CCA India root certificate inclusion request and later withdrawal of the old hierarchy
This case began as a request to add the CCA India root certificate to Mozilla’s root store. The CA submitted its CA information checklist, subordinate CA details, hierarchy diagrams, policy documents, and later SSL verification guidelines and compliance material. Mozilla’s CA program lead accepted the bug and split the work into separate bugs for the seven intermediate CAs, with this root bug made dependent on those reviews. In 2014, the thread noted Google’s report of unauthorized certificates and that the NIC intermediate CA certificates had been revoked; Mozilla then discussed name constraints and the need for subordinate CAs to apply separately. In March 2015, the CA stated that it had a new CA hierarchy and that inclusion of certificates in the old hierarchy was no longer requested. The bug is resolved WONTFIX.
- CCA India requested inclusion of its root certificate in Mozilla’s root store.
- Mozilla split the hierarchy into separate intermediate CA reviews before considering the root.
- Unauthorized certificates were reported publicly in connection with India CCA.
- CCA India said the old CA hierarchy was no longer being requested for inclusion.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — Opened the bug and said the CA was looking forward to submitting details for inclusion of the Root CA certificate in Mozilla.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — Attached CA information, subordinate CA checklist, framework diagram, and intermediate CA details.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — Explained that seven intermediate CAs existed under the India root and that they shared a single CPS and audit framework.
- Mozilla representative — Accepted the bug and started the information gathering and verification phase.
- Mozilla representative — Summarized the seven intermediate CA hierarchies and their subordinate structures.
- Mozilla representative — Proposed creating separate bugs for each intermediate CA before evaluating the root certificate.
- Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) — Agreed to proceed and offered to provide more information if needed.
- Mozilla representative — Said the NIC intermediate CA would use the existing bug and that new bugs would be created for the other six intermediates.
- Mozilla representative — Listed the separate bugs for NIC, SafeScrypt, IDRBT, TCS, MTNL, nCode, and eMudhra.
- Mozilla representative — Asked when licensed CAs would comply with the new SSL guidelines and how compliance would be verified.
- Hboeck representative — Cited Google’s report that India CCA had issued unauthorized certificates and suggested closing the bug as WONTFIX.
- Mozilla representative — Quoted Google’s statement that NIC intermediate CA certificates were revoked and that Chrome would constrain the India CCA root to specific domains.
- Community commenter — Asked whether the proposed name constraints would also be acceptable for Firefox inclusion.
- Mozilla representative — Explained that this was a super-CA and that subordinate CAs needed to apply separately; noted NIC’s inclusion bug had been closed WONTFIX due to the incident.
- Mozilla representative — Recorded that CCA India said a new CA hierarchy existed and the old hierarchy was no longer requested for inclusion.