ComSign root inclusion request for ComSign CA and ComSign Secured CA
This bug is a request from ComSign to add two root certificates to Mozilla: ComSign CA and ComSign Secured CA. The request began with ComSign asking Mozilla to add its certificates, and Mozilla then asked for CA details, audit evidence, CP/CPS links, hierarchy information, and validation practices. Over the course of the thread, ComSign provided the requested materials, including hierarchy diagrams, audit letters, CPS links, and examples of certificates chaining to the roots. Mozilla reviewed the submission, asked follow-up questions about audit criteria, validation text, and trust bits, and ComSign responded with additional documentation and clarifications. Mozilla later stated that the audit authenticity had been verified and that the request was ready for public discussion. After the second public discussion, Mozilla approved adding the two roots to NSS with trust bits set to email only for ComSign CA and SSL/object signing for ComSign Secured CA, and the bug was then tied to NSS bug 490487 for the actual changes.
- ComSign requested Mozilla add the ComSign CA and ComSign Secured CA roots
- Mozilla recorded that ComSign had completed the information-gathering and verification phase
- Mozilla approved adding ComSign CA and ComSign Secured CA to NSS with specified trust bits
- Mozilla filed NSS bug 490487 for the implementation work
- Comda representative — ComSign asked Mozilla to add three certificates and described its services and SSL example site.
- Mozilla representative — Mozilla accepted the bug and requested detailed CA, certificate, audit, and policy information.
- Comda representative — ComSign supplied updated CPS links, validation statements, hierarchy information, and noted it removed the CRL critical flag.
- Mozilla representative — Mozilla said the audit letter was addressed to Microsoft, asked for clearer CPS evidence for validation practices, and sought confirmation of trust bits.
- Mozilla representative — Mozilla summarized the first public discussion and asked ComSign to clarify audit criteria and mapping to Mozilla policy.
- Mozilla representative — Mozilla said the audit authenticity had been verified and that the request was ready for public discussion.
- Hecker representative — Mozilla approved the request and asked Kathleen to file the NSS implementation bug and link it as a dependency.
- Mozilla representative — Kathleen filed bug 490487 against NSS for the actual changes.