Entrust request to replace the Entrust.net Certification Authority (2048) root and enable EV
This case concerns Entrust’s request to replace the existing "Entrust.net Certification Authority (2048)" root certificate while keeping its trust bits enabled and enabling EV. Entrust provided details for the existing root and a new "Entrust Root Certification Authority - G2" root, but the G2 inclusion was later split into a separate bug. Mozilla requested and reviewed CA information, discussed EV testing requirements, and asked Entrust to provide a working EV test site chained through the correct certificate path. Mozilla approved the root update for the Entrust.net Certification Authority (2048) root, and noted that EV treatment would be handled separately after successful EV testing. The thread also records that bug 856678 was filed for the actual NSS root replacement, and bug 1102519 was filed later for EV treatment.
- Entrust requested replacement of the Entrust.net Certification Authority (2048) root certificate and provided a new G2 root for consideration.
- The G2 root inclusion was moved to a separate bug, leaving this bug focused on the replacement root certificate.
- Mozilla approved updating the Entrust.net Certification Authority (2048) root certificate and keeping all three trust bits enabled.
- Entrust updated the 2048 test site to use a test certificate issued from an intermediate CA, and Mozilla filed bug 1102519 for EV treatment.
- Entrust representative — Bruce Morton opened the request and attached the Entrust.net Certification Authority (2048) root certificate and the Entrust Root Certification Authority - G2 root certificate.
- Mozilla representative — Kathleen Wilson said she hoped to begin information verification soon and would update the bug later.
- Mozilla representative — Kathleen reported an OCSP error when visiting the G2 test site and said the CRL link did not seem to work.
- Entrust representative — Bruce said the G2 root was not in production and that CRL or OCSP support was not currently being provided for it.
- Mozilla representative — Kathleen said she could start discussion for the 2048 root once there was a test website with an EV SSL cert chaining to that root and EV testing was completed.
- Entrust representative — Bruce provided an EV test site for the 2048 root and said the certificate had expired.
- Mozilla representative — Kathleen asked Bruce to issue a new certificate for the EV test site.
- Mozilla representative — Kathleen said the G2 root inclusion had been moved to bug 849950 and that this bug would cover only the replacement of the Entrust.net Certification Authority (2048) root certificate.
- Entrust representative — Bruce said the CNNIC cross-certificate had expired, the CPS documents had been updated, and OCSP responses were generated every 8 hours.
- Mozilla representative — Kathleen opened public discussion for Entrust’s request to replace the root, keep all three trust bits enabled, and enable EV.
- Mozilla representative — Kathleen approved the request to update the Entrust.net Certification Authority (2048) root certificate and said EV-enablement would wait for successful EV testing.
- Entrust representative — Bruce said the 2048 test site had been updated with a test certificate issued from an intermediate CA.
- Mozilla representative — Kathleen posted EV checking tool output showing success and said she had filed bug 1102519 for enabling EV treatment for this root.