← Disig, a.s. cases
Bugzilla #1420855 Root Removal

Remove CA Disig Root R1

RESOLVED FIXED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Disig, a.s. requested removal of the “CA Disig Root R1” certificate from the Mozilla CA Certificate Root Program. The request states the root was added as a possible replacement for the CA Disig (sha1RSA) root certificate, which expired on March 3, 2016. After that expiration, Disig decided not to use CA Disig Root R1 (and its subCA “CA Disig R1I1 Certification Services”) for issuing SSL certificates, and instead used CA Disig Root R2 (sha256RSA) and its subCA “CA Disig R2I2 Certification Service.” Disig also stated there would be no impact on Mozilla users because there is no valid certificate that chains to this root. Mozilla staff asked why the bug was marked “Security-Sensitive,” and Disig responded that there is no security problem and it does not need to be removed immediately. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:40 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 4 comments
Chronology
  1. Disig requested removal of the CA Disig Root R1 trust anchor from Mozilla’s CA Certificate Root Program.
  2. Mozilla staff confirmed the removal did not relate to a security problem and discussed timing and the Security-Sensitive flag.
Thread Activity
  1. Disig, a.s. — Requested removal of the CA Disig Root R1 root, explaining it was a replacement for an expired sha1RSA root and that Disig chose Root R2 for SSL issuance instead, with no expected user impact because no valid chains exist.
  2. Mozilla representative — Asked why the bug was marked “Security-Sensitive” and whether the root needed immediate removal or could wait for the next batch of root changes.
  3. Disig, a.s. — Confirmed there is no security problem and that the root can be removed with the next batch of root changes.
  4. Mozilla representative — Asked Peter to uncheck the “Security-Sensitive Crypto Bug” checkbox since there is no security problem.
Participants
Disig, a.s. Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#605187 RESOLVED Root Removal Opened 2010-10-18 · Closed 2022-11-14 · 71% similar
Remove AOL Time Warner root certs
#1301731 RESOLVED Root Removal Certificate Misissuance Opened 2016-09-09 · Closed 2022-11-14 · 66% similar
ANSSI: problematic certificates issued by AC Infrastructure
#1640819 RESOLVED Root Removal Opened 2020-05-26 · Closed 2022-11-14 · 64% similar
Remove CN=LuxTrust Global Root 2 root cert
#487150 RESOLVED Root Removal Opened 2009-04-07 · Closed 2022-11-14 · 59% similar
Removal request of StartCom 1024 bit CA root
#2024749 ASSIGNED Root Removal Opened 2026-03-19 Still Open · 58% similar
Firmaprofesional: Request for voluntary root removal - FIRMAPROFESIONAL CA ROOT-A WEB
#1455053 RESOLVED Root Removal Opened 2018-04-18 · Closed 2022-11-14 · 48% similar
Add some Firmaprofesional SubCAs to OneCRL
#849833 RESOLVED Root Removal Opened 2013-03-11 · Closed 2022-11-14 · 47% similar
Basic Constraint Ext: Proposal: Remove old Entrust 2048 root, add equivalent 2048 intermediate
#1841551 RESOLVED Root Removal Opened 2023-07-03 · Closed 2023-07-11 · 47% similar
Remove duplicate Firmaprofesional root certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action