Visa request to add the Visa Information Delivery Root CA certificate was withdrawn
This case was Visa’s request to include the Visa Information Delivery Root CA certificate in Mozilla’s root store. The request began with Visa providing root and PKI details, audit history, and supporting documentation, while Mozilla asked for public CP/CPS information, test websites, CRL testing, and later BR audit and self-assessment materials. Over time, Visa provided updated policy documents, audit statements, a BR self-assessment, and test URLs, and Mozilla noted several remaining issues during review. The thread also references related concerns about SHA-1 issuance and other Visa bugs, but the case itself stayed focused on this root inclusion request. In the end, Mozilla recorded that Visa emailed saying it wanted to withdraw the request for this SHA1 root, and Visa said it might open a new request for a new SHA2 Root and ECC Root CA.
- Visa Information Delivery Root CA became valid.
- Visa opened the request to add the Visa Information Delivery Root CA certificate.
- Mozilla noted that Visa’s OCSP service was already implemented.
- Visa attached its BR self-assessment.
- Visa said it wanted to withdraw the request for this SHA1 root.
- Visa — Visa opened the bug and provided general and technical information about the Visa Information Delivery Root CA.
- Mozilla representative — Mozilla began information verification and asked for more public documentation and clarification about the CPS.
- Visa — Visa resubmitted the request with revised information and responses to Mozilla’s recommended practices questions.
- Mozilla representative — Mozilla asked for an HTTPS test site and reported a CRL import error in Firefox.
- Visa — Visa said it had published a DER-encoded CRL and would provide an HTTPS URL.
- Mozilla representative — Mozilla said the test website worked but CRL import still failed and OCSP was required under the Baseline Requirements.
- Visa — Visa responded to Mozilla’s BR-related questions about audit statements, BR commitment, MFA, network security, and SHA-1 certificates.
- Mozilla representative — Mozilla said the request still needed resolution of bug 1034834, a published CP/CPS with BR commitment, and a BR audit statement before public discussion.
- Visa — Visa said it had finished its 2016 WebTrust audit and would provide the report when received from KPMG.
- Mozilla representative — Mozilla noted that the BR audit had been provided.
- Visa — Visa confirmed that all exceptions had been remediated and would not appear in the next BR audit report.
- Mozilla representative — Mozilla said the Visa case was placed in the queue for public discussion.
- Mozilla representative — Mozilla asked Visa to complete a BR self-assessment and attach it to the bug.
- Visa — Visa attached the BR self-assessment.
- Mozilla representative — Mozilla said two items still needed input: test website URLs and an updated audit statement.
- Mozilla representative — Mozilla attached 2017 audit statements and moved the bug back to information verification.
- Mozilla representative — Mozilla said Visa emailed that it wanted to withdraw the request for this SHA1 root.