← certSIGN cases
Bugzilla #1905070 Trust Bit Disablement

Turn off Secure Email Trust Bit for certSIGN ROOT CA cert

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

certSIGN reported that a CCADB report on intermediate certificates with failed ALV results showed certSIGN CAs with missing S/MIME BR audit, and certSIGN sought to fix the issue by removing the “Secure Email” trust bit. The CA requested removal of the Secure Email trust bit for the “certSIGN ROOT CA” identified by SHA256 fingerprint EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB. certSIGN stated the root was created on 4 July 2006 and will expire in 2031, and that under Mozilla roots life-cycle guidance the Websites trust bit would be removed on 15 April 2026. certSIGN also stated it does not use the Secure Email trust bit because it is a derived bit inherited from the root, and it asked for removal of this bit from all root store programs (Apple, Microsoft, Mozilla, and Chrome). The bug was resolved as FIXED, and Mozilla’s Ben Wilson noted that the change was included in Nightly 131.0a1 on 2024-08-28.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 2 comments
Chronology
  1. certSIGN requested removal of the Secure Email trust bit for its certSIGN ROOT CA root certificate.
  2. Mozilla indicated the change was included in Nightly 131.0a1.
Thread Activity
  1. certSIGN — Requested removal of the “Secure Email” trust bit for the certSIGN ROOT CA (SHA256 fingerprint EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB), stating the bit is derived and not used and that the root’s lifecycle had already been prepared.
  2. Mozilla representative — Confirmed the change is now in Nightly 131.0a1 (2024-08-28).
Participants
certSIGN Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1905072 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-22 · 100% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#1943135 RESOLVED Trust Bit Disablement Closure Request Opened 2025-01-22 · Closed 2025-05-25 · 70% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 67% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#847604 RESOLVED Trust Bit Disablement Opened 2013-03-04 · Closed 2022-11-14 · 62% similar
Turn off websites and code signing trust bits for two IdenTrust root certs
#1684158 RESOLVED Trust Bit Disablement Opened 2020-12-24 · Closed 2022-11-14 · 61% similar
PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
#1465625 RESOLVED Trust Bit Disablement Opened 2018-05-30 · Closed 2022-11-14 · 61% similar
Turn off Websites trust bit for OpenTrust and Certplus root certs
#1655074 RESOLVED Trust Bit Disablement Opened 2020-07-24 · Closed 2022-11-14 · 58% similar
Add several ICAs of Firmaprofesional to OneCRL
#1891438 RESOLVED Trust Bit Disablement Opened 2024-04-15 · Closed 2026-02-13 · 47% similar
Chunghwa Telecom: Postpone removal of ePKI Root CA's websites trust bit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action