← SSL.com cases
Bugzilla #1799703 Root Inclusion

Add SSL.com 2022 Client Root CA Certificates

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com requested the addition of two 2022 Client Root CA certificates to NSS and the Mozilla root store. The roots were described as intended for S/MIME Server authentication, with the Email trust bit requested, and the request stated they would not be used for TLS issuance. SSL.com also stated it planned to migrate S/MIME issuance to subCAs chaining to these roots and referenced a CCADB case for inclusion. Mozilla asked SSL.com to provide end-user S/MIME certificates from these roots and to supply specific SPKI hashes. After public discussion, Mozilla recommended approving the request and Mozilla approved inclusion of the two specified email roots, with Mozilla noting it would file the NSS bug for the approved changes. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.90 8 comments
Chronology
  1. SSL.com submitted a request to include two 2022 Client Root CA certificates (Email trust) in NSS and the Mozilla root store.
  2. Mozilla requested end-user S/MIME certificates and related information from SSL.com for the proposed roots.
  3. Mozilla approved inclusion of the two SSL.com 2022 email roots and indicated it would file the NSS bug for the changes.
  4. The CA Program bug was resolved as FIXED.
Thread Activity
  1. SSL.com — SSL.com requested addition of two 2022 Client Root CA certificates for S/MIME Server authentication with the Email trust bit enabled, stating they would not be used for TLS issuance and referencing a CCADB case and a self-assessment attachment URL.
  2. Mozilla representative — Mozilla asked SSL.com to attach end-user S/MIME certificates from these roots to the bug.
  3. Mozilla representative — Mozilla requested specific SPKIs for the proposed roots.
  4. SSL.com — SSL.com provided the requested SPKI hashes and verification commands.
  5. Mozilla representative — Mozilla noted public discussion began 3/21/2023 and was scheduled to end 5/2/2023, linking to a Google Groups thread.
  6. Mozilla representative — Mozilla recommended approving SSL.com's request and linked to a Mozilla dev-security-policy thread.
  7. Mozilla representative — On behalf of Mozilla, she approved SSL.com's request to include the SSL.com Client ECC Root CA 2022 (Email) and SSL.com Client RSA Root CA 2022 (Email) roots and stated she would file the NSS bug for the approved changes.
  8. Mozilla representative — She stated she filed bug #1839992 against NSS for the actual changes.
Participants
SSL.com Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1799533 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2022-11-07 · Closed 2024-03-15 · 86% similar
Add SSL.com 2022 TLS Root CA Certificates
#1695486 RESOLVED Root Inclusion Opened 2021-02-28 · Closed 2022-11-14 · 85% similar
Add HARICA 2021 SMIME Root CA Certificates to Mozilla Root store program
#1817340 RESOLVED Root Inclusion Opened 2023-02-16 · Closed 2023-08-14 · 83% similar
Add Sectigo R46/E46 Roots
#1637269 RESOLVED Root Inclusion Opened 2020-05-12 · Closed 2022-11-14 · 79% similar
Add GlobalSign SMIME Roots to Mozilla root store
#1679256 RESOLVED Root Inclusion Opened 2020-11-25 · Closed 2022-11-14 · 79% similar
Root inclusion request for D-TRUST BR Root CA 1 2020
#1404221 RESOLVED Root Inclusion Opened 2017-09-29 · Closed 2022-11-14 · 78% similar
Add Root certificate of NAVER Business Platform
#1628720 RESOLVED Root Inclusion Opened 2020-04-09 · Closed 2022-11-14 · 78% similar
Add E-Tugra Root Certificates RSA v3 / ECC v3
#1706228 RESOLVED Root Inclusion Opened 2021-04-20 · Closed 2022-11-14 · 77% similar
Add DigiCert root Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action