ComSign Global Root CA inclusion request and public discussion
ComSign requested Mozilla inclusion of a new root certificate, ComSign Global Root CA, initially described as a SHA-256 root with a 4096-bit public key. The request evolved over time as ComSign clarified that the new root was intended to replace its existing ComSign CA root, and Mozilla asked for supporting information including test websites, trust bits, CP/CPS documents, audit statements, and verification procedures. The discussion also covered OCSP/revocation testing, updated CPS versions, and a BR self-assessment that ComSign later provided. Mozilla ultimately denied the inclusion request after public discussion concerns, and stated that ComSign may submit a newly generated root and key-pair for inclusion. The bug was then moved to on-hold pending submission of the new root.
- ComSign requested inclusion of a new ComSign Global Root CA certificate.
- ComSign provided an audit report for the root request.
- Mozilla opened public discussion for the ComSign Global Root CA request with Websites and Email trust bits.
- ComSign submitted a BR self-assessment and announced CPS version 4.0.
- Mozilla denied the inclusion request and said ComSign may submit a newly generated root and key-pair.
- Mozilla representative — Mozilla recorded ComSign's request to include a new root certificate with SHA-256 and a 4096-bit key.
- Comda representative — ComSign said the new root would replace its current Comsign CA root and that the CPS was the same as the one used for the first root.
- Comda representative — ComSign corrected the case information, listed its company website, described the root hierarchy, and said the root was for email signing only at that time.
- Mozilla representative — Mozilla opened public discussion for the request and said the root would eventually replace the ComSign CA root already included in NSS.
- Mozilla representative — Mozilla said the WebTrust audit statements had been confirmed by the auditor and that the remaining action item was an updated/restructured CPS.
- Comda representative — ComSign said it had completed the BR self-assessment and published CPS version 4.0 with several links.
- Mozilla representative — Mozilla said it had verified CPS v4.0 and the BR self-assessment and updated CCADB accordingly.
- Fastly representative — Mozilla said it was denying the inclusion request due to concerns raised during public discussion and moved the bug on hold pending a newly generated root and key-pair.