Netlock root rollover and inclusion request for NetLock Arany (Class Gold) Főtanúsítvány
Netlock opened this bug to request inclusion of a new root certificate as part of a rollover from four existing built-in Netlock roots to a new common root. The request also sought trust-bit enablement for websites, email, and code signing, and it included subordinate CA information for internally operated and externally operated sub-CAs. Mozilla asked for translated CPS material, hierarchy details, CRL and OCSP information, subordinate CA checklists, a test website, and audit evidence. Netlock provided translated CPS documents, subordinate checklists, CRL and OCSP details, and audit materials, and Mozilla later confirmed that the request was ready for public discussion. After public discussion, Mozilla approved inclusion of the NetLock Arany (Class Gold) Főtanúsítvány root certificate with web sites, email, and code signing trust bits, and filed NSS bug 532201 for the actual changes. An action item remained for Netlock to consolidate its SSL domain-validation documentation into the new CPS, and Netlock later said that work was still in process.
- Netlock requested rollover to a new common root for its existing built-in roots.
- Mozilla opened first public discussion for inclusion of the new NetLock Arany root with all three trust bits.
- Mozilla approved inclusion of the new root with web sites, email, and code signing trust bits.
- Mozilla filed NSS bug 532201 for the approved root changes.
- Netlock — Netlock said it wanted to start a rollover of its existing roots and include a new root certificate.
- Mozilla representative — Mozilla accepted the bug and began information gathering and verification.
- Netlock — Netlock answered Mozilla’s questions about hierarchy, subordinate CAs, CRL availability, and EV timing.
- Mozilla representative — Mozilla asked for clarification about the externally operated sub-CAs and what was needed before public discussion.
- Community commenter — Netlock confirmed that MKB and MNB only issue certificates to their own employees and provided hierarchy plans.
- Netlock — Netlock provided audit-related attachments and said the new root was covered by the latest audit report.
- Mozilla representative — Mozilla said the necessary information had been gathered and placed the request in the queue for public discussion.
- Mozilla representative — Mozilla opened the first public discussion period for the request.
- Mozilla representative — Mozilla summarized the request and noted the remaining action item to consolidate SSL domain-validation documentation into the new CPS.
- Mozilla representative — Mozilla approved the request and said it would file the NSS bug for the changes.
- Netlock — Netlock said the CPS work was under process and that it would post the updated links when accepted.