Closed Bug 1957699 Opened 1 year ago Closed 10 months ago

Remove HARICA 2015 Root Certificates

Categories

(NSS :: CA Certificates Code, task)

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: bwilson, Assigned: bwilson)

References

Details

Per Bug #1953105, please remove the following root certificates from NSS:

Hellenic Academic and Research Institutions RootCA 2015
SHA256 Hash: A040929A02CE53B4ACF4F2FFC6981CE4496F755E6D45FE0B2A692BCD52523F36
CN=Hellenic Academic and Research Institutions RootCA 2015; O=Hellenic Academic and Research Institutions Cert. Authority; C=GR; L=Athens
Certificate Serial Number: 00
SHA-1 Fingerprint: 010C0695A6981914FFBF5FC6B0B695EA29E912A6

Hellenic Academic and Research Institutions ECC RootCA 2015
SHA256 Hash: 44B545AA8A25E65A73CA15DC27FC36D24C1CB9953A066539B11582DC487B4833
CN=Hellenic Academic and Research Institutions ECC RootCA 2015; O=Hellenic Academic and Research Institutions Cert. Authority; C=GR; L=Athens
Certificate Serial Number: 00
SHA-1 Fingerprint: 9FF1718D92D59AF37D7497B4BC6F84680BBAB666

Blocks: 1937338
Depends on: 1957679
Blocks: 1957701

Considering the discussion in https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/uYAm_c_pfos/m/6KWQckAYCgAJ, I would like to kindly ask that the **removal ** of the HARICA 2015 Roots is paused until we can assess the impact on other consumers of the NSS Root Store.

We can pause this removal for now, and revise it, and include this bug in a subsequent batch of changes.
We are seeking feedback from the HARICA community on any concerns there may be about the effects of root removal.
Please provide any comments here.

No longer blocks: 1937338
No longer blocks: 1957701

I reached out to Martijn Katerbarg who actively participates in the discussion referenced in comment 1 and he is aware of the last comments and pending questions. He hasn't found the time to respond yet.

Assignee: nobody → bwilson
Flags: needinfo?(bwilson)
Flags: needinfo?(bwilson)

@bwilson, in order to support legacy mTLS use cases that need the clientAuth EKU, in light of CRP's policy that forbids clientAuth EKU in end-entity certificates in server TLS-only hierarchies after June 2026, we would like to kindly ask that the 2015 HARICA Roots are re-instated for the websites trust bit in NSS. These Roots are still covered under HARICA's consecutive audits.

Thank you for the consideration. Please let me know if there are any questions or concerns.

Flags: needinfo?(bwilson)
Status: NEW → RESOLVED
Closed: 10 months ago
Flags: needinfo?(bwilson)
Resolution: --- → WONTFIX
No longer depends on: 1957679
See Also: → 1957679
You need to log in before you can comment on or make changes to this bug.