Add ComSign CA root certs (3) to certificate store
This case is a request from ComSign to be added to Mozilla’s root CA certificate store. The reporter (Ran Harel of ComSign) provided CA details and three certificate entries (ComSign CA Signing, ComSign Secured CA Signing, and ComSign Advanced Security CA Signing), including certificate URLs, validity periods, CRL URLs, and requested trust indicators (email, SSL, code, client-authentication). Mozilla reviewer Gerv asked whether ComSign offers OCSP, whether it plans to issue EV certificates, and how ComSign complies with Mozilla CA policy audit sections (including who performed the audit and evidence of the audit). ComSign responded that it does not currently offer OCSP, is not currently planning to issue EV certificates, and that audits were conducted by the Israeli Ministry of Justice but were in Hebrew and were being translated and notarized. Gerv reiterated that the key questions were who performed the audit and to what standard it was performed, and asked whether those questions could be answered. The bug was later resolved as INCOMPLETE due to lack of input from the reporter.
- ComSign submitted a request to add three ComSign CA root certificates to Mozilla’s certificate store.
- Mozilla requested additional information about OCSP, EV plans, and audit compliance evidence/standards.
- ComSign replied about OCSP/EV status and described audit translation/notarization; Mozilla asked again for audit provider and standard.
- Mozilla resolved the inclusion request as INCOMPLETE due to lack of input.
- ComSign — Submitted a CA inclusion request with three ComSign root certificates, their URLs, CRL URLs, and requested trust indicators.
- Mozilla representative — Asked whether ComSign offers OCSP, whether it plans to issue EV certificates, and how it complies with Mozilla CA policy audit sections, including audit standards and evidence.
- Mozilla representative — Warned that if ComSign could not answer the questions, the bug would be closed.
- ComSign — Said ComSign does not offer OCSP, is not planning EV issuance, and is translating/notarizing Israeli Ministry of Justice audit documents.
- Mozilla representative — Asked again for who performed the audit and what standard it was performed against.
- Mozilla representative — Resolved the bug as INCOMPLETE due to lack of input from the reporter.
- Earthlink representative — Posted a long external comment questioning ComSign’s legitimacy and referencing Mozilla’s refusal to recognize certain certificates for lack of audit records.