Closed Bug 1840432 Opened 3 years ago Closed 3 years ago

Enable EV Treatment for Sectigo E46 and R46 root certificates

Categories

(Core :: Security: PSM, task)

task

Tracking

()

RESOLVED FIXED
118 Branch
Tracking Status
firefox118 --- fixed

People

(Reporter: kathleen.a.wilson, Assigned: keeler)

References

Details

(Whiteboard: August 2023 batch of EV changes)

Attachments

(1 file)

Per bug #1817340 the request from Sectigo has been approved to enable the following root certificates for EV use. Please make the corresponding changes to PSM.

Friendly Name: Sectigo Public Server Authentication Root E46
SHA-1 Fingerprint: EC8A396C40F02EBC4275D49FAB1C1A5B67BED29A
SHA-256 Fingerprint: C90F26F0FB1B4018B22227519B5CA2B53E2CA5B3BE5CF18EFE1BEF47380C5383
EV Policy OID: 2.23.140.1.1
Test URL: https://sectigopublicserverauthenticationroote46-ev.sectigo.com/

Friendly Name: Sectigo Public Server Authentication Root R46
SHA-1 Fingerprint: AD98F9F3E47D753B65D482B3A45217BB6EF5E438
SHA-256 Fingerprint: 7BB647A62AEEAC88BF257AA522D01FFEA395E0AB45C73F93F65654EC38F25A06
EV Policy OID: 2.23.140.1.1
Test URL: https://sectigopublicserverauthenticationrootr46-ev.sectigo.com/

NOTE: Bug #1840429 must be completed (the certs added to NSS), before this EV-enablement may be implemented.

Assignee: nobody → dkeeler
Status: NEW → ASSIGNED

Hi Kathleen. I just reviewed D185704 and noticed that the EV policy OID isn't what I was anticipating. (TBH, I don't think the CCADB Root Inclusion Request process actually asked us to specify our desired EV policy OID(s) ).

For consistency with existing EV-enabled roots owned by Sectigo, please could I ask for the entries in ExtendedValidation.cpp for the Sectigo E46 and R46 roots to specify the OID 1.3.6.1.4.1.6449.1.2.1.5.1 instead of 2.23.140.1.1 ?

(https://wiki.mozilla.org/CA/EV_Processing_for_CAs#First_OID explains that the 2.23.140.1.1 OID is implicitly EV-enabled for each root listed in ExtendedValidation.cpp anyway).

Flags: needinfo?(kwilson)

(In reply to Rob Stradling from comment #2)

Hi Kathleen. I just reviewed D185704 and noticed that the EV policy OID isn't what I was anticipating. (TBH, I don't think the CCADB Root Inclusion Request process actually asked us to specify our desired EV policy OID(s) ).

For consistency with existing EV-enabled roots owned by Sectigo, please could I ask for the entries in ExtendedValidation.cpp for the Sectigo E46 and R46 roots to specify the OID 1.3.6.1.4.1.6449.1.2.1.5.1 instead of 2.23.140.1.1 ?

(https://wiki.mozilla.org/CA/EV_Processing_for_CAs#First_OID explains that the 2.23.140.1.1 OID is implicitly EV-enabled for each root listed in ExtendedValidation.cpp anyway).

Hi Rob, we stopped adding CA-specific EV OIDs to ExtendedValidation.cpp, and are only adding the 2.23.140.1.1 for new EV-enablement requests. Our documentation (https://wiki.mozilla.org/CA/EV_Processing_for_CAs#Firefox_EV_Processing_Logic) still mentions the CA-specific EV OIDs because we are still phasing out the use -- not going back and changing it for roots that already had a CA-specific EV OID. Our long-term goal is to get to the point that Firefox only recognizes the 2.23.140.1.1 EV OID.

It is fine for your certificates to also specify your CA-specific OID(s), but the 2.23.140.1.1 OID will also need to be in them.

Flags: needinfo?(kwilson)

Ah, OK. Thanks Kathleen. (And thanks for adding a note about this phase out to the wiki page too).

Pushed by dkeeler@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/2c7f90a70628 Enable EV Treatment for Sectigo E46 and R46 root certificates r=jschanck
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 118 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: