IdenTrust request to add two additional root CA certificates
IdenTrust asked Mozilla to add two additional root CA certificates to the Mozilla root store. The request was initially described as a root rollover for two existing certificates that were due to expire in 11/2008: DST RootCA X1 to be replaced by DST Root CA X3, and DST RootCA X2 to be replaced by DST ACES CA X6. Mozilla asked for the CA’s policy documents, certificate details, and confirmation of the published information, and IdenTrust provided the requested materials and clarifications. The review focused on validation practices for email and SSL certificates, and IdenTrust later said it would forego trying to get the email bit enabled. Mozilla then recorded that IdenTrust met the minimum requirements for SSL validation, noted the WebTrust audit, and opened a public discussion period. After no objections were raised, the bug was linked to Bug 394733 for inclusion tracking and was resolved fixed.
- IdenTrust requested that two additional root CA certificates be added to the Mozilla root store.
- IdenTrust clarified that the request was a root rollover for DST RootCA X1 and DST RootCA X2.
- Mozilla completed its evaluation and said it was minded to approve the application.
- Mozilla noted that no objections had been raised and filed Bug 394733 to track inclusion of the roots.
- IdenTrust Services, LLC — Requested that two IdenTrust root certificates be added to the Mozilla root store.
- Rossde representative — Asked whether the request involved additional IdenTrust certificates separate from DST certificates already in Mozilla.
- Mozilla representative — Asked IdenTrust to provide the policy information required for the pending CA request.
- IdenTrust Services, LLC — Confirmed that the information in the pending request list was correct.
- Mozilla representative — Sought clarification on how IdenTrust verified email ownership before issuance.
- IdenTrust Services, LLC — Explained IdenTrust’s identity vetting and domain verification procedures for its certificates.
- IdenTrust Services, LLC — Said IdenTrust would forego trying to get the email bit enabled and asked what remained to remediate for SSL issuance.
- Mozilla representative — Removed the email part of the request and explained that Mozilla still needed clearer CPS language for domain control verification.
- IdenTrust Services, LLC — Pointed to updated CPS language for X3 and said the ACES CPS for X6 still lacked similar language.
- Mozilla representative — Published his assessment, stating that IdenTrust met the minimum SSL validation requirements and that he was minded to approve the application.
- Mozilla representative — Reported that no objections had been raised and that Bug 394733 had been filed to track inclusion of the roots.