Certigna root inclusion request for Mozilla NSS
Certigna (Dhimyotis) asked Mozilla to add its root certificate to the Mozilla root CA list. The request began with Certigna providing details for its root and subordinate CAs, audit information, and validation practices for SSL and email certificates. Mozilla then gathered additional information, including CP/CPS excerpts, audit confirmation from LSTI, and public discussion on the request. After the second public discussion, Mozilla approved the Certigna root for email and SSL trust bits, but postponed code-signing because it was unclear whether code-signing had been covered by the audit. The thread ends with the NSS implementation bug filed and the code-signing trust bit left for a separate future request.
- Certigna requested inclusion of its root certificate in Mozilla’s root store.
- Certigna provided CP/CPS excerpts describing SSL and email validation practices.
- Mozilla opened the first public discussion period for the inclusion request.
- Mozilla approved the Certigna root for email and SSL trust bits and deferred code-signing.
- Dhimyotis representative — Certigna opened the request and listed its root and subordinate certificates, audit status, and contact details.
- Mozilla representative — Mozilla asked Certigna to complete the CA inclusion form with root-certificate details.
- Hecker representative — Frank Hecker assigned Kathleen Wilson to gather information for the request.
- Mozilla representative — Kathleen requested translations and policy details needed to verify validation practices and problematic-practice questions.
- Dhimyotis representative — Certigna answered questions about whois checks, email verification, and its planned code-signing work.
- Mozilla representative — Kathleen reported that LSTI had provided a public ETSI 102.042 compliance statement and that the pending list had been updated.
- Mozilla representative — Kathleen closed the first public discussion and listed action items about public CPS material and audit documentation.
- Mozilla representative — Kathleen summarized the assessment and recommended approval for the Certigna root.
- Hecker representative — Frank Hecker approved the request for email and SSL trust bits and deferred code-signing to a separate request.
- Mozilla representative — Kathleen filed bug 483889 for the NSS implementation work and noted code-signing would need a new request.