← Internet Security Research Group cases
Bugzilla #1658437 Root Inclusion

Let's Encrypt: intent to issue root and intermediate certificates with organizationName and CABF DV OID

RESOLVED WORKSFORME Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns Let’s Encrypt (ISRG) planning to create new root and intermediate keys and certificates. ISRG stated it wanted to limit intermediate certificates to Domain Validation by including the CABF DV OID, while also including organizationName in the Subject as required by the Baseline Requirements. ISRG referenced a prior discussion indicating this approach might not be technically allowed by the BRs, but said it expected the language would be rectified via an upcoming ballot. ISRG also explained it planned to proceed without waiting for a clarification ballot because waiting would delay work needed to minimize disruption to websites and would be difficult to schedule due to COVID-19 restrictions. Mozilla acknowledged receipt and referenced a related Bugzilla discussion where Mozilla’s interpretation was that organizational identification is allowed in DV-issuing CAs, and encouraged clarification of BR section 7.1.6.1 with the CA/Browser Forum. The bug is marked RESOLVED with resolution WORKSFORME.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.86 2 comments
Chronology
  1. ISRG communicated its intent to issue new root and intermediate certificates with organizationName and the CABF DV OID for DV-limited intermediates.
  2. Mozilla acknowledged the communication and pointed to an interpretation and a request to clarify BR section 7.1.6.1 with the CA/Browser Forum.
Thread Activity
  1. Kflag representative — ISRG (Let’s Encrypt) said it planned new root/intermediate certificates, intended DV-limited intermediates by including the CABF DV OID, and would include organizationName in the Subject as required by the BRs.
  2. Mozilla representative — Mozilla acknowledged receipt, cited Bug 1650018#c2 for an interpretation that organizational identification is allowed in DV-issuing CAs, and urged clarification of BR section 7.1.6.1 with the CA/Browser Forum.
Participants
Kflag representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1204656 RESOLVED Root Inclusion Opened 2015-09-14 · Closed 2022-11-14 · 64% similar
Add ISRG / Let's Encrypt root certificate
#715136 RESOLVED Root Inclusion Ca Certificate Root Program Opened 2012-01-04 · Closed 2022-11-14 · 58% similar
Add Renewed TURKTRUST root certificate
#1450805 RESOLVED Root Inclusion Opened 2018-04-02 · Closed 2022-11-14 · 58% similar
Add Consorci AOC "old" hierarchy to OneCRL
#1720400 RESOLVED Root Inclusion Opened 2021-07-13 · Closed 2022-11-14 · 58% similar
Add Actalis intermediate certs to OneCRL
#380067 RESOLVED Root Removal Root Inclusion Opened 2007-05-08 · Closed 2022-11-14 · 56% similar
Delete Visa International Root - GP2 and add Visa International Root - InfoDelivery
#986854 RESOLVED Root Inclusion Opened 2014-03-22 · Closed 2022-11-14 · 56% similar
Add Renewed AC Camerfirma root certificate.
#1658789 RESOLVED Root Inclusion Closure Request Opened 2020-08-12 · Closed 2022-11-14 · 47% similar
Add Carillon PKI Services G2 Root CA 1
#1554846 RESOLVED Root Inclusion Cp Cps Document Opened 2019-05-28 · Closed 2024-04-12 · 46% similar
Add iTrusChina root certificate(s)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action