Good to know that our new certs are there :-)
Regarding StartCom, these are the new certs we´ve generated and will be used
to apply for inclusion in the Mozilla root program. Nothing to disclose at
the moment I guess. We´ve not been audited yet nor applied.

Hi Iñigo. The old StartCom roots still have the SSL trust bit enabled in NSS, and you've used one of those old roots to cross-sign the new StartCom roots. AFAICT, that means that these new StartCom intermediates do need to be disclosed to the CCADB.

