← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1465625 Trust Bit Disablement

Turn off the Websites trust bit for OpenTrust and Certplus root certificates

RESOLVED FIXED DocuSign (OpenTrust/Keynectis)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is about a request to disable the “Websites” trust bit for specific root certificates. The CA owner (DocuSign, OpenTrust/Keynectis) asked Mozilla to turn off the Websites trust bit for five roots: OpenTrust Root CA G1, G2, and G3, and Certplus Root CA G1 and G2. In response to Mozilla’s questions, the CA stated there was no urgency or security concern, describing it as an end-of-life of the TLS certificates offer on their side, and said the roots had not been used to issue TLS certificates. The CA also indicated there would be no impact to customers, and requested that EV treatment and the point at which SSL certificates stop being trusted in NSS and Firefox be disabled “sooner the better.” Mozilla noted the code changes for the request should be included in the July/August batch of root changes planned for NSS 3.39 and Firefox 63, and provided links for release timing and testing. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:50 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.90 5 comments
Chronology
  1. DocuSign requested removal of the Websites trust bit for five OpenTrust and Certplus root certificates.
  2. DocuSign clarified there was no urgency, no BR/EV audit statements would be provided, and the roots had not been used to issue TLS certificates.
  3. Mozilla confirmed the request details and indicated the change would be included in the July/August root changes batch for NSS 3.39 and Firefox 63.
  4. Mozilla provided a test build link and testing instructions for the root changes.
Thread Activity
  1. Mozilla representative — Opened the request to remove the Trust Bit “Websites” for OpenTrust Root CA G1/G2/G3 and Certplus Root CA G1/G2, listing SHA-1 fingerprints.
  2. Mozilla representative — Asked Erwann to clarify urgency/security concerns, audit statements, certificate expiration, customer impact, and preferred dates for disabling EV and trust in NSS/Firefox.
  3. Docusign representative — Responded that there was no urgency, no BR/EV audit statements would be provided, the roots had not been used to issue TLS certificates, there would be no customer impact, and requested EV and trust disablement as soon as possible.
  4. Mozilla representative — Provided the full list of root certificate identifiers/fingerprints and stated the code changes should be in the July/August batch planned for NSS 3.39 and Firefox 63, with links to release timing.
  5. Mozilla representative — Shared a Treeherder try build URL and noted testing/confirmation of the changes, with a link to Mozilla CA testing instructions.
Participants
Mozilla representative Docusign representative
Similar Local Cases
#1684158 RESOLVED Trust Bit Disablement Opened 2020-12-24 · Closed 2022-11-14 · 69% similar
PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
#1655074 RESOLVED Trust Bit Disablement Opened 2020-07-24 · Closed 2022-11-14 · 68% similar
Add several ICAs of Firmaprofesional to OneCRL
#847604 RESOLVED Trust Bit Disablement Opened 2013-03-04 · Closed 2022-11-14 · 64% similar
Turn off websites and code signing trust bits for two IdenTrust root certs
#1943135 RESOLVED Trust Bit Disablement Closure Request Opened 2025-01-22 · Closed 2025-05-25 · 61% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#1905070 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-28 · 61% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
#1905072 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-22 · 59% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 58% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 42% similar
SHA-1 issuance by DocuSign root

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action