TWCA root inclusion request for the TWCA Root Certification Authority
This case is TWCA’s request to add the “TWCA Root Certification Authority” root certificate to Mozilla and enable the Websites and Email trust bits. TWCA initially submitted details for a 2048-bit root and also mentioned a 4096-bit root, but Mozilla asked about the duplicate issuer DN and serial number, and TWCA later said it would proceed with only the 2048-bit certificate for Mozilla. The thread focused on document review, validation practices, hierarchy details, and audit evidence, including updates to the TWCA UCA CPS and related policy documents. TWCA also fixed a test website issue where the intermediate CA certificate was not being sent during SSL handshaking. Mozilla opened public discussion, completed its assessment, and then approved the request; the bug was filed against NSS for the actual changes and was resolved fixed.
- TWCA Root Certification Authority root inclusion request was submitted with 2048-bit root details.
- Mozilla raised a problem with TWCA using the same issuer DN and serial number for both the 2048-bit and 4096-bit root certificates.
- TWCA fixed the SSL test website so the intermediate CA certificate was sent during SSL handshaking.
- Mozilla opened public discussion for adding the TWCA Root Certification Authority root certificate and enabling Websites and Email trust bits.
- Mozilla approved inclusion of the TWCA Root Certification Authority root certificate for websites and email.
- Community commenter — TWCA opened the request with root certificate details, audit information, and requested trust bits for email, SSL, and code signing.
- Mozilla representative — Mozilla accepted the bug and began information gathering and verification.
- Velox representative — Mozilla noted that the 2048-bit and 4096-bit roots used the same issuer DN and serial number, which NSS could not handle well.
- Community commenter — TWCA said it would proceed with only the 2048-bit certificate for Mozilla and postpone the 4096-bit certificate until internal issues were solved.
- Taiwan-CA Inc. (TWCA) — TWCA said the test website had been fixed because the sub-CA certificate had not been installed on the web server.
- Taiwan-CA Inc. (TWCA) — TWCA uploaded a CPS update stating that SSL server and CXML certificate subscriber information must be verified before issuance.
- Mozilla representative — Mozilla opened the first public discussion period for the TWCA root inclusion request.
- Mozilla representative — Mozilla summarized the assessment and said it intended to approve the request for the root certificate and Websites and Email trust bits.
- Mozilla representative — Mozilla approved inclusion of the TWCA Root Certification Authority root certificate and said the NSS bug would implement the changes.