Turn off the Websites trust bit for OpenTrust and Certplus root certificates
This case is about a request to disable the “Websites” trust bit for specific root certificates. The CA owner (DocuSign, OpenTrust/Keynectis) asked Mozilla to turn off the Websites trust bit for five roots: OpenTrust Root CA G1, G2, and G3, and Certplus Root CA G1 and G2. In response to Mozilla’s questions, the CA stated there was no urgency or security concern, describing it as an end-of-life of the TLS certificates offer on their side, and said the roots had not been used to issue TLS certificates. The CA also indicated there would be no impact to customers, and requested that EV treatment and the point at which SSL certificates stop being trusted in NSS and Firefox be disabled “sooner the better.” Mozilla noted the code changes for the request should be included in the July/August batch of root changes planned for NSS 3.39 and Firefox 63, and provided links for release timing and testing. The bug is marked RESOLVED with resolution FIXED.
- DocuSign requested removal of the Websites trust bit for five OpenTrust and Certplus root certificates.
- DocuSign clarified there was no urgency, no BR/EV audit statements would be provided, and the roots had not been used to issue TLS certificates.
- Mozilla confirmed the request details and indicated the change would be included in the July/August root changes batch for NSS 3.39 and Firefox 63.
- Mozilla provided a test build link and testing instructions for the root changes.
- Mozilla representative — Opened the request to remove the Trust Bit “Websites” for OpenTrust Root CA G1/G2/G3 and Certplus Root CA G1/G2, listing SHA-1 fingerprints.
- Mozilla representative — Asked Erwann to clarify urgency/security concerns, audit statements, certificate expiration, customer impact, and preferred dates for disabling EV and trust in NSS/Firefox.
- Docusign representative — Responded that there was no urgency, no BR/EV audit statements would be provided, the roots had not been used to issue TLS certificates, there would be no customer impact, and requested EV and trust disablement as soon as possible.
- Mozilla representative — Provided the full list of root certificate identifiers/fingerprints and stated the code changes should be in the July/August batch planned for NSS 3.39 and Firefox 63, with links to release timing.
- Mozilla representative — Shared a Treeherder try build URL and noted testing/confirmation of the changes, with a link to Mozilla CA testing instructions.