← Netrust Pte Ltd cases
Bugzilla #632292 Root Inclusion

Netrust root certificate inclusion request and follow-up information review

RESOLVED WONTFIX Netrust Pte Ltd
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Netrust Pte Ltd opened this bug to request inclusion of its root certificate in Mozilla. Mozilla requested the CA’s information checklist, direct URLs to policy documents, audit details, and clarification about whether the Netrust CA1 root signed end-entity certificates directly and whether EV treatment was being requested. Netrust replied that the root did sign end-entity certificates directly, had no subordinate CAs, and was not requesting EV treatment, and later provided verification procedure details and several audit-related attachments. Mozilla also noted that Netrust was a third-party reseller of Entrust SSL certificates for web sites and asked Netrust to identify which trust bits were being requested and to provide Netrust-specific SSL verification documentation if websites trust was sought. The bug was ultimately closed WONTFIX after no update from the CA for more than 1.5 years.

Model: gpt-5.4-mini Generated: 2026-06-13 12:17 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.95 32 comments
Chronology
  1. Netrust requested Mozilla include the Netrust root certificate.
  2. Netrust stated the Netrust CA1 root signed end-entity certificates directly and had no subordinate CAs.
  3. Netrust described its subscriber verification procedures for certificate issuance.
  4. Mozilla closed the bug WONTFIX due to no CA update for more than 1.5 years.
Thread Activity
  1. Netrust representative — Opened the bug to request inclusion of the Netrust root certificate in Mozilla.
  2. Mozilla representative — Marked bug 632251 as a duplicate of this bug and requested the remaining checklist information with direct URLs and section/page references.
  3. Netrust representative — Provided direct URLs for the root certificate and policy document.
  4. Mozilla representative — Asked whether the root signed end-entity certificates directly, whether there were subordinate CAs, and whether EV treatment was requested.
  5. Netrust representative — Confirmed the root signed end-entity certificates directly, had no subordinate CAs, and that EV treatment was not requested.
  6. Mozilla representative — Asked why the root directly signed end-entity certificates and requested the audit criteria and summary rather than the full audit report.
  7. Netrust representative — Added multiple audit-related attachments, including audit documents and auditor credentials.
  8. Mozilla representative — Asked which Mozilla-accepted audit criteria the audit statement corresponded to and requested clarification.
  9. Netrust representative — Stated that Netrust was an authorized distributor for Entrust SSL certificates and did not issue its own SSL certificates.
  10. Rossde representative — Commented that Netrust was merely a third-party reseller of Entrust certificates for web sites and that the request should not be approved for web sites.
  11. Mozilla representative — Asked Netrust to identify which trust bits were being requested and said Netrust-specific SSL verification documentation would be required for websites trust.
  12. Netrust representative — Described subscriber verification steps including proof of rights, domain ownership, DN checks, and employment verification.
  13. Mozilla representative — Requested the CP/CPS URLs and section numbers where the verification information could be found.
  14. Mozilla representative — Closed the bug WONTFIX because there had been no CA update for more than 1.5 years.
Participants
Netrust representative Community commenter Mozilla representative Rossde representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#848766 RESOLVED Root Inclusion Opened 2013-03-07 · Closed 2023-02-24 · 86% similar
Add OATI's Root CA Certificate to Mozilla's trusted root list
#636557 RESOLVED Root Inclusion Opened 2011-02-24 · Closed 2022-11-14 · 80% similar
Add Visa Information Delivery Root CA certificate
#1277336 RESOLVED Root Inclusion Trust Bit Enablement Ev Enablement Opened 2016-06-01 · Closed 2022-11-14 · 80% similar
Add SSL.com root certificate(s)
#467891 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-12-04 · Closed 2022-11-14 · 80% similar
Add "D-TRUST Root Class 3 CA 2 2009" and "D-TRUST Root Class 3 CA 2 EV 2009"
#480966 RESOLVED Root Inclusion Opened 2009-03-02 · Closed 2022-11-14 · 79% similar
Netlock Root CA rollover request
#368970 RESOLVED Root Inclusion Opened 2007-02-01 · Closed 2022-11-14 · 79% similar
Add French Government (DCSSI) CA certificate
#1128392 RESOLVED Root Inclusion Opened 2015-02-02 · Closed 2022-11-14 · 79% similar
Add GDCA Root Certificate
#1265683 RESOLVED Root Inclusion Opened 2016-04-19 · Closed 2026-05-21 · 79% similar
Add [Certigna Root CA] root certificate(s)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action