← GlobalSign nv-sa cases
Bugzilla #1390803 Root Inclusion Ev Enablement Incident

GlobalSign Root CA - R6 inclusion request and later BR compliance discussion

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case began as GlobalSign’s request to include the new "GlobalSign Root CA - R6" root certificate in Mozilla products. GlobalSign said the RSA-4096 root was created in 2014 and provided its checklist, BR self-assessment, CP/CPS updates, and audit reports as part of the inclusion review. Mozilla reviewers asked follow-up questions about the audit statements and CP/CPS language, and GlobalSign supplied updated documents and clarifications before public discussion and approval. Mozilla later approved inclusion of the root with Websites and Email trust bits and EV enabled, and filed the corresponding NSS and PSM implementation bugs. In 2019, the thread was reopened to discuss whether the root’s subject complied with the Baseline Requirements and whether newly issued cross-certificates to that root were BR-compliant; Mozilla staff stated that root inclusion does not grant permission to violate the BRs and that the cross-certificates were issued in violation of the then-current BRs. The thread does not record a later change to the original inclusion decision, but it does document the compliance concern and follow-on discussion.

Model: gpt-5.4-mini Generated: 2026-06-13 17:03 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.93 36 comments
Chronology
  1. GlobalSign Root CA - R6 was created.
  2. Mozilla approved inclusion of GlobalSign Root CA - R6 with Websites and Email trust bits and EV enabled.
  3. Mozilla raised a Baseline Requirements compliance concern about the root’s subject and newly issued cross-certificates.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign opened the bug to request inclusion of the new RSA-4096 root certificate and provided download links and intended trust uses.
  2. Mozilla representative — Mozilla said the request was ready for detailed CP/CPS review and reassigned the bug to Wayne Thayer.
  3. Fastly representative — Wayne Thayer listed review questions and noted several CP/CPS and audit issues to be addressed before proceeding.
  4. GlobalSign nv-sa — GlobalSign uploaded updated CPS and CP documents and said they were ready to proceed with the next step.
  5. Fastly representative — Wayne announced that public discussion had begun and posted the inclusion request details for comment.
  6. Mozilla representative — Mozilla approved inclusion of GlobalSign Root CA - R6 and said the NSS and PSM bugs would be filed for the changes.
  7. Community commenter — Ryan Sleevi said the root’s subject did not comply with the Baseline Requirements and raised concern about whether the inclusion bug implied acceptance of the non-compliant cross-certificates.
  8. Fastly representative — Wayne stated that including a root does not implicitly permit BR violations and that the subordinate CA certificates were issued in violation of the then-current BRs.
Participants
GlobalSign nv-sa Mozilla representative Fastly representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1637269 RESOLVED Root Inclusion Opened 2020-05-12 · Closed 2022-11-14 · 96% similar
Add GlobalSign SMIME Roots to Mozilla root store
#1585951 RESOLVED Root Inclusion Ev Enablement Opened 2019-10-03 · Closed 2023-05-02 · 88% similar
Add ANF AC root certificates
#1404221 RESOLVED Root Inclusion Opened 2017-09-29 · Closed 2022-11-14 · 86% similar
Add Root certificate of NAVER Business Platform
#1570724 RESOLVED Root Inclusion Self Assessment Opened 2019-08-01 · Closed 2022-11-14 · 85% similar
Add GlobalSign Root Certificates R46/E46
#1454977 RESOLVED Root Inclusion Public Discussion Opened By Ca Opened 2018-04-18 · Closed 2023-07-12 · 85% similar
Add ACIN Global Trusted Sign root certificate
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 84% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 82% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1393555 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 81% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action