LAWtrust Root CA certificate inclusion in NSS
Categories
(CA Program :: CA Certificate Root Program, task, P4)
Tracking
(Not tracked)
People
(Reporter: nielvg, Assigned: bwilson)
References
Details
(Whiteboard: [ca-verifying] BW 2020-09-30 - Comment #21)
Attachments
(8 files, 1 obsolete file)
|
146.43 KB,
application/pdf
|
Details | |
|
199.43 KB,
application/pdf
|
Details | |
|
2.60 KB,
text/plain
|
Details | |
|
2.77 KB,
application/x-x509-ca-cert
|
Details | |
|
2.06 KB,
application/x-x509-ca-cert
|
katekani
:
review+
katekani
:
data-review+
|
Details |
|
2.08 KB,
application/x-x509-ca-cert
|
katekani
:
review+
katekani
:
data-review+
|
Details |
|
2.13 KB,
application/x-x509-ca-cert
|
katekani
:
review+
katekani
:
data-review+
|
Details |
|
345.88 KB,
application/pdf
|
Details |
| Reporter | ||
Updated•11 years ago
|
Updated•11 years ago
|
Comment 2•11 years ago
|
||
Comment 3•11 years ago
|
||
Updated•11 years ago
|
| Reporter | ||
Comment 4•11 years ago
|
||
Comment 5•11 years ago
|
||
Comment 6•11 years ago
|
||
Updated•11 years ago
|
Comment 7•11 years ago
|
||
Comment 8•11 years ago
|
||
Updated•11 years ago
|
Updated•9 years ago
|
Comment 10•9 years ago
|
||
Updated•9 years ago
|
| Reporter | ||
Comment 11•9 years ago
|
||
Comment 12•9 years ago
|
||
Comment 13•9 years ago
|
||
Updated•9 years ago
|
Comment 14•8 years ago
|
||
Comment 15•7 years ago
|
||
Good day
We would like to continue with this process of getting our Root into Mozilla. I am now the assigned resource to deal with all the questions and updates to this bug.
Kindly assign me as the owner of the bug.
Many thanks and kind regards
Updated•7 years ago
|
Comment 16•7 years ago
|
||
The information for this root inclusion request is here:
https://ccadb-public.secure.force.com/mozilla/PrintViewForCase?CaseNumber=00000054
Katekani, you may directly update the information via the CCADB here:
https://ccadb.force.com/500o0000002EqPq
Please send me email if you have any questions or problems updating the Case and Root Case directly in the CCADB.
Add another comment to this Bugzilla Bug when the information in the Case and Root Case has been updated and is ready for me to review.
More information, and and example is available here:
https://wiki.mozilla.org/CA/Information_Checklist
| Assignee | ||
Comment 17•5 years ago
|
||
Reviewed submission in the CCADB and request that LawTrust update its CPS and ensure that it has uploaded all subordinate CAs under the 2048 Root in the CCADB. Thanks, Ben
Comment 18•5 years ago
|
||
Subordinate certificate : LAWtrust AeSign CA01
Comment 19•5 years ago
|
||
Subordinate CA certificate as requested : LAWtrust AeSign CA02
Comment 20•5 years ago
|
||
Subordinate CA Certificate as requested : LAWtrust AATL CA01
| Assignee | ||
Comment 21•5 years ago
|
||
Dear Katekani,
Thanks for submitting the certificates and updating your CPs and CPSes. Am I correct in understanding that the following are the best (most specific) CP/CPS statements concerning the procedures you require for verifying email addresses?
From LT_ISP_IS_CPS_LT2048CA2_V006 2019-12-11.pdf:
3.2.3.2 Authentication of a personal identity eMail address
In cases where the LAWtrust2048 CA2 Certificate will be used for digitally signing and/or
encrypting eMail the LAWtrust2048 CA2 RA will establish reasonable proof that the person
or Entity submitting the certificate request controls the eMail account associated with the
eMail address referenced in the LAWtrust2048 CA2 Certificate.
From LT_ISP_AeSign_CEN-SSCD_CPS_V004 2020-08-25_final.pdf:
3.2.3.2 Authentication of a personal identity eMail address
In cases where the LAWtrust AeSign CEN-SSCD CA Certificate will be used for digitally
signing the RA-Agent will establish reasonable proof that the person or legal Entity
submitting the certificate request controls the eMail account associated with the eMail
address referenced in the LAWtrust AeSign CEN-SSCD CA Certificate.
And from LT_ISP_AATL_CEN-SSCD_CPS_V003 2020-08-26_final.pdf:
3.2.3.2 Authentication of a personal identity eMail address
In cases where the LAWtrust AATL CA01 Certificate will be used for digitally signing the
RA-Agent will establish reasonable proof that the person or legal Entity submitting the
certificate request controls the eMail account associated with the eMail address
referenced in the LAWtrust AATL CA01 Certificate.
Please refer to https://wiki.mozilla.org/CA/Required_or_Recommended_Practices#Email_Challenge-Response and https://wiki.mozilla.org/CA/Required_or_Recommended_Practices#Verifying_Email_Address_Control to see if this language can be improved in a way that adequately describes the email validation process that meets these requirements.
Many CAs include requirements in their CPs/CPSes that verification of the domain portion of the email address not be delegated, per section 2.2 of Mozilla Policy-https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/#22-validation-practices. This still allows CAs to use methods of verifying domains for enterprise-type accounts - see section 3.2.2.4 of the CA/Browser Forum's Baseline Requirements - https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.7.2.pdf . Additionally, the challenge-response email process cited further above can then be used to verify full email addresses for other types of email verification.
Thanks again,
Ben
| Assignee | ||
Updated•5 years ago
|
| Assignee | ||
Comment 22•5 years ago
|
||
Dear Katekani,
Do you have any updates on your efforts?
Thanks,
Ben
Comment 23•5 years ago
|
||
Good day Ben
We are currently undergoing our annual Webtrust audits. I plan to update the CP/CPS to be more specific. We are already doing this by sending an email to the email address to be included in the certificate. I just need to describe the procedure more clearly.
Many thanks and kind regards
Katekani
| Assignee | ||
Updated•5 years ago
|
| Assignee | ||
Updated•5 years ago
|
Comment 24•5 years ago
|
||
This is the LAWtrust Webtrust Audit report for the 2020 calendar year. For root update submission
| Assignee | ||
Comment 25•4 years ago
|
||
This inclusion request should be closed as superseded by the newer Root CA submitted under Bug #1710831.
| Assignee | ||
Updated•4 years ago
|
Updated•3 years ago
|
Description
•