Reading through Kathleen's summary of the issue[1] that others linked elsewhere in this thread, the only statement relevant to the actual CA portion of TrustCor's business seems to be:
> There is no evidence of TrustCor mis-issuing TLS or SMIME certificates.
Even the original post says:
> Just to restate: I have no evidence that Trustcor has done anything wrong, and I have no evidence that Trustcor has been anything other than a diligent competent certificate authority.
So it seems like the sole basis for this action is TrustCor's mere affiliation with another company that does TLS interception? If that's true, it seems like a pretty significant departure from previous removals, which all (to my knowledge) involved some sort of action or inaction affecting the security of the CA certificate itself.
Is there anything in either Mozilla or Microsoft's root store policies which prohibit CAs from being affiliated with shady companies? Or does this just fall under the "at our sole discretion" clause?
[1]: https://groups.google.com/a/mozilla.org/g/dev-security-polic...