Remove CA Disig Root R1
Disig, a.s. requested removal of the “CA Disig Root R1” certificate from the Mozilla CA Certificate Root Program. The request states the root was added as a possible replacement for the CA Disig (sha1RSA) root certificate, which expired on March 3, 2016. After that expiration, Disig decided not to use CA Disig Root R1 (and its subCA “CA Disig R1I1 Certification Services”) for issuing SSL certificates, and instead used CA Disig Root R2 (sha256RSA) and its subCA “CA Disig R2I2 Certification Service.” Disig also stated there would be no impact on Mozilla users because there is no valid certificate that chains to this root. Mozilla staff asked why the bug was marked “Security-Sensitive,” and Disig responded that there is no security problem and it does not need to be removed immediately. The bug was marked RESOLVED with resolution FIXED.
- Disig requested removal of the CA Disig Root R1 trust anchor from Mozilla’s CA Certificate Root Program.
- Mozilla staff confirmed the removal did not relate to a security problem and discussed timing and the Security-Sensitive flag.
- Disig, a.s. — Requested removal of the CA Disig Root R1 root, explaining it was a replacement for an expired sha1RSA root and that Disig chose Root R2 for SSL issuance instead, with no expected user impact because no valid chains exist.
- Mozilla representative — Asked why the bug was marked “Security-Sensitive” and whether the root needed immediate removal or could wait for the next batch of root changes.
- Disig, a.s. — Confirmed there is no security problem and that the root can be removed with the next batch of root changes.
- Mozilla representative — Asked Peter to uncheck the “Security-Sensitive Crypto Bug” checkbox since there is no security problem.