ACCV root inclusion request for Root CA Generalitat Valenciana
This case is a Mozilla CA Program request to include ACCV’s root certificate, Root CA Generalitat Valenciana, for websites, email, and code signing. It began when Frank Hecker opened the bug in 2004 to evaluate ACCV, a CA operated by the government of the Valencia region of Spain. Over time, ACCV provided its WebTrust audit, English translations of its CPS and related policy documents, and additional clarification on OCSP behavior and domain-name verification. Mozilla requested updates to the SSL CP to document how domain ownership/control is checked, and ACCV responded by adding section 3.1.10 describing WHOIS, DNS, and connection tests. After public discussion and review, Kathleen Wilson approved the request on 2011-04-29 and said she would file the NSS bug to make the changes; she then filed bug 653761 for the actual changes.
- ACCV root certificate inclusion request opened for Mozilla review.
- ACCV reported obtaining a WebTrust Seal.
- ACCV updated its SSL policy with domain-checking procedures.
- Mozilla approved inclusion of Root CA Generalitat Valenciana for websites, email, and code signing.
- Hecker representative — Frank Hecker described ACCV, identified the true root certificate for consideration, and noted that he could not find audit information at that time.
- Gva representative — ACCV said it had obtained a WebTrust Seal and provided the seal link.
- Mozilla representative — Kathleen Wilson reported an OCSP authorization error in Firefox and asked for public-facing audited documentation of domain-name verification.
- Gva representative — ACCV said it had updated its policy with section 3.1.10, describing WHOIS, DNS, and HTTPS checks for domain ownership.
- Mozilla representative — Wilson opened the first public discussion period and said approval would be contingent on an updated audit.
- Mozilla representative — Wilson summarized the assessment and noted that ACCV appeared to meet the minimum requirements for subscriber verification.
- Mozilla representative — Wilson approved inclusion of the ACCV root certificate and said she would file the NSS bug for the approved changes.
- Mozilla representative — Wilson filed bug 653761 against NSS for the actual changes.