Netrust root certificate inclusion request and follow-up information review
Netrust Pte Ltd opened this bug to request inclusion of its root certificate in Mozilla. Mozilla requested the CA’s information checklist, direct URLs to policy documents, audit details, and clarification about whether the Netrust CA1 root signed end-entity certificates directly and whether EV treatment was being requested. Netrust replied that the root did sign end-entity certificates directly, had no subordinate CAs, and was not requesting EV treatment, and later provided verification procedure details and several audit-related attachments. Mozilla also noted that Netrust was a third-party reseller of Entrust SSL certificates for web sites and asked Netrust to identify which trust bits were being requested and to provide Netrust-specific SSL verification documentation if websites trust was sought. The bug was ultimately closed WONTFIX after no update from the CA for more than 1.5 years.
- Netrust requested Mozilla include the Netrust root certificate.
- Netrust stated the Netrust CA1 root signed end-entity certificates directly and had no subordinate CAs.
- Netrust described its subscriber verification procedures for certificate issuance.
- Mozilla closed the bug WONTFIX due to no CA update for more than 1.5 years.
- Netrust representative — Opened the bug to request inclusion of the Netrust root certificate in Mozilla.
- Mozilla representative — Marked bug 632251 as a duplicate of this bug and requested the remaining checklist information with direct URLs and section/page references.
- Netrust representative — Provided direct URLs for the root certificate and policy document.
- Mozilla representative — Asked whether the root signed end-entity certificates directly, whether there were subordinate CAs, and whether EV treatment was requested.
- Netrust representative — Confirmed the root signed end-entity certificates directly, had no subordinate CAs, and that EV treatment was not requested.
- Mozilla representative — Asked why the root directly signed end-entity certificates and requested the audit criteria and summary rather than the full audit report.
- Netrust representative — Added multiple audit-related attachments, including audit documents and auditor credentials.
- Mozilla representative — Asked which Mozilla-accepted audit criteria the audit statement corresponded to and requested clarification.
- Netrust representative — Stated that Netrust was an authorized distributor for Entrust SSL certificates and did not issue its own SSL certificates.
- Rossde representative — Commented that Netrust was merely a third-party reseller of Entrust certificates for web sites and that the request should not be approved for web sites.
- Mozilla representative — Asked Netrust to identify which trust bits were being requested and said Netrust-specific SSL verification documentation would be required for websites trust.
- Netrust representative — Described subscriber verification steps including proof of rights, domain ownership, DN checks, and employment verification.
- Mozilla representative — Requested the CP/CPS URLs and section numbers where the verification information could be found.
- Mozilla representative — Closed the bug WONTFIX because there had been no CA update for more than 1.5 years.