← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #817994 Ca Certificate Root Program Root Inclusion

KIR S.A. root inclusion request for SZAFIR ROOT CA

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is KIR S.A.'s request to include the SZAFIR ROOT CA in Mozilla's Root Certificate Program. The request began in December 2012 and moved through information verification, public discussion, and follow-up review of KIR's CP/CPS, audit statements, and technical compliance details. Mozilla asked KIR to address Baseline Requirements issues including OCSP/CRL behavior, revocation handling, certificate profiles, and the treatment of ELIXIR certificates. KIR reported updates to its CPS and CP, provided audit statements, and made additional technical changes, including adding clientAuth EKU to future ELIXIR certificates and fixing OCSP/header issues. Mozilla later approved the request for the original root, and the thread also records later updates for a regenerated root certificate and related NSS work.

Model: gpt-5.4-mini Generated: 2026-06-13 13:00 UTC Revised: 2026-06-16 17:28 UTC Confidence: 0.98 73 comments
Chronology
  1. KIR opened a request to include SZAFIR ROOT CA in Mozilla's root program.
  2. Mozilla opened the first public discussion period for the root inclusion request.
  3. Mozilla opened the second public discussion period for the request.
  4. Mozilla approved inclusion of SZAFIR ROOT CA for websites, email, and code signing.
  5. Mozilla updated the discussion for the regenerated root certificate and noted no concerns were raised.
Thread Activity
  1. Kir representative — KIR opened the bug and attached the initial CA information and an example certificate.
  2. Mozilla representative — Mozilla started information verification and clarified that the request was for inclusion of SZAFIR ROOT CA.
  3. Mozilla representative — Mozilla asked KIR to revoke the old intermediate certificate, re-evaluate BR compliance, and provide a BR audit statement.
  4. Kir representative — KIR said all new SSL certs would be BR-compliant and that it would start using a new intermediate certificate after acceptance.
  5. Mozilla representative — Mozilla opened the first public discussion period for inclusion of SZAFIR ROOT CA.
  6. Mozilla representative — Mozilla listed action items for CPS and CRL updates before the second discussion period.
  7. Kir representative — KIR said it had completed the action items and published updated CPS and CP documents.
  8. Kir representative — KIR responded to revocation-related concerns and said it had started publishing CRLs with AKI and IDP.
  9. Kir representative — KIR clarified that ELIXIR certificates have no EKU extension and are not for server authentication, and offered to add clientAuth EKU.
  10. Kir representative — KIR reported a test showing Firefox returned ssl_error_bad_cert_domain when an ELIXIR cert was used as an SSL cert.
  11. Kir representative — KIR said future ELIXIR certificates would include id-kp-clientAuth starting 2015-02-15 and that CPS would be updated.
  12. Mozilla representative — Mozilla opened the second public discussion period for the request.
  13. Mozilla representative — Mozilla approved the request for SZAFIR ROOT CA with websites, email, and code signing trust bits.
  14. Mozilla representative — Mozilla updated the discussion for the regenerated root certificate and noted the replacement root data had been added to bug 1157375.
Participants
Kir representative Mozilla representative Abalea representative Docusign representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#944783 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2013-11-29 · Closed 2022-11-14 · 89% similar
Add LuxTrust Global Root CA Certificate
#455878 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-09-18 · Closed 2022-11-14 · 82% similar
Add CA Disig root certificate into browser
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 82% similar
Add Certigna certificates to Mozilla root CA list
#1710831 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2021-05-12 · Closed 2023-08-01 · 81% similar
Add LAWtrust Root CA2 to NSS
#926029 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2013-10-12 · Closed 2022-11-14 · 81% similar
CFCA (China Financial Certification Authority) root CA
#711366 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2011-12-16 · Closed 2022-11-14 · 80% similar
Add Atos Trustcenter CA cert to trusted root CA cert list
#1313982 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2016-10-31 · Closed 2025-04-02 · 80% similar
Add SECOM root certificates
#467891 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2008-12-04 · Closed 2022-11-14 · 80% similar
Add "D-TRUST Root Class 3 CA 2 2009" and "D-TRUST Root Class 3 CA 2 EV 2009"

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action