FNMT root inclusion request for Spanish government certificates
This case is a Mozilla root inclusion request for FNMT’s Spanish government certificate hierarchy, initially opened to add the FNMT Clase 2 CA root and later narrowed to the new AC RAIZ FNMT-RCM root. The request was triggered by FNMT’s submission of CA details, root certificate information, and supporting CPS/audit material for Mozilla review. Over the course of the thread, Mozilla requested information about audit status, certificate verification practices, revocation checking, and whether the requested trust bits should include email. FNMT provided updated CPS documents, described its verification procedures, clarified that SSL and code-signing requests are manually approved, and stated that the new root has subordinate CAs and that the old Class 2 root is being phased out. The thread also records that the request was added to Mozilla’s queue for public discussion, and later comments indicate the inclusion request was updated to focus only on the new AC RAIZ FNMT-RCM root.
- FNMT submitted a request to add the Spanish FNMT root certificate.
- FNMT stated it had created a new root CA and was renewing its ETSI audit.
- FNMT reported that Firefox OCSP validation problems were being investigated.
- Mozilla added the request to the queue for public discussion.
- FNMT agreed the inclusion request should be only for the new AC RAIZ FNMT-RCM root.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — FNMT opened the bug with CA and root certificate details for the FNMT Clase 2 CA.
- Mozilla representative — Kathleen asked for end-of-life plans, revocation details, verification procedures, and an updated audit report.
- Community commenter — FNMT said it had created a new root CA, agreed that email trust bits should not be requested, and said the audit was being renewed.
- Community commenter — FNMT said domain ownership was checked through public registrars and official publications, and that RAs do not issue SSL or code-signing certificates.
- Mozilla representative — Kathleen noted that the auditor had confirmed the audit statement and that the request was added to the public discussion queue.
- Community commenter — FNMT reported a new CA under AC RAIZ FNMT-RCM, provided a test website, and said the current audit statement was still valid until August 2012.
- Community commenter — FNMT agreed the inclusion request should be only for the new AC RAIZ FNMT-RCM root and said SSL certificates under it would be valid for a maximum of three years.