Hongkong Post Root CA 1 inclusion request for SSL trust
This case is Hongkong Post’s request to add the Hongkong Post Root CA 1 certificate to Mozilla’s trusted root store with SSL trust enabled. The request was opened by Stephen Choy of Hongkong Post in December 2007 and later accepted by Mozilla for review. During information gathering, Mozilla asked about the certificate hierarchy, outsourcing, and CRL behavior; Hongkong Post clarified that the root and its subordinate CA services were operated by E-Mice Solutions and that the request was for SSL trust only. Mozilla initially held the request pending CRL-related concerns, including that the full CRL was not discoverable via CRLDP and that the CRL nextUpdate period was one month. Hongkong Post later said it would change the server certificate CRLDP to the full CRL and set nextUpdate to 10 days, and Mozilla confirmed those action items were completed. Mozilla then filed bug 541499 against NSS for the actual inclusion changes, and the bug was marked RESOLVED FIXED.
- Hongkong Post requested inclusion of Hongkong Post Root CA 1 with SSL trust enabled.
- Mozilla completed its assessment and recommended approval for SSL use only.
- Mozilla confirmed the CRL-related action items were completed and filed the NSS implementation bug 541499.
- Hkpo representative — Hongkong Post opened the request to include Hongkong Post Root CA 1 and enable SSL trust.
- Mozilla representative — Mozilla began information gathering on the root, hierarchy, outsourcing, and testing details.
- Hkpo representative — Hongkong Post clarified the hierarchy, said E-Mice operated the services, and stated the email trust bit was intended if policy allowed.
- Hkpo representative — Hongkong Post asked Mozilla to proceed with enabling the SSL trust bit only.
- Mozilla representative — Mozilla said the request was ready for public discussion but noted the CRL issue and asked whether the critical CRLDP flag could be removed.
- Mozilla representative — Mozilla summarized the assessment and recommended approval for Hongkong Post Root CA 1 with websites trust only.
- Hecker representative — Mozilla approved the request subject to the caveat that the full CRL must be discoverable via CRLDP before future CRLDP support.
- Mozilla representative — Mozilla confirmed both CRL-related action items were completed and said it would create the NSS bug for inclusion.
- Mozilla representative — Bug 541499 was filed against NSS for the actual changes.