes active.
- National Certification Authority of Sri Lanka submitted a request to include its TLS Root CA - G1 in the Mozilla Root Store.
- Mozilla completed an initial review and requested clarifications and additional information for the inclusion request.
- The CA clarified the subordinate CA’s current document-signing-only purpose and that TLS issuance infrastructure is not yet operational.
- Mozilla recommended creating purpose-specific roots and separate hierarchies for different certificate purposes.
- The CA reiterated that the TLS root is dedicated to TLS and requested guidance on next-step information during the pre-operational phase.
- Cert representative — Created the bug to request Mozilla Root Store inclusion for “National Certification Authority of Sri Lanka TLS Root CA - G1,” providing CCADB URL, root certificate URL, fingerprint, hierarchy, audit info, and TLS/CT/OCSP/CRL details.
- Mozilla representative — Reported Mozilla’s initial review found items needing clarification, including externally operated subordinate CAs and missing TLS-related materials required for the requested trust bit enablement, and requested a Value Statement.
- Cert representative — Explained the hierarchy includes a subordinate CA that is not yet registered in CCADB, that it is intended for document signing only (not publicly trusted TLS issuance), and asked for guidance on next steps for continuing the inclusion review.
- Mozilla representative — Recommended that NCA create purpose-specific roots and maintain separate hierarchies for document signing, email, TLS, and other purposes.
- Cert representative — Clarified that the TLS root under review is dedicated to TLS, no publicly trusted TLS subordinate CA is activated yet, TLS issuance operations are not commenced, and requested guidance on what to provide during the pre-operational phase.