HARICA request to add the Hellenic Academic and Research Institutions RootCA 2011 root certificate
HARICA opened this case to request Mozilla inclusion of its root certificate, initially describing the Hellenic Academic and Research Institutions RootCA 2006 and later updating the request to the Hellenic Academic and Research Institutions RootCA 2011. The thread records Mozilla’s information-gathering and verification process, including requests for audit evidence, CP/CPS updates, and confirmation of CRL/OCSP support. HARICA provided audit reports, updated its CP/CPS, enabled OCSP for the new hierarchy, and later implemented name constraints after discussion in the Mozilla security policy mailing list. Mozilla then opened public discussion and, after the discussion period ended, approved inclusion of the Hellenic Academic and Research Institutions RootCA 2011 for websites, email, and code. The bug was later marked resolved, and the NSS follow-up bug was filed separately as bug 711594.
- HARICA requested Mozilla inclusion of its root certificate hierarchy.
- HARICA reported completion of an ETSI TS 101 456 audit and CP/CPS updates.
- HARICA enabled OCSP support for https://www2.harica.gr under the new SHA1 root CA.
- HARICA implemented the name constraints extension for the new root.
- Mozilla approved inclusion of the Hellenic Academic and Research Institutions RootCA 2011 root certificate.
- HARICA — HARICA requested addition of its root certificate and described its PKI, audit plans, and certificate usage.
- Mozilla representative — Mozilla accepted the bug and began the information-gathering and verification phase.
- HARICA — HARICA said it had completed an ETSI TS 101 456 audit and updated its CP/CPS.
- Mozilla representative — Mozilla asked whether CRL and OCSP support had been implemented for the new root.
- HARICA — HARICA said OCSP support had been enabled for https://www2.harica.gr under the new SHA1 root CA.
- HARICA — HARICA responded to Mozilla’s security questions about audits, cross-signing, MFA, domain restrictions, and third-party subordinate CAs.
- HARICA — HARICA said the OCSP daemon issue had been fixed and confirmed the information in the gathering document was current and correct.
- Mozilla representative — Mozilla opened the first public discussion period for the request to add the Hellenic Academic and Research Institutions RootCA 2011 root certificate and enable all three trust bits.
- HARICA — HARICA reported that it had implemented the name constraints extension and updated the CP/CPS.
- Mozilla representative — Mozilla summarized the assessment after public comment, including validation, hierarchy, and audit findings.
- Mozilla representative — Mozilla approved inclusion of the Hellenic Academic and Research Institutions RootCA 2011 root certificate.
- Mozilla representative — Mozilla noted that the root certificate was a Builtin Object Token in Firefox 11.