Add GRCA root CA certificate
This case is about submitting the self-signed root certificate for the Government Root Certification Authority (GRCA) of Taiwan for acceptance by Mozilla. The request was initiated by Frank Hecker after receiving a letter stating that Chunghwa Telecom, as the operation authority of GRCA, wanted to submit the GRCA root CA certificate. Hecker attached the self-signed GRCA root certificate to the bug and noted that GRCA had not yet undergone a WebTrust for CA audit at the time of the initial submission, though it was planning to do so. Later, Hecker reported that GRCA had successfully completed a WebTrust audit (with a link to the WebTrust seal) and reviewed publicly available information against Mozilla’s CA policy. Hecker verified that the attached certificate fingerprint matched the correct GRCA root CA certificate, then approved the root CA certificate for inclusion in Mozilla and filed bug 341022 to add the certificate to NSS. According to a later comment referencing bug 341022, the certificate was included in NSS 3.11.4, and this bug was marked resolved/fixed.
- Frank Hecker submitted and attached the GRCA self-signed root CA certificate for Mozilla acceptance.
- Hecker reported GRCA had completed a WebTrust for CA audit.
- Hecker reviewed GRCA information and indicated intent to approve inclusion after comment.
- Hecker verified the attached certificate fingerprint matched the correct GRCA root CA certificate.
- Hecker approved the GRCA root CA certificate for inclusion and filed bug 341022 to add it to NSS.
- A later note stated the certificate was included in NSS 3.11.4 and this bug was marked resolved/fixed.
- Hecker representative — Hecker wrote that a letter requested submission of the GRCA self-signed root certificate for Mozilla acceptance, attached the certificate, and described GRCA’s audit status and public documentation links.
- Hecker representative — Hecker created an attachment containing the GRCA self-signed root CA certificate.
- Hecker representative — Hecker noted he had forgotten to accept the bug as assigned to him and did so.
- Hecker representative — Hecker stated GRCA successfully completed a WebTrust audit and provided a WebTrust seal link.
- Hecker representative — Hecker reviewed GRCA information against Mozilla’s CA policy, discussed subordinate CAs and audit details, and said he was inclined to approve inclusion after a comment period.
- Hecker representative — Hecker verified with a GRCA representative that the attached certificate fingerprint was the correct GRCA root CA certificate.
- Hecker representative — Hecker approved the GRCA root CA certificate for inclusion and filed bug 341022 to add the certificate to NSS.
- Bolyard representative — Nelson reported that, per bug 341022, the certificate was included in NSS 3.11.4 and marked this bug resolved/fixed.