← Korea Information Security Agency (KISA) cases
Bugzilla #335197 Root Inclusion

KISA request to add three root CA certificates for Mozilla trust store inclusion

RESOLVED WONTFIX Korea Information Security Agency (KISA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

KISA asked Mozilla to add three KISA root CA certificates to the Mozilla certificate store. The request described KISA as a Korean government agency operating a national PKI that issues certificates only to six subordinate licensed CAs, not directly to end entities. Mozilla reviewers asked for details about the subordinate CAs, certificate issuance practices, and audit evidence, and KISA provided CPS documents, legal references, and later a public MIC statement about the audit. The thread also covered the fact that KISA’s second root replaced an earlier root for the wired PKI, while the third root was for the wireless PKI. In January 2008, Mozilla’s reviewer said the application was ready for public discussion and intended to approve the three roots, and later comments focused on additional mapping between KISA’s CPS and WebTrust criteria. The bug was ultimately resolved WONTFIX.

Model: gpt-5.4-mini Generated: 2026-06-13 11:01 UTC Revised: 2026-06-16 16:19 UTC Confidence: 0.95 170 comments
Chronology
  1. KISA requested Mozilla add three KISA root CA certificates to the Mozilla certificate store.
  2. KISA submitted structured details for the three roots, including URLs, validity periods, and requested trust indicators.
  3. MIC posted a public statement about the KISA Root CA audit on its website.
  4. Mozilla reviewer said the KISA application was ready for public discussion and intended to approve the three roots.
  5. Mozilla reviewer said the remaining issue was additional mapping between WebTrust criteria and KISA’s CPS.
  6. Mozilla asked whether the request should continue for the two still-valid roots after the first root had expired.
Thread Activity
  1. Kisa representative — KISA opened the bug and requested inclusion of three root CA certificates, providing certificate URLs, CRLs, CPS URL, and requested trust usages.
  2. Kisa representative — KISA provided a structured application with CA details, certificate details, and audit information, including that it issues certificates only to six LCAs.
  3. Mozilla representative — Mozilla asked for a formal application summary, audit details, and certificate metadata in a standard format.
  4. Kisa representative — KISA supplied a CPS document and an MIC official document for root CA audit, and said the CPS was version-controlled by MIC.
  5. Kisa representative — KISA said MIC had supervised and audited KISA Root CA every year and that subordinate CAs must verify email validity using their own methods.
  6. Hecker representative — Mozilla said it had completed its review, found KISA/KCAC to meet the policy requirements, and opened a public discussion period.
  7. Kisa representative — KISA said MIC audited KCAC based on its CPS and CII security plans, and that the MIC letter stated those requirements were sufficient to meet WebTrust criteria.
  8. Hecker representative — Mozilla said the document mapping WebTrust criteria to KISA’s CPS still lacked mappings for WebTrust sections 2 and 3.
  9. Kisa representative — KISA attached an updated mapping table covering WebTrust chapters 2 and 3 and attached MIC notifications.
  10. Mozilla representative — Mozilla noted that the MIC audit-statement link had expired and requested updated information, including sub-CA review and test-site URLs.
  11. Kisa representative — KISA pointed Mozilla back to the MOPAS audit statement and the updated WebTrust mapping table.
  12. Mozilla representative — Mozilla asked whether the request should continue for the two still-valid roots, since CertRSA01 had expired.
Participants
Kisa representative Mozilla representative Hecker representative Community commenter Bolyard representative Paygate representative Rossde representative Startcom representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#370505 RESOLVED Root Inclusion Opened 2007-02-15 · Closed 2022-11-14 · 88% similar
Add Microsec Ltd root CA certificate
#511380 RESOLVED Root Inclusion Opened 2009-08-19 · Closed 2022-11-14 · 88% similar
Add NIC (India) Root CA Certificate
#420705 RESOLVED Root Inclusion Opened 2008-03-03 · Closed 2022-11-14 · 88% similar
add Comsign CA certs
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 88% similar
Add Certigna certificates to Mozilla root CA list
#324126 RESOLVED Root Inclusion Opened 2006-01-20 · Closed 2022-11-14 · 87% similar
Add Trustis Root CA Certificate
#480966 RESOLVED Root Inclusion Opened 2009-03-02 · Closed 2022-11-14 · 87% similar
Netlock Root CA rollover request
#368970 RESOLVED Root Inclusion Opened 2007-02-01 · Closed 2022-11-14 · 87% similar
Add French Government (DCSSI) CA certificate
#335392 RESOLVED Root Inclusion Opened 2006-04-25 · Closed 2022-11-14 · 87% similar
Add Keynectis/Certplus root CA cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action