Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
certSIGN reported that a CCADB report on intermediate certificates with failed ALV results showed certSIGN CAs with missing S/MIME BR audit, and certSIGN sought to fix the issue by removing the “Secure Email” trust bit. The CA requested removal of the Secure Email trust bit for the “certSIGN ROOT CA” identified by SHA256 fingerprint EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB. certSIGN stated the root was created on 4 July 2006 and will expire in 2031, and that under Mozilla roots life-cycle guidance the Websites trust bit would be removed on 15 April 2026. certSIGN also stated it does not use the Secure Email trust bit because it is a derived bit inherited from the root, and it asked for removal of this bit from all root store programs (Apple, Microsoft, Mozilla, and Chrome). The bug was resolved as FIXED, and Mozilla’s Ben Wilson noted that the change was included in Nightly 131.0a1 on 2024-08-28.
- certSIGN requested removal of the Secure Email trust bit for its certSIGN ROOT CA root certificate.
- Mozilla indicated the change was included in Nightly 131.0a1.
- certSIGN — Requested removal of the “Secure Email” trust bit for the certSIGN ROOT CA (SHA256 fingerprint EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB), stating the bit is derived and not used and that the root’s lifecycle had already been prepared.
- Mozilla representative — Confirmed the change is now in Nightly 131.0a1 (2024-08-28).