← certSIGN cases
Bugzilla #1905070
Technical Compliance
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN requested the removal of the 'Secure Email' Trust Bit from their ROOT CA certificate due to its lack of use and the upcoming expiration of the certificate. This change is part of certSIGN's compliance with Mozilla's root lifecycle proposal and aims to address issues identified in a CCADB report regarding missing S/MIME BR audits. The removal is not expected to impact Mozilla users, and there is no urgency for the change.
Chronology
- certSIGN reported issues with S/MIME BR audit and requested removal of Secure Email Trust Bit.
- Change implemented in Nightly 131.0a1.
Participants
Gabriel PETCU
Ben Wilson
External References
Similar Local Cases
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
Request to disable SMIME "trust bit" for GoDaddy CAs
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
Entrust: CRLs and OCSP responses not issued as specified in the CPS
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity