← Internet Security Research Group cases
Bugzilla #1204656 Root Inclusion

ISRG / Let's Encrypt root certificate inclusion request for ISRG Root X1

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a Mozilla CA Program request from Internet Security Research Group (ISRG) to include the ISRG Root X1 root certificate and enable the Websites trust bit. The request was opened by Josh Aas of ISRG and included the root certificate details, CP/CPS links, and audit information for Let’s Encrypt. During review, Mozilla asked ISRG to provide a test website that chained to the root being included, and ISRG updated the server so the test site could be successfully verified. The public discussion also included questions about audit timing and certificate revocation practices, but the inclusion review itself concluded with approval. Mozilla later approved the request and filed the corresponding NSS bug for the actual change.

Model: gpt-5.4-mini Generated: 2026-06-13 11:58 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.98 65 comments
Chronology
  1. ISRG requested inclusion of the ISRG Root X1 root certificate for Websites trust.
  2. Mozilla opened the public discussion period for the ISRG Root X1 inclusion request.
  3. The test website was updated so it chained to ISRG Root X1 and could be successfully tested.
  4. Mozilla approved inclusion of ISRG Root X1 and the Websites trust bit.
  5. Mozilla filed NSS bug 1289889 for the actual root-store change.
Thread Activity
  1. Kflag representative — Josh Aas opened the request with ISRG and Let’s Encrypt root, certificate, and audit details.
  2. Mozilla representative — Kathleen Wilson said the request had been entered into Salesforce and asked ISRG to review the attached CA information for corrections and missing details.
  3. Kflag representative — ISRG corrected several CA policy and audit-related details and pointed to a point-in-time readiness assessment.
  4. IdenTrust Services, LLC — IdenTrust explained its audit coverage and stated that the Let’s Encrypt subordinate CA certificate would be included in the next audit cycle.
  5. Rossde representative — A commenter raised concerns about a reported subscriber certificate used in a malware campaign and said Let’s Encrypt declined to revoke it.
  6. Mozilla representative — Mozilla opened public discussion and asked for a test website that chained to the root under review.
  7. Mozilla representative — Mozilla confirmed the test website now chained to ISRG Root X1 and could be tested successfully.
  8. Mozilla representative — Mozilla posted its assessment summary and said it intended to approve the request.
  9. Mozilla representative — Mozilla approved the request and said it would file the NSS bug for the change.
  10. Mozilla representative — Mozilla updated the test websites list to include valid, expired, and revoked ISRG Root X1 test sites.
Participants
Kflag representative Mozilla representative IdenTrust Services, LLC Rossde representative Startcom representative DigiCert Community commenter Wolfbeast representative Joshuadwire representative Tree representative Chrisrebert representative Psw representative Smcc representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#476766 VERIFIED Root Inclusion Opened 2009-02-04 · Closed 2022-11-14 · 90% similar
Add China Internet Network Information Center (CNNIC) CA Root Certificate
#480966 RESOLVED Root Inclusion Opened 2009-03-02 · Closed 2022-11-14 · 88% similar
Netlock Root CA rollover request
#555156 RESOLVED Root Inclusion Opened 2010-03-26 · Closed 2022-11-14 · 88% similar
Add ANF root certificate
#393166 RESOLVED Ca Certificate Root Program Root Inclusion Public Discussion Opened 2007-08-22 · Closed 2022-11-14 · 87% similar
Add Certigna certificates to Mozilla root CA list
#370505 RESOLVED Root Inclusion Opened 2007-02-15 · Closed 2022-11-14 · 86% similar
Add Microsec Ltd root CA certificate
#274100 RESOLVED Root Inclusion Opened 2004-12-10 · Closed 2022-11-14 · 86% similar
Add ACCV CA certificate (Spain)
#511380 RESOLVED Root Inclusion Opened 2009-08-19 · Closed 2022-11-14 · 86% similar
Add NIC (India) Root CA Certificate
#368970 RESOLVED Root Inclusion Opened 2007-02-01 · Closed 2022-11-14 · 86% similar
Add French Government (DCSSI) CA certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action