← TurkTrust cases
Bugzilla #380635 Root Inclusion Ca Certificate Root Program

TÜRKTRUST root CA inclusion request and review

RESOLVED FIXED FIXED TurkTrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is TÜRKTRUST’s request to add two root CA certificates to Mozilla’s root store. The bug was opened by TÜRKTRUST with details about its roots, CPS, audit status, and intended trust uses, including SSL, email, code signing, timestamping, and OCSP. Mozilla reviewers asked for public documentation, CRL details, hierarchy diagrams, and clearer statements in the CPS about email, SSL, and code-signing vetting. TÜRKTRUST responded with an English CPS, published audit letter URL, hierarchy diagrams, and explanations of its verification practices. After a public comment period, Mozilla approved the two TÜRKTRUST root CAs for inclusion and filed a follow-up NSS bug; this bug was then resolved FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 12:00 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.98 47 comments
Chronology
  1. TÜRKTRUST requested inclusion of two root CA certificates in Mozilla software certificate stores.
  2. Mozilla completed its review and announced intent to approve the two TÜRKTRUST root CAs for inclusion.
  3. Mozilla approved the TÜRKTRUST root CAs for inclusion after addressing the remaining concerns.
  4. The bug was resolved FIXED after the related NSS inclusion bug was resolved.
Thread Activity
  1. Community commenter — TÜRKTRUST opened the bug to complete the formal request to add two root CA certificates and provided CA, audit, and certificate details.
  2. Mozilla representative — Mozilla asked about the public availability of the auditor letter, CRL URLs, root naming, and whether the two roots served distinct uses.
  3. Community commenter — TÜRKTRUST confirmed the CA information, said it had started correspondence to publish the letter on the auditor’s web domain, and explained the two roots were not for distinct uses.
  4. Community commenter — TÜRKTRUST provided the published letter URL, daily CRL issuance, hierarchy diagrams, an English CPS, and section references for SSL verification.
  5. Mozilla representative — Mozilla said it could not accept roots without a public, binding commitment to meet the minimum vetting criteria in the policy.
  6. Community commenter — TÜRKTRUST said it would rewrite and extend its CPS to address the unclear minimum vetting criteria.
  7. Hecker representative — Frank Hecker took over the review, asked whether the revised CPS was on TÜRKTRUST’s website, and began a preliminary assessment.
  8. Community commenter — TÜRKTRUST provided the CPS URL on its website and answered questions about object signing certificates and annual audits.
  9. Hecker representative — Mozilla completed its final assessment, opened public discussion, and said it was minded to approve the two root CAs.
  10. Bolyard representative — A participant objected that trial certificates without authentication would be a show stopper if they validated like normal certificates.
  11. Hecker representative — Mozilla said the trial-certificate issue was not relevant to this application because those certificates were under a separate root, and approved the two root CAs for inclusion.
  12. Hecker representative — Mozilla filed bug 410821 for NSS inclusion of the two TÜRKTRUST root CA certificates.
  13. Hecker representative — The bug was resolved FIXED after bug 410821 was resolved FIXED.
Participants
Community commenter Mozilla representative Hecker representative Bolyard representative Beonex representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 99% similar
Add Certigna certificates to Mozilla root CA list
#239488 RESOLVED Ca Certificate Root Program Root Inclusion Duplicate Or Superseded Opened 2004-04-03 · Closed 2022-11-14 · 94% similar
Request to include CA cert for Certipost E-Trust
#370505 RESOLVED Root Inclusion Opened 2007-02-15 · Closed 2022-11-14 · 93% similar
Add Microsec Ltd root CA certificate
#343756 RESOLVED Ca Certificate Root Program Opened 2006-07-06 · Closed 2022-11-14 · 90% similar
Request to add SwissSign root CA certificate
#368970 RESOLVED Root Inclusion Opened 2007-02-01 · Closed 2022-11-14 · 89% similar
Add French Government (DCSSI) CA certificate
#370627 RESOLVED Ca Certificate Root Program Opened 2007-02-16 · Closed 2022-11-14 · 88% similar
Add S-TRUST root certificates
#361957 RESOLVED Root Inclusion Ev Enablement Opened 2006-11-27 · Closed 2022-11-14 · 87% similar
Add Izenpe CA EV root certificate (Spain)
#335392 RESOLVED Root Inclusion Opened 2006-04-25 · Closed 2022-11-14 · 87% similar
Add Keynectis/Certplus root CA cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action