Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
The case concerns a request by certSIGN to remove the derived “Secure Email” trust bit from the certSIGN ROOT CA G2 root. The request was triggered by a CCADB report on intermediate certificates with failed ALV results, which presented certSIGN CAs with missing S/MIME BR audit. certSIGN stated that it created certSIGN ROOT CA G2 on 6 Feb 2017 with all issuance policies, but decided from the beginning of 2024 to migrate issuing to certSIGN Public CA and certSIGN Qualified CA for signature certificates and to keep the PKI system only for TLS certificates issued with certSIGN Web CA. certSIGN also explained that the Secure Email trust bit is inherited from the root as a derived bit, and therefore asked for removal of this bit from Apple and Microsoft root store programs, stating there is no impact on Mozilla users and no urgency beyond fixing the intermediate certificates with failed ALV. Mozilla closed the bug as INVALID, stating that certSIGN ROOT CA G2 only has the websites bit enabled and does not have the email trust bit enabled.
- certSIGN requested removal of the “Secure Email” trust bit from certSIGN ROOT CA G2.
- Mozilla closed the request as INVALID after confirming the root did not have the email trust bit enabled.
- certSIGN — certSIGN requested turning off the “Secure Email” trust bit for certSIGN ROOT CA G2, citing a CCADB ALV-related issue and explaining the root’s migration to TLS-only usage.
- Mozilla representative — Mozilla closed the bug as INVALID, stating certSIGN ROOT CA G2 only has the websites bit enabled and does not have the email trust bit enabled.