← National Certification Authority of Sri Lanka (NCA of Sri Lanka) cases
Bugzilla #2033676 Root Inclusion

Add National Certification Authority of Sri Lanka TLS Root CA - G1

ASSIGNED National Certification Authority of Sri Lanka (NCA of Sri Lanka)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a new request to include the “National Certification Authority of Sri Lanka TLS Root CA - G1” in the Mozilla Root Store. The CA operator (Sri Lanka CERT / National Certification Authority of Sri Lanka) provided CCADB information, a root certificate URL, a SHA-256 fingerprint, hierarchy details (offline root with subordinate/intermediate CAs), and audit information (WebTrust audit period 05/15/2025–08/31/2025 with report URLs). Mozilla performed an initial review and requested clarifications and additional information before proceeding, citing that the application indicates externally operated subordinate CAs and that the request includes Mozilla websites trust bit enablement without providing required TLS-related materials (e.g., TLS domain validation methods, automated issuance information, public test infrastructure, and test websites) plus a Value Statement. The CA clarified that the hierarchy includes a registered subordinate CA under the NCA root framework, but that the subordinate CA is intended for document signing only and is not yet operating for publicly trusted TLS certificate issuance; therefore, TLS issuance infrastructure and public test websites are not yet operational. Mozilla recommended that NCA create purpose-specific roots and maintain separate hierarchies for different purposes, and the CA reiterated that the TLS root under review is dedicated to TLS services while no publicly trusted TLS subordinate CA has been activated yet. The bug remains in ASSIGNED status, with the CA asking what information should be provided at this pre-operational stage and whether TLS operational requirements can be submitted once the TLS subordinate CA becomes active.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 5 comments
Chronology
  1. National Certification Authority of Sri Lanka submitted a request to include its TLS Root CA - G1 in the Mozilla Root Store.
  2. Mozilla completed an initial review and requested clarifications and additional information for the inclusion request.
  3. The CA clarified the subordinate CA’s current document-signing-only purpose and that TLS issuance infrastructure is not yet operational.
  4. Mozilla recommended creating purpose-specific roots and separate hierarchies for different certificate purposes.
  5. The CA reiterated that the TLS root is dedicated to TLS and requested guidance on next-step information during the pre-operational phase.
Thread Activity
  1. Cert representative — Created the bug to request Mozilla Root Store inclusion for “National Certification Authority of Sri Lanka TLS Root CA - G1,” providing CCADB URL, root certificate URL, fingerprint, hierarchy, audit info, and TLS/CT/OCSP/CRL details.
  2. Mozilla representative — Reported Mozilla’s initial review found items needing clarification, including externally operated subordinate CAs and missing TLS-related materials required for the requested trust bit enablement, and requested a Value Statement.
  3. Cert representative — Explained the hierarchy includes a subordinate CA that is not yet registered in CCADB, that it is intended for document signing only (not publicly trusted TLS issuance), and asked for guidance on next steps for continuing the inclusion review.
  4. Mozilla representative — Recommended that NCA create purpose-specific roots and maintain separate hierarchies for document signing, email, TLS, and other purposes.
  5. Cert representative — Clarified that the TLS root under review is dedicated to TLS, no publicly trusted TLS subordinate CA is activated yet, TLS issuance operations are not commenced, and requested guidance on what to provide during the pre-operational phase.
Participants
Cert representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1552403 RESOLVED Root Inclusion Opened 2019-05-17 · Closed 2024-01-26 · 87% similar
Add National Certification Authority of Sri Lanka root certificates
#1990213 ASSIGNED Root Inclusion Self Reported Incident Opened 2025-09-23 Still Open · 69% similar
Add certSIGN Root CA G4 root certificate
#1404221 RESOLVED Root Inclusion Opened 2017-09-29 · Closed 2022-11-14 · 69% similar
Add Root certificate of NAVER Business Platform
#1592138 RESOLVED Root Inclusion Opened 2019-10-28 · Closed 2025-12-19 · 68% similar
Add Macao Post eSignTrust root certificate
#2031847 ASSIGNED Root Inclusion Opened 2026-04-14 Still Open · 68% similar
Add FNMT TLS RSA Root Certificate SERVIDORES SEGUROS G2R
#1988341 ASSIGNED Root Inclusion Opened 2025-09-12 Still Open · 68% similar
Add ACCV ROOT RSA TLS 2024 and ACCV ROOT ECC TLS 2024 root certificates
#1679258 RESOLVED Root Inclusion Opened 2020-11-25 · Closed 2022-11-14 · 68% similar
Root inclusion request for D-TRUST EV Root CA 1 2020
#1992971 ASSIGNED Root Inclusion Opened 2025-10-07 Still Open · 68% similar
Add Actalis TLS Root CAs 2025 and Actalis SMIME Root CAs 2025

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action