← Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) cases
Bugzilla #511380 Root Inclusion

NIC (India) root inclusion request for NIC Certifying Authority

RESOLVED WONTFIX Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was an application from National Informatics Centre (NIC) to add the “NIC Certifying Authority” certificate to Mozilla’s trust store. The request initially included the NICCA certificate and later clarified that NICCA was an intermediate CA under the CCA India hierarchy, not the root. Mozilla asked for hierarchy details, CPS updates, and an auditor statement to verify compliance information such as domain validation and audit scope. The CA provided a hierarchy diagram, updated CPS material, and an audit equivalency certificate, and Mozilla confirmed the audit statement’s authenticity. In 2011 Mozilla opened public discussion for the request, but in 2013–2014 the thread became inactive; after a 2014 report of misissued certificates and a note that the intermediate CA certificates held by NIC were revoked on July 3, the request was treated as closed.

Model: gpt-5.4-mini Generated: 2026-06-13 12:13 UTC Revised: 2026-06-16 19:07 UTC Confidence: 0.93 46 comments
Chronology
  1. NIC submitted a request to include the NIC Certifying Authority certificate in Mozilla.
  2. NIC clarified that it had one Sub-CA and that NICCA issued certificates directly to users and user systems.
  3. Mozilla said the CCA root would be evaluated as the trust anchor and that NICCA would not be included separately.
  4. Mozilla opened the first public discussion period for the NIC root inclusion request.
  5. NIC said it had published a CPS addendum dated 10 Jan 2013 for enrolling the root certificate under Mozilla.
  6. Mozilla noted that the intermediate CA certificates held by NIC were revoked on July 3 and said the request could be closed.
Thread Activity
  1. Community commenter — NIC opened the bug and provided organizational, root certificate, hierarchy, and usage details for the request.
  2. Mozilla representative — Mozilla accepted the bug and began information gathering and verification.
  3. Community commenter — NIC explained its CA hierarchy, email verification, SSL domain verification, and audit practices.
  4. Mozilla representative — Mozilla said it would proceed with the CCA root as the trust anchor and that NICCA would not be included separately.
  5. Mozilla representative — Mozilla requested more detail on audit authenticity, domain verification, and RA controls.
  6. Community commenter — NIC answered that a new audit had been conducted, described domain verification steps, and said RAs were audited under CCA guidelines.
  7. Mozilla representative — Mozilla confirmed the authenticity of the audit equivalency certificate with CyberQ Consulting.
  8. Mozilla representative — Mozilla opened public discussion for the NIC root inclusion request.
  9. Community commenter — NIC stated that it had published a CPS addendum dated 10 Jan 2013 for enrolling the root certificate under Mozilla.
  10. Dominia representative — A commenter cited recent misissued certificates issued by the organization and argued the request should be rejected.
  11. Mozilla representative — Mozilla noted that the intermediate CA certificates held by NIC were revoked on July 3 and said the inclusion request could be closed.
Participants
Community commenter Mozilla representative Bolyard representative Startcom representative Dominia representative Vickyshah representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#512973 RESOLVED Root Inclusion Opened 2009-08-27 · Closed 2022-11-14 · 93% similar
Pre-install India's Root CA/Licensed CA authorities trusted by Root CA into Firefox
#370505 RESOLVED Root Inclusion Opened 2007-02-15 · Closed 2022-11-14 · 91% similar
Add Microsec Ltd root CA certificate
#480966 RESOLVED Root Inclusion Opened 2009-03-02 · Closed 2022-11-14 · 88% similar
Netlock Root CA rollover request
#335197 RESOLVED Root Inclusion Opened 2006-04-24 · Closed 2022-11-14 · 88% similar
Add KISA root CA Certificate
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 87% similar
Add Certigna certificates to Mozilla root CA list
#1204656 RESOLVED Root Inclusion Opened 2015-09-14 · Closed 2022-11-14 · 86% similar
Add ISRG / Let's Encrypt root certificate
#368970 RESOLVED Root Inclusion Opened 2007-02-01 · Closed 2022-11-14 · 86% similar
Add French Government (DCSSI) CA certificate
#476766 VERIFIED Root Inclusion Opened 2009-02-04 · Closed 2022-11-14 · 86% similar
Add China Internet Network Information Center (CNNIC) CA Root Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action