US FPKI request to add the Common Policy CA root to Mozilla’s trust store
This case was a request from the U.S. Federal PKI Management Authority to add the Federal Common Policy CA root certificate to Mozilla products. The request began in 2009 and was later updated to refer to a new Federal Common Policy CA (FCPCA) root established for the U.S. Federal government’s SHA-256 transition. Mozilla reviewers asked for root certificate details, audit information, CPS/CP documentation, and evidence that subordinate CAs met Mozilla policy requirements. Over time, the discussion focused on whether the FCPCA hierarchy should be treated as a super-CA, whether subordinate SSP CAs needed their own inclusion requests, and whether public CP/CPS and audit statements were available for those subordinate CAs. In 2015–2017, the CA reported work to publish SSP documents and align its policy with CA/Browser Forum Baseline Requirements, while Mozilla noted that redacted CPS documents were not ideal for inclusion requirements. The bug was ultimately closed WONTFIX, and Mozilla stated that the CA could re-apply by filing a new bug.
- US FPKI requested Mozilla add the Common Policy CA root certificate to the default trust store.
- A new Federal Common Policy CA root was introduced to support the U.S. Federal government’s SHA-256 move.
- Mozilla opened the first public discussion for the FCPCA root inclusion request.
- Mozilla said the US FPKI hierarchy needed public-facing SSP documentation and audit statements to meet inclusion requirements.
- Mozilla closed the bug and said the CA could re-apply in a new request.
- Protiviti representative — Requested that the Federal Common Policy Framework CA certificate be added to Mozilla’s default CA certificates.
- Mozilla representative — Accepted the bug and asked for the root download URL, policy documents, and audit information.
- Mozilla representative — Added the request to the queue for public discussion.
- Protiviti representative — Said the latest FPKI audit had concluded and that the CA fell into Mozilla’s public disclosure/audit category for sub-CAs.
- Mozilla representative — Opened the first public discussion for the FCPCA root inclusion request.
- Mozilla representative — Said the US FPKI should be treated as a super-CA and that subordinate CAs should file separate inclusion bugs.
- Protiviti representative — Asked whether posting SSP CPS and audit letters would satisfy Mozilla’s requirements.
- Mozilla representative — Said the US FPKI would need public-facing SSP CP/CPS and annual audit statements, and that the policy must make those requirements clear.
- Protiviti representative — Reported that the Federal PKI was working on public SSP documents and a BR change proposal.
- Mozilla representative — Said it was reasonable to expect CP/CPS documents used for Mozilla inclusion not be redacted.
- Mozilla representative — Closed the bug and said the CA could re-apply by filing a new bug.