KIR S.A. root inclusion request for SZAFIR ROOT CA
This case is KIR S.A.'s request to include the SZAFIR ROOT CA in Mozilla's Root Certificate Program. The request began in December 2012 and moved through information verification, public discussion, and follow-up review of KIR's CP/CPS, audit statements, and technical compliance details. Mozilla asked KIR to address Baseline Requirements issues including OCSP/CRL behavior, revocation handling, certificate profiles, and the treatment of ELIXIR certificates. KIR reported updates to its CPS and CP, provided audit statements, and made additional technical changes, including adding clientAuth EKU to future ELIXIR certificates and fixing OCSP/header issues. Mozilla later approved the request for the original root, and the thread also records later updates for a regenerated root certificate and related NSS work.
- KIR opened a request to include SZAFIR ROOT CA in Mozilla's root program.
- Mozilla opened the first public discussion period for the root inclusion request.
- Mozilla opened the second public discussion period for the request.
- Mozilla approved inclusion of SZAFIR ROOT CA for websites, email, and code signing.
- Mozilla updated the discussion for the regenerated root certificate and noted no concerns were raised.
- Kir representative — KIR opened the bug and attached the initial CA information and an example certificate.
- Mozilla representative — Mozilla started information verification and clarified that the request was for inclusion of SZAFIR ROOT CA.
- Mozilla representative — Mozilla asked KIR to revoke the old intermediate certificate, re-evaluate BR compliance, and provide a BR audit statement.
- Kir representative — KIR said all new SSL certs would be BR-compliant and that it would start using a new intermediate certificate after acceptance.
- Mozilla representative — Mozilla opened the first public discussion period for inclusion of SZAFIR ROOT CA.
- Mozilla representative — Mozilla listed action items for CPS and CRL updates before the second discussion period.
- Kir representative — KIR said it had completed the action items and published updated CPS and CP documents.
- Kir representative — KIR responded to revocation-related concerns and said it had started publishing CRLs with AKI and IDP.
- Kir representative — KIR clarified that ELIXIR certificates have no EKU extension and are not for server authentication, and offered to add clientAuth EKU.
- Kir representative — KIR reported a test showing Firefox returned ssl_error_bad_cert_domain when an ELIXIR cert was used as an SSL cert.
- Kir representative — KIR said future ELIXIR certificates would include id-kp-clientAuth starting 2015-02-15 and that CPS would be updated.
- Mozilla representative — Mozilla opened the second public discussion period for the request.
- Mozilla representative — Mozilla approved the request for SZAFIR ROOT CA with websites, email, and code signing trust bits.
- Mozilla representative — Mozilla updated the discussion for the regenerated root certificate and noted the replacement root data had been added to bug 1157375.