← e-tugra cases
Bugzilla #443653 Root Inclusion

E-Tugra root inclusion request and later request to add a second root

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case began as E-Tugra’s request to add its root certificate, EBG Elektronik Sertifika Hizmet Sağlayıcısı, to Mozilla’s trusted store. Mozilla asked E-Tugra to provide the required root-inclusion information, clarify its subordinate CA structure, and address questions about audit coverage, problematic practices, and OCSP behavior. E-Tugra supplied the requested details, updated its CP/CPS, and fixed the OCSP responder issue that had caused Firefox validation errors. Mozilla then approved inclusion of the root with trust bits for web sites, email, and code signing, while noting that an updated audit statement should be added separately. The bug remained open for a time until that audit-related action item was completed, and later E-Tugra also requested inclusion of a new root certificate because its existing root was due to expire in 2016 and it needed SHA-256/2048-bit certificates under Turkish law.

Model: gpt-5.4-mini Generated: 2026-06-13 12:08 UTC Revised: 2026-06-16 18:27 UTC Confidence: 0.93 51 comments
Chronology
  1. E-Tugra requested inclusion of its root certificate in Mozilla’s trusted store.
  2. E-Tugra fixed its OCSP server signing certificate so OCSP responses validated correctly.
  3. Mozilla approved inclusion of the EBG Elektronik Sertifika Hizmet Sağlayıcısı root with web, email, and code-signing trust bits.
  4. E-Tugra provided an updated audit statement for the root program review.
  5. E-Tugra requested inclusion of a new root certificate and EV enablement for that new root.
Thread Activity
  1. Community commenter — E-Tugra opened the bug requesting Mozilla trust for its root and provided certificate, CP/CPS, and policy links.
  2. Mozilla representative — Mozilla reopened the bug to the public after it had been marked security sensitive.
  3. Bolyard representative — Mozilla asked E-Tugra to provide the full set of information required for root requests.
  4. Mozilla representative — Mozilla accepted the bug and began the information-gathering and verification phase.
  5. Mozilla representative — Mozilla requested a newer audit statement, updated problematic-practices information, and a fix for the OCSP test failure.
  6. E-Tugra — E-Tugra said it had installed SSL certificate support for OCSP and asked Mozilla to test again.
  7. E-Tugra — E-Tugra said the OCSP signing certificate had been fixed and provided a link to the latest audit document.
  8. Mozilla representative — Mozilla opened the first public discussion for the root inclusion request.
  9. Mozilla representative — Mozilla summarized the review and recommended approval, subject to an updated audit being tracked separately.
  10. Hecker representative — Mozilla approved inclusion of the root and asked Kathleen to file the NSS and PSM implementation bugs.
  11. Mozilla representative — Kathleen filed bug 509440 against NSS for the actual changes.
  12. Mozilla representative — Kathleen attached the 2010 audit statement.
  13. Mozilla representative — Kathleen noted that the updated audit statement had been posted on the ICTA website.
  14. E-Tugra — E-Tugra requested inclusion of a new root certificate and asked for EV enablement for that new root.
Participants
Community commenter Mozilla representative Bolyard representative Hecker representative E-Tugra
Related Bugzilla IDs Mentioned
Similar Local Cases
#1628720 RESOLVED Root Inclusion Opened 2020-04-09 · Closed 2022-11-14 · 96% similar
Add E-Tugra Root Certificates RSA v3 / ECC v3
#381974 RESOLVED Root Inclusion Opened 2007-05-25 · Closed 2022-11-14 · 90% similar
Add Kamu Sertifikasyon Merkezi CA root certificate
#369357 RESOLVED Root Inclusion Ev Enablement Opened 2007-02-05 · Closed 2022-11-14 · 88% similar
ADD DigiNotar EV Root CA certificates
#435736 RESOLVED Root Inclusion Opened 2008-05-26 · Closed 2022-11-14 · 87% similar
Add Spanish FNMT root certificate
#403915 RESOLVED Root Inclusion Ev Enablement Opened 2007-11-15 · Closed 2022-11-14 · 85% similar
Add Network Solutions EV root cert
#342426 RESOLVED Root Inclusion Opened 2006-06-22 · Closed 2022-11-14 · 77% similar
Add Firmaprofesional root CA certificate (Spain)
#313942 RESOLVED Root Inclusion Opened 2005-10-26 · Closed 2022-11-14 · 73% similar
Add Netlock Class QA root CA certificate
#1037590 RESOLVED Root Inclusion Opened 2014-07-11 · Closed 2022-11-14 · 72% similar
Add Renewal IdenTrust root certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action