← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1655074 Trust Bit Disablement

Add several ICAs of Firmaprofesional to OneCRL

RESOLVED WONTFIX Autoridad de Certificacion Firmaprofesional
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case requests adding several Firmaprofesional intermediate CA (ICA) certificates to Mozilla’s OneCRL. The request was made to align with Firmaprofesional’s plans referenced in other bugs (1649943 and 1651637) and includes multiple specific intermediate certificates, with the stated intent that they are not intended to issue TLS. Kathleen Wilson indicated she planned to close the bug as WONTFIX, stating that the listed intermediate certificates are technically constrained via EKU to not issue TLS certificates, and that OneCRL is only used by Firefox for TLS, so adding non-TLS intermediates would have zero effect other than adding data. Ryan Sleevi responded that the context was OCSP, noting the intermediates could potentially issue OCSP responses, but that Mozilla code already rejects these due to checks, and that Mozilla clients like Thunderbird would not be protected by adding them to OneCRL. The bug was resolved as WONTFIX.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.84 4 comments
Chronology
  1. A bug was filed to add multiple Firmaprofesional intermediate certificates to OneCRL.
  2. Mozilla staff discussed closing the request as WONTFIX due to EKU constraints and OneCRL’s TLS-only use.
  3. The bug was resolved as WONTFIX.
Thread Activity
  1. Isigma representative — Requested adding several Firmaprofesional intermediate certificates to OneCRL to align with Firmaprofesional’s plans, listing the specific ICA certificates and their details.
  2. Mozilla representative — Planned to close the bug as WONTFIX, arguing the intermediates are EKU-constrained to not issue TLS and that OneCRL is only used by Firefox for TLS.
  3. Community commenter — Responded that the discussion relates to OCSP, but stated Mozilla code already rejects these OCSP responses and that Thunderbird would not be protected by adding them to OneCRL.
Participants
Isigma representative Mozilla representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1465625 RESOLVED Trust Bit Disablement Opened 2018-05-30 · Closed 2022-11-14 · 68% similar
Turn off Websites trust bit for OpenTrust and Certplus root certs
#1684158 RESOLVED Trust Bit Disablement Opened 2020-12-24 · Closed 2022-11-14 · 66% similar
PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
#1943135 RESOLVED Trust Bit Disablement Closure Request Opened 2025-01-22 · Closed 2025-05-25 · 59% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#847604 RESOLVED Trust Bit Disablement Opened 2013-03-04 · Closed 2022-11-14 · 58% similar
Turn off websites and code signing trust bits for two IdenTrust root certs
#1905070 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-28 · 58% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 57% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#1905072 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-22 · 57% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#794036 RESOLVED Ev Enablement Opened 2012-09-25 · Closed 2022-11-14 · 50% similar
Enable EV for Firmaprofesional

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action