OATI root inclusion request for webCARES Root CA and replacement root
Open Access Technology International, Inc. (OATI) asked Mozilla to include its OATI webCARES root certificate in the trusted root list, initially requesting SSL/TLS and S/MIME trust bits and later asking about code signing as well. Mozilla reviewers identified several issues during verification, including missing OCSP support on the test site, lint failures in the original root certificate, and later the need for a BR self-assessment and updated audit and CPS materials. OATI responded by providing additional information, fixing test websites, and eventually attaching a replacement root certificate intended to address the outstanding lint and policy issues. Mozilla then required three test websites chaining to the new 2018 root and noted that the existing test sites did not chain to that root. In 2023, OATI said it was fine to close the bug and that it would submit a new request once new material was ready; the bug was then intended to be closed.
- OATI requested Mozilla inclusion of the OATI webCARES root certificate.
- OATI completed and attached a BR self-assessment.
- OATI attached a replacement root certificate.
- Mozilla said the provided test websites did not chain to the requested webCARES Root CA 2018 root.
- OATI said it was fine to close the request and that it would submit a new request later.
- Oati representative — OATI opened the bug asking Mozilla to include the OATI webCARES CA certificate and provided the root certificate, CPS URL, and test website URL.
- Mozilla representative — Mozilla said SSL trust required CA/B Forum Baseline Requirements compliance and confirmed OCSP was required for the hierarchy.
- Oati representative — OATI provided answers on validation, current audit statements, and said code signing trust was not needed.
- Mozilla representative — Mozilla said the request had been added to the queue for public discussion and asked for new audit statements.
- Mozilla representative — Mozilla asked OATI to complete a BR self-assessment.
- Mozilla representative — Mozilla reported remaining issues with test websites and lint errors and asked OATI to fix them.
- Mozilla representative — Mozilla said new inclusions must have all existing unexpired unrevoked certs in the hierarchy BR-compliant and asked OATI to update the bug with its chosen solution.
- Oati representative — OATI attached a replacement root cert and said it fixed the outstanding test and lint issues.
- Mozilla representative — Mozilla said the audit statements needed SHA256 fingerprints, the CPS needed a revision table and removal of confidentiality notices, and three test websites chaining to the new root were still needed.
- Mozilla representative — Mozilla noted the problem still appeared to be present because the chain went to the old root rather than webCARES Root CA 2018.
- Oati representative — OATI said it was fine to close the bug and that it would submit a new request once ready.