← U.S. Federal Public Key Infrastructure (US FPKI) cases
Bugzilla #478418 Ca Certificate Root Program

US FPKI request to add the Common Policy CA root to Mozilla’s trust store

RESOLVED WONTFIX U.S. Federal Public Key Infrastructure (US FPKI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was a request from the U.S. Federal PKI Management Authority to add the Federal Common Policy CA root certificate to Mozilla products. The request began in 2009 and was later updated to refer to a new Federal Common Policy CA (FCPCA) root established for the U.S. Federal government’s SHA-256 transition. Mozilla reviewers asked for root certificate details, audit information, CPS/CP documentation, and evidence that subordinate CAs met Mozilla policy requirements. Over time, the discussion focused on whether the FCPCA hierarchy should be treated as a super-CA, whether subordinate SSP CAs needed their own inclusion requests, and whether public CP/CPS and audit statements were available for those subordinate CAs. In 2015–2017, the CA reported work to publish SSP documents and align its policy with CA/Browser Forum Baseline Requirements, while Mozilla noted that redacted CPS documents were not ideal for inclusion requirements. The bug was ultimately closed WONTFIX, and Mozilla stated that the CA could re-apply by filing a new bug.

Model: gpt-5.4-mini Generated: 2026-06-13 12:11 UTC Revised: 2026-06-16 17:25 UTC Confidence: 0.93 83 comments
Chronology
  1. US FPKI requested Mozilla add the Common Policy CA root certificate to the default trust store.
  2. A new Federal Common Policy CA root was introduced to support the U.S. Federal government’s SHA-256 move.
  3. Mozilla opened the first public discussion for the FCPCA root inclusion request.
  4. Mozilla said the US FPKI hierarchy needed public-facing SSP documentation and audit statements to meet inclusion requirements.
  5. Mozilla closed the bug and said the CA could re-apply in a new request.
Thread Activity
  1. Protiviti representative — Requested that the Federal Common Policy Framework CA certificate be added to Mozilla’s default CA certificates.
  2. Mozilla representative — Accepted the bug and asked for the root download URL, policy documents, and audit information.
  3. Mozilla representative — Added the request to the queue for public discussion.
  4. Protiviti representative — Said the latest FPKI audit had concluded and that the CA fell into Mozilla’s public disclosure/audit category for sub-CAs.
  5. Mozilla representative — Opened the first public discussion for the FCPCA root inclusion request.
  6. Mozilla representative — Said the US FPKI should be treated as a super-CA and that subordinate CAs should file separate inclusion bugs.
  7. Protiviti representative — Asked whether posting SSP CPS and audit letters would satisfy Mozilla’s requirements.
  8. Mozilla representative — Said the US FPKI would need public-facing SSP CP/CPS and annual audit statements, and that the policy must make those requirements clear.
  9. Protiviti representative — Reported that the Federal PKI was working on public SSP documents and a BR change proposal.
  10. Mozilla representative — Said it was reasonable to expect CP/CPS documents used for Mozilla inclusion not be redacted.
  11. Mozilla representative — Closed the bug and said the CA could re-apply by filing a new bug.
Participants
Protiviti representative Mozilla representative Community commenter Deneb representative Briansmith representative Kuix representative Nasa representative Va representative Cequs representative Rossde representative DigiCert Konklone representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#520557 RESOLVED Ca Certificate Root Program Opened 2009-10-05 · Closed 2022-11-14 · 79% similar
Add Actalis Authentication Root CA certificate
#359069 RESOLVED Ca Certificate Root Program Opened 2006-11-01 · Closed 2022-11-14 · 78% similar
Request to add two additional IdenTrust root CA certificates
#455878 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-09-18 · Closed 2022-11-14 · 78% similar
Add CA Disig root certificate into browser
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 78% similar
Add Certigna certificates to Mozilla root CA list
#467891 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-12-04 · Closed 2022-11-14 · 77% similar
Add "D-TRUST Root Class 3 CA 2 2009" and "D-TRUST Root Class 3 CA 2 EV 2009"
#851435 RESOLVED Ca Certificate Root Program Ca Certificate Compliance Opened 2013-03-15 · Closed 2022-11-14 · 76% similar
WoSign two root certificate inclusion application
#1201423 RESOLVED Ca Certificate Root Program Opened 2015-09-03 · Closed 2022-11-14 · 76% similar
Add 2 HARICA Rollover Root CA Certificates
#408949 RESOLVED Ca Certificate Root Program Opened 2007-12-19 · Closed 2022-11-14 · 76% similar
Add Hongkong Post Root Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action