E-Tugra root inclusion request and later request to add a second root
This case began as E-Tugra’s request to add its root certificate, EBG Elektronik Sertifika Hizmet Sağlayıcısı, to Mozilla’s trusted store. Mozilla asked E-Tugra to provide the required root-inclusion information, clarify its subordinate CA structure, and address questions about audit coverage, problematic practices, and OCSP behavior. E-Tugra supplied the requested details, updated its CP/CPS, and fixed the OCSP responder issue that had caused Firefox validation errors. Mozilla then approved inclusion of the root with trust bits for web sites, email, and code signing, while noting that an updated audit statement should be added separately. The bug remained open for a time until that audit-related action item was completed, and later E-Tugra also requested inclusion of a new root certificate because its existing root was due to expire in 2016 and it needed SHA-256/2048-bit certificates under Turkish law.
- E-Tugra requested inclusion of its root certificate in Mozilla’s trusted store.
- E-Tugra fixed its OCSP server signing certificate so OCSP responses validated correctly.
- Mozilla approved inclusion of the EBG Elektronik Sertifika Hizmet Sağlayıcısı root with web, email, and code-signing trust bits.
- E-Tugra provided an updated audit statement for the root program review.
- E-Tugra requested inclusion of a new root certificate and EV enablement for that new root.
- Community commenter — E-Tugra opened the bug requesting Mozilla trust for its root and provided certificate, CP/CPS, and policy links.
- Mozilla representative — Mozilla reopened the bug to the public after it had been marked security sensitive.
- Bolyard representative — Mozilla asked E-Tugra to provide the full set of information required for root requests.
- Mozilla representative — Mozilla accepted the bug and began the information-gathering and verification phase.
- Mozilla representative — Mozilla requested a newer audit statement, updated problematic-practices information, and a fix for the OCSP test failure.
- E-Tugra — E-Tugra said it had installed SSL certificate support for OCSP and asked Mozilla to test again.
- E-Tugra — E-Tugra said the OCSP signing certificate had been fixed and provided a link to the latest audit document.
- Mozilla representative — Mozilla opened the first public discussion for the root inclusion request.
- Mozilla representative — Mozilla summarized the review and recommended approval, subject to an updated audit being tracked separately.
- Hecker representative — Mozilla approved inclusion of the root and asked Kathleen to file the NSS and PSM implementation bugs.
- Mozilla representative — Kathleen filed bug 509440 against NSS for the actual changes.
- Mozilla representative — Kathleen attached the 2010 audit statement.
- Mozilla representative — Kathleen noted that the updated audit statement had been posted on the ICTA website.
- E-Tugra — E-Tugra requested inclusion of a new root certificate and asked for EV enablement for that new root.