Remove "Security Communication EV RootCA1" root cert
Categories
(NSS :: CA Certificates Code, task)
Tracking
(Not tracked)
People
(Reporter: kathleen.a.wilson, Assigned: h-kamo)
References
Details
(Whiteboard: Removed in NSS 3.35, Firefox 59)
| Reporter | ||
Updated•8 years ago
|
| Reporter | ||
Updated•8 years ago
|
Comment 1•7 years ago
|
||
Kathleen: For clarity, this appears to still be cross-signed by a root in the Mozilla program:
https://crt.sh/?id=36251
https://crt.sh/?id=1644
The CCADB disclosures apparently indicate "same as parent", except this is not included in the scope of those audits.
| Reporter | ||
Comment 2•7 years ago
|
||
(In reply to Ryan Sleevi from comment #1)
Kathleen: For clarity, this appears to still be cross-signed by a root in the Mozilla program:
https://crt.sh/?id=36251
https://crt.sh/?id=1644
The CCADB disclosures apparently indicate "same as parent", except this is not included in the scope of those audits.
Ryan, Thank you for pointing this out.
Dear Kamo-san,
As you know, we removed the "Security Communication EV RootCA1" root certificate from Mozilla's root store, because it was no longer being audited.
However, this root certificate was cross-signed by the "SECOM Trust.net - Security Communication RootCA1" root certificate that is still included in Mozilla's Root Store.
Therefore, please revoke the following root certificate asap. Otherwise, we need audit statements for it.
https://crt.sh/?id=36251
Subject: OU=Security Communication EV RootCA1; O=SECOM Trust Systems CO.,LTD.; C=JP
Issuer: OU=Security Communication RootCA1; O=SECOM Trust.net; C=JP
Certificate Serial Number: 12B9B0E4
SHA-256 Fingerprint: E5AD411164AF69216B768D5272E564C2A08FFFE20A547065119545AF03BEFEF0
Note: The other cert mentioned in Comment #1 (https://crt.sh/?id=1644) is expired, so no action need for that cert.
I look forward to your prompt response.
Thanks,
Kathleen
| Assignee | ||
Comment 3•7 years ago
|
||
Dear Kathleen-san,
Thank you for your notice.
We will revoke this certificate upon confirming the revocation procedure carefully.
The target for this is the end of January.
Thank you for your consideration.
Best regards,
Hisashi Kamo
| Reporter | ||
Comment 4•7 years ago
|
||
(In reply to Kathleen Wilson from comment #2)
please revoke the following root certificate asap. Otherwise, we need audit statements for it.
https://crt.sh/?id=36251
Subject: OU=Security Communication EV RootCA1; O=SECOM Trust Systems CO.,LTD.; C=JP
Issuer: OU=Security Communication RootCA1; O=SECOM Trust.net; C=JP
Certificate Serial Number: 12B9B0E4
SHA-256 Fingerprint: E5AD411164AF69216B768D5272E564C2A08FFFE20A547065119545AF03BEFEF0
I confirm that this certificate has been revoked and is indicated as such in the CCADB.
It will be added to OneCRL as part of our standard CCADB->OneCRL process.
Thanks,
Kathleen
| Assignee | ||
Comment 5•7 years ago
|
||
Dear Kathleen-san,
Thank you for your confirmation.
As you described at comment #4, we revoked this certificate and indicated in the CCADB yesterday.
Best regards,
Hisashi Kamo
Description
•