TÜRKTRUST root CA inclusion request and review
This case is TÜRKTRUST’s request to add two root CA certificates to Mozilla’s root store. The bug was opened by TÜRKTRUST with details about its roots, CPS, audit status, and intended trust uses, including SSL, email, code signing, timestamping, and OCSP. Mozilla reviewers asked for public documentation, CRL details, hierarchy diagrams, and clearer statements in the CPS about email, SSL, and code-signing vetting. TÜRKTRUST responded with an English CPS, published audit letter URL, hierarchy diagrams, and explanations of its verification practices. After a public comment period, Mozilla approved the two TÜRKTRUST root CAs for inclusion and filed a follow-up NSS bug; this bug was then resolved FIXED.
- TÜRKTRUST requested inclusion of two root CA certificates in Mozilla software certificate stores.
- Mozilla completed its review and announced intent to approve the two TÜRKTRUST root CAs for inclusion.
- Mozilla approved the TÜRKTRUST root CAs for inclusion after addressing the remaining concerns.
- The bug was resolved FIXED after the related NSS inclusion bug was resolved.
- Community commenter — TÜRKTRUST opened the bug to complete the formal request to add two root CA certificates and provided CA, audit, and certificate details.
- Mozilla representative — Mozilla asked about the public availability of the auditor letter, CRL URLs, root naming, and whether the two roots served distinct uses.
- Community commenter — TÜRKTRUST confirmed the CA information, said it had started correspondence to publish the letter on the auditor’s web domain, and explained the two roots were not for distinct uses.
- Community commenter — TÜRKTRUST provided the published letter URL, daily CRL issuance, hierarchy diagrams, an English CPS, and section references for SSL verification.
- Mozilla representative — Mozilla said it could not accept roots without a public, binding commitment to meet the minimum vetting criteria in the policy.
- Community commenter — TÜRKTRUST said it would rewrite and extend its CPS to address the unclear minimum vetting criteria.
- Hecker representative — Frank Hecker took over the review, asked whether the revised CPS was on TÜRKTRUST’s website, and began a preliminary assessment.
- Community commenter — TÜRKTRUST provided the CPS URL on its website and answered questions about object signing certificates and annual audits.
- Hecker representative — Mozilla completed its final assessment, opened public discussion, and said it was minded to approve the two root CAs.
- Bolyard representative — A participant objected that trial certificates without authentication would be a show stopper if they validated like normal certificates.
- Hecker representative — Mozilla said the trial-certificate issue was not relevant to this application because those certificates were under a separate root, and approved the two root CAs for inclusion.
- Hecker representative — Mozilla filed bug 410821 for NSS inclusion of the two TÜRKTRUST root CA certificates.
- Hecker representative — The bug was resolved FIXED after bug 410821 was resolved FIXED.