Remove HARICA 2015 Root Certificates
Categories
(NSS :: CA Certificates Code, task)
Tracking
(Not tracked)
People
(Reporter: bwilson, Assigned: bwilson)
References
Details
Per Bug #1953105, please remove the following root certificates from NSS:
Hellenic Academic and Research Institutions RootCA 2015
SHA256 Hash: A040929A02CE53B4ACF4F2FFC6981CE4496F755E6D45FE0B2A692BCD52523F36
CN=Hellenic Academic and Research Institutions RootCA 2015; O=Hellenic Academic and Research Institutions Cert. Authority; C=GR; L=Athens
Certificate Serial Number: 00
SHA-1 Fingerprint: 010C0695A6981914FFBF5FC6B0B695EA29E912A6
Hellenic Academic and Research Institutions ECC RootCA 2015
SHA256 Hash: 44B545AA8A25E65A73CA15DC27FC36D24C1CB9953A066539B11582DC487B4833
CN=Hellenic Academic and Research Institutions ECC RootCA 2015; O=Hellenic Academic and Research Institutions Cert. Authority; C=GR; L=Athens
Certificate Serial Number: 00
SHA-1 Fingerprint: 9FF1718D92D59AF37D7497B4BC6F84680BBAB666
| Assignee | ||
Updated•1 year ago
|
Comment 1•1 year ago
|
||
Considering the discussion in https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/uYAm_c_pfos/m/6KWQckAYCgAJ, I would like to kindly ask that the **removal ** of the HARICA 2015 Roots is paused until we can assess the impact on other consumers of the NSS Root Store.
| Assignee | ||
Comment 2•1 year ago
|
||
We can pause this removal for now, and revise it, and include this bug in a subsequent batch of changes.
We are seeking feedback from the HARICA community on any concerns there may be about the effects of root removal.
Please provide any comments here.
Comment 3•1 year ago
|
||
I reached out to Martijn Katerbarg who actively participates in the discussion referenced in comment 1 and he is aware of the last comments and pending questions. He hasn't found the time to respond yet.
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Updated•10 months ago
|
Comment 4•10 months ago
|
||
@bwilson, in order to support legacy mTLS use cases that need the clientAuth EKU, in light of CRP's policy that forbids clientAuth EKU in end-entity certificates in server TLS-only hierarchies after June 2026, we would like to kindly ask that the 2015 HARICA Roots are re-instated for the websites trust bit in NSS. These Roots are still covered under HARICA's consecutive audits.
Thank you for the consideration. Please let me know if there are any questions or concerns.
| Assignee | ||
Updated•10 months ago
|
Description
•