KISA request to add three root CA certificates for Mozilla trust store inclusion
KISA asked Mozilla to add three KISA root CA certificates to the Mozilla certificate store. The request described KISA as a Korean government agency operating a national PKI that issues certificates only to six subordinate licensed CAs, not directly to end entities. Mozilla reviewers asked for details about the subordinate CAs, certificate issuance practices, and audit evidence, and KISA provided CPS documents, legal references, and later a public MIC statement about the audit. The thread also covered the fact that KISA’s second root replaced an earlier root for the wired PKI, while the third root was for the wireless PKI. In January 2008, Mozilla’s reviewer said the application was ready for public discussion and intended to approve the three roots, and later comments focused on additional mapping between KISA’s CPS and WebTrust criteria. The bug was ultimately resolved WONTFIX.
- KISA requested Mozilla add three KISA root CA certificates to the Mozilla certificate store.
- KISA submitted structured details for the three roots, including URLs, validity periods, and requested trust indicators.
- MIC posted a public statement about the KISA Root CA audit on its website.
- Mozilla reviewer said the KISA application was ready for public discussion and intended to approve the three roots.
- Mozilla reviewer said the remaining issue was additional mapping between WebTrust criteria and KISA’s CPS.
- Mozilla asked whether the request should continue for the two still-valid roots after the first root had expired.
- Kisa representative — KISA opened the bug and requested inclusion of three root CA certificates, providing certificate URLs, CRLs, CPS URL, and requested trust usages.
- Kisa representative — KISA provided a structured application with CA details, certificate details, and audit information, including that it issues certificates only to six LCAs.
- Mozilla representative — Mozilla asked for a formal application summary, audit details, and certificate metadata in a standard format.
- Kisa representative — KISA supplied a CPS document and an MIC official document for root CA audit, and said the CPS was version-controlled by MIC.
- Kisa representative — KISA said MIC had supervised and audited KISA Root CA every year and that subordinate CAs must verify email validity using their own methods.
- Hecker representative — Mozilla said it had completed its review, found KISA/KCAC to meet the policy requirements, and opened a public discussion period.
- Kisa representative — KISA said MIC audited KCAC based on its CPS and CII security plans, and that the MIC letter stated those requirements were sufficient to meet WebTrust criteria.
- Hecker representative — Mozilla said the document mapping WebTrust criteria to KISA’s CPS still lacked mappings for WebTrust sections 2 and 3.
- Kisa representative — KISA attached an updated mapping table covering WebTrust chapters 2 and 3 and attached MIC notifications.
- Mozilla representative — Mozilla noted that the MIC audit-statement link had expired and requested updated information, including sub-CA review and test-site URLs.
- Kisa representative — KISA pointed Mozilla back to the MOPAS audit statement and the updated WebTrust mapping table.
- Mozilla representative — Mozilla asked whether the request should continue for the two still-valid roots, since CertRSA01 had expired.