AC Camerfirma request to add renewed root certificates was denied after review
This case concerned AC Camerfirma’s request to add renewed root certificates for its Chambers of Commerce and Global Chambersign hierarchies. The request began with Camerfirma reporting that browsers did not recognize the new SHA-256 root certificates as valid roots or for EV use. Mozilla then worked through information verification, audit statements, lint/test issues, and BR self-assessment materials with the CA over an extended period. Camerfirma provided updated audit reports, corrected root fingerprint information, and supplied test website URLs and policy documents as requested. The discussion was eventually opened on Mozilla’s CA policy mailing list, and the request was denied, with the bug closed WONTFIX.
- Camerfirma reported that new SHA-256 root certificates were not recognized as valid roots or for EV.
- Mozilla identified OCSP and lint-test issues that needed to be fixed before the request could proceed.
- Mozilla added the request to the queue for public discussion.
- Mozilla asked Camerfirma to complete a BR self-assessment.
- Mozilla opened public discussion on the request.
- Mozilla concluded the discussion and denied the request.
- AC Camerfirma, S.A. — Camerfirma reported that new SHA-256 root certificates with the same keys and names were not being recognized as valid roots or for EV.
- Mozilla representative — Mozilla said the initial CA information document had been verified and asked Camerfirma to review it for completeness.
- Mozilla representative — Mozilla said OCSP and lint-test errors still needed to be resolved and requested a BR audit statement.
- AC Camerfirma, S.A. — Camerfirma said the OCSP issue had already been fixed.
- Mozilla representative — Mozilla said the request had been added to the queue for public discussion.
- Mozilla representative — Mozilla requested that Camerfirma perform a BR self-assessment and attach it to the bug.
- AC Camerfirma, S.A. — Camerfirma attached final WebTrust audit reports and said the audit was written to reflect the new requirements.
- AC Camerfirma, S.A. — Camerfirma provided test website URLs for valid, revoked, and expired certificates and a CPS URL.
- Mozilla representative — Mozilla said Camerfirma should update the related audit-update case and noted permission to update the CA audit update request cases.
- Fastly representative — Wayne Thayer said he had reviewed the request and opened discussion on the Mozilla dev security policy mailing list.
- Fastly representative — Wayne Thayer said the discussion concluded that the request should be denied and changed the status to WONTFIX.