NIC (India) root inclusion request for NIC Certifying Authority
This case was an application from National Informatics Centre (NIC) to add the “NIC Certifying Authority” certificate to Mozilla’s trust store. The request initially included the NICCA certificate and later clarified that NICCA was an intermediate CA under the CCA India hierarchy, not the root. Mozilla asked for hierarchy details, CPS updates, and an auditor statement to verify compliance information such as domain validation and audit scope. The CA provided a hierarchy diagram, updated CPS material, and an audit equivalency certificate, and Mozilla confirmed the audit statement’s authenticity. In 2011 Mozilla opened public discussion for the request, but in 2013–2014 the thread became inactive; after a 2014 report of misissued certificates and a note that the intermediate CA certificates held by NIC were revoked on July 3, the request was treated as closed.
- NIC submitted a request to include the NIC Certifying Authority certificate in Mozilla.
- NIC clarified that it had one Sub-CA and that NICCA issued certificates directly to users and user systems.
- Mozilla said the CCA root would be evaluated as the trust anchor and that NICCA would not be included separately.
- Mozilla opened the first public discussion period for the NIC root inclusion request.
- NIC said it had published a CPS addendum dated 10 Jan 2013 for enrolling the root certificate under Mozilla.
- Mozilla noted that the intermediate CA certificates held by NIC were revoked on July 3 and said the request could be closed.
- Community commenter — NIC opened the bug and provided organizational, root certificate, hierarchy, and usage details for the request.
- Mozilla representative — Mozilla accepted the bug and began information gathering and verification.
- Community commenter — NIC explained its CA hierarchy, email verification, SSL domain verification, and audit practices.
- Mozilla representative — Mozilla said it would proceed with the CCA root as the trust anchor and that NICCA would not be included separately.
- Mozilla representative — Mozilla requested more detail on audit authenticity, domain verification, and RA controls.
- Community commenter — NIC answered that a new audit had been conducted, described domain verification steps, and said RAs were audited under CCA guidelines.
- Mozilla representative — Mozilla confirmed the authenticity of the audit equivalency certificate with CyberQ Consulting.
- Mozilla representative — Mozilla opened public discussion for the NIC root inclusion request.
- Community commenter — NIC stated that it had published a CPS addendum dated 10 Jan 2013 for enrolling the root certificate under Mozilla.
- Dominia representative — A commenter cited recent misissued certificates issued by the organization and argued the request should be rejected.
- Mozilla representative — Mozilla noted that the intermediate CA certificates held by NIC were revoked on July 3 and said the inclusion request could be closed.