← Open Access Technology International, Inc. (OATI) cases
Bugzilla #848766 Root Inclusion

OATI root inclusion request for webCARES Root CA and replacement root

RESOLVED WONTFIX Open Access Technology International, Inc. (OATI)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Open Access Technology International, Inc. (OATI) asked Mozilla to include its OATI webCARES root certificate in the trusted root list, initially requesting SSL/TLS and S/MIME trust bits and later asking about code signing as well. Mozilla reviewers identified several issues during verification, including missing OCSP support on the test site, lint failures in the original root certificate, and later the need for a BR self-assessment and updated audit and CPS materials. OATI responded by providing additional information, fixing test websites, and eventually attaching a replacement root certificate intended to address the outstanding lint and policy issues. Mozilla then required three test websites chaining to the new 2018 root and noted that the existing test sites did not chain to that root. In 2023, OATI said it was fine to close the bug and that it would submit a new request once new material was ready; the bug was then intended to be closed.

Model: gpt-5.4-mini Generated: 2026-06-13 13:00 UTC Revised: 2026-06-16 17:28 UTC Confidence: 0.96 72 comments
Chronology
  1. OATI requested Mozilla inclusion of the OATI webCARES root certificate.
  2. OATI completed and attached a BR self-assessment.
  3. OATI attached a replacement root certificate.
  4. Mozilla said the provided test websites did not chain to the requested webCARES Root CA 2018 root.
  5. OATI said it was fine to close the request and that it would submit a new request later.
Thread Activity
  1. Oati representative — OATI opened the bug asking Mozilla to include the OATI webCARES CA certificate and provided the root certificate, CPS URL, and test website URL.
  2. Mozilla representative — Mozilla said SSL trust required CA/B Forum Baseline Requirements compliance and confirmed OCSP was required for the hierarchy.
  3. Oati representative — OATI provided answers on validation, current audit statements, and said code signing trust was not needed.
  4. Mozilla representative — Mozilla said the request had been added to the queue for public discussion and asked for new audit statements.
  5. Mozilla representative — Mozilla asked OATI to complete a BR self-assessment.
  6. Mozilla representative — Mozilla reported remaining issues with test websites and lint errors and asked OATI to fix them.
  7. Mozilla representative — Mozilla said new inclusions must have all existing unexpired unrevoked certs in the hierarchy BR-compliant and asked OATI to update the bug with its chosen solution.
  8. Oati representative — OATI attached a replacement root cert and said it fixed the outstanding test and lint issues.
  9. Mozilla representative — Mozilla said the audit statements needed SHA256 fingerprints, the CPS needed a revision table and removal of confidentiality notices, and three test websites chaining to the new root were still needed.
  10. Mozilla representative — Mozilla noted the problem still appeared to be present because the chain went to the old root rather than webCARES Root CA 2018.
  11. Oati representative — OATI said it was fine to close the bug and that it would submit a new request once ready.
Participants
Oati representative Mozilla representative Community commenter Rossde representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#636557 RESOLVED Root Inclusion Opened 2011-02-24 · Closed 2022-11-14 · 88% similar
Add Visa Information Delivery Root CA certificate
#675060 RESOLVED Root Inclusion Opened 2011-07-28 · Closed 2022-11-14 · 87% similar
Add Comsign Global Root CA certificate
#1265683 RESOLVED Root Inclusion Opened 2016-04-19 · Closed 2026-05-21 · 87% similar
Add [Certigna Root CA] root certificate(s)
#632292 RESOLVED Root Inclusion Opened 2011-02-08 · Closed 2022-11-14 · 86% similar
Add Netrust root certificate
#1710831 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2021-05-12 · Closed 2023-08-01 · 86% similar
Add LAWtrust Root CA2 to NSS
#1128392 RESOLVED Root Inclusion Opened 2015-02-02 · Closed 2022-11-14 · 86% similar
Add GDCA Root Certificate
#1277336 RESOLVED Root Inclusion Trust Bit Enablement Ev Enablement Opened 2016-06-01 · Closed 2022-11-14 · 85% similar
Add SSL.com root certificate(s)
#1313982 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2016-10-31 · Closed 2025-04-02 · 85% similar
Add SECOM root certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action