Hongkong Post root cert inclusion (duplicate of bug 408949)
The case is about including the Hongkong Post root certificate in Mozilla’s CA Certificate Root Program. The initial request was submitted by Stephen Chu (an end user who owns a certificate issued by Hongkong Post), who provided information about the Hongkong Post CA, including the root certificate name, URLs, fingerprints, validity dates, and requested trust indicators (email, SSL, code). Mozilla staff noted that Mozilla does not accept certificate applications from anyone other than an official representative of the CA, to avoid issues such as incorrect trust bits. The reporter clarified that they were not an official representative and that an official representative would submit updated information. Mozilla indicated that the official request had been filed as bug 408949 and marked this bug as a duplicate. The thread’s resolution is therefore that the inclusion request should proceed under the referenced duplicate bug.
- An end user submitted a request to include the Hongkong Post root certificate in Mozilla’s trust store, providing CA and certificate details.
- Mozilla staff rejected the application as not coming from an official CA representative and requested an official representative to apply.
- The reporter stated an official representative would submit updated information.
- Mozilla marked the bug as a duplicate after the official request was filed as bug 408949.
- Community commenter — Submitted details for Hongkong Post CA and the “Hongkong Post Root CA 1” certificate, including CPS/CP URLs and requested trust indicators (email, SSL, code).
- Tuxmachine representative — Pointed the reporter to the Mozilla CA certificate policy and related bugs in the component.
- Bolyard representative — Asked whether the reporter was a representative of Hongkong Post and requested the common information from CA applicants (referencing other bugs).
- Community commenter — Confirmed they were not a representative, described the CA hierarchy and certificate details, and provided the requested CA information.
- Mozilla representative — Stated Mozilla only accepts CA applications from official CA representatives and questioned how the reporter knew the CA wanted code signing trust.
- Bolyard representative — Commented that the reporter did a good job applying on their behalf and suggested the official applicant could reuse the bug report.
- Community commenter — Said an official representative will submit updated information.
- Bolyard representative — Noted the official request was filed as bug 408949 and marked this bug as a duplicate of bug 408949.