Enable EV Treatment for Sectigo E46 and R46 root certificates
Categories
(Core :: Security: PSM, task)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox118 | --- | fixed |
People
(Reporter: kathleen.a.wilson, Assigned: keeler)
References
Details
(Whiteboard: August 2023 batch of EV changes)
Attachments
(1 file)
Per bug #1817340 the request from Sectigo has been approved to enable the following root certificates for EV use. Please make the corresponding changes to PSM.
Friendly Name: Sectigo Public Server Authentication Root E46
SHA-1 Fingerprint: EC8A396C40F02EBC4275D49FAB1C1A5B67BED29A
SHA-256 Fingerprint: C90F26F0FB1B4018B22227519B5CA2B53E2CA5B3BE5CF18EFE1BEF47380C5383
EV Policy OID: 2.23.140.1.1
Test URL: https://sectigopublicserverauthenticationroote46-ev.sectigo.com/
Friendly Name: Sectigo Public Server Authentication Root R46
SHA-1 Fingerprint: AD98F9F3E47D753B65D482B3A45217BB6EF5E438
SHA-256 Fingerprint: 7BB647A62AEEAC88BF257AA522D01FFEA395E0AB45C73F93F65654EC38F25A06
EV Policy OID: 2.23.140.1.1
Test URL: https://sectigopublicserverauthenticationrootr46-ev.sectigo.com/
NOTE: Bug #1840429 must be completed (the certs added to NSS), before this EV-enablement may be implemented.
| Assignee | ||
Comment 1•3 years ago
|
||
Depends on D185703
Updated•3 years ago
|
Comment 2•3 years ago
|
||
Hi Kathleen. I just reviewed D185704 and noticed that the EV policy OID isn't what I was anticipating. (TBH, I don't think the CCADB Root Inclusion Request process actually asked us to specify our desired EV policy OID(s) ).
For consistency with existing EV-enabled roots owned by Sectigo, please could I ask for the entries in ExtendedValidation.cpp for the Sectigo E46 and R46 roots to specify the OID 1.3.6.1.4.1.6449.1.2.1.5.1 instead of 2.23.140.1.1 ?
(https://wiki.mozilla.org/CA/EV_Processing_for_CAs#First_OID explains that the 2.23.140.1.1 OID is implicitly EV-enabled for each root listed in ExtendedValidation.cpp anyway).
| Reporter | ||
Comment 3•3 years ago
|
||
(In reply to Rob Stradling from comment #2)
Hi Kathleen. I just reviewed D185704 and noticed that the EV policy OID isn't what I was anticipating. (TBH, I don't think the CCADB Root Inclusion Request process actually asked us to specify our desired EV policy OID(s) ).
For consistency with existing EV-enabled roots owned by Sectigo, please could I ask for the entries in ExtendedValidation.cpp for the Sectigo E46 and R46 roots to specify the OID 1.3.6.1.4.1.6449.1.2.1.5.1 instead of 2.23.140.1.1 ?
(https://wiki.mozilla.org/CA/EV_Processing_for_CAs#First_OID explains that the 2.23.140.1.1 OID is implicitly EV-enabled for each root listed in ExtendedValidation.cpp anyway).
Hi Rob, we stopped adding CA-specific EV OIDs to ExtendedValidation.cpp, and are only adding the 2.23.140.1.1 for new EV-enablement requests. Our documentation (https://wiki.mozilla.org/CA/EV_Processing_for_CAs#Firefox_EV_Processing_Logic) still mentions the CA-specific EV OIDs because we are still phasing out the use -- not going back and changing it for roots that already had a CA-specific EV OID. Our long-term goal is to get to the point that Firefox only recognizes the 2.23.140.1.1 EV OID.
It is fine for your certificates to also specify your CA-specific OID(s), but the 2.23.140.1.1 OID will also need to be in them.
Comment 4•3 years ago
|
||
Ah, OK. Thanks Kathleen. (And thanks for adding a note about this phase out to the wiki page too).
Comment 6•3 years ago
|
||
| bugherder | ||
Description
•