← certSIGN cases
Bugzilla #1905072 Trust Bit Disablement

Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert

RESOLVED INVALID certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns a request by certSIGN to remove the derived “Secure Email” trust bit from the certSIGN ROOT CA G2 root. The request was triggered by a CCADB report on intermediate certificates with failed ALV results, which presented certSIGN CAs with missing S/MIME BR audit. certSIGN stated that it created certSIGN ROOT CA G2 on 6 Feb 2017 with all issuance policies, but decided from the beginning of 2024 to migrate issuing to certSIGN Public CA and certSIGN Qualified CA for signature certificates and to keep the PKI system only for TLS certificates issued with certSIGN Web CA. certSIGN also explained that the Secure Email trust bit is inherited from the root as a derived bit, and therefore asked for removal of this bit from Apple and Microsoft root store programs, stating there is no impact on Mozilla users and no urgency beyond fixing the intermediate certificates with failed ALV. Mozilla closed the bug as INVALID, stating that certSIGN ROOT CA G2 only has the websites bit enabled and does not have the email trust bit enabled.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 2 comments
Chronology
  1. certSIGN requested removal of the “Secure Email” trust bit from certSIGN ROOT CA G2.
  2. Mozilla closed the request as INVALID after confirming the root did not have the email trust bit enabled.
Thread Activity
  1. certSIGN — certSIGN requested turning off the “Secure Email” trust bit for certSIGN ROOT CA G2, citing a CCADB ALV-related issue and explaining the root’s migration to TLS-only usage.
  2. Mozilla representative — Mozilla closed the bug as INVALID, stating certSIGN ROOT CA G2 only has the websites bit enabled and does not have the email trust bit enabled.
Participants
certSIGN Mozilla representative
External References
Similar Local Cases
#1905070 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-28 · 100% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 67% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#1943135 RESOLVED Trust Bit Disablement Closure Request Opened 2025-01-22 · Closed 2025-05-25 · 67% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#847604 RESOLVED Trust Bit Disablement Opened 2013-03-04 · Closed 2022-11-14 · 60% similar
Turn off websites and code signing trust bits for two IdenTrust root certs
#1684158 RESOLVED Trust Bit Disablement Opened 2020-12-24 · Closed 2022-11-14 · 59% similar
PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
#1465625 RESOLVED Trust Bit Disablement Opened 2018-05-30 · Closed 2022-11-14 · 59% similar
Turn off Websites trust bit for OpenTrust and Certplus root certs
#1655074 RESOLVED Trust Bit Disablement Opened 2020-07-24 · Closed 2022-11-14 · 57% similar
Add several ICAs of Firmaprofesional to OneCRL
#1891438 RESOLVED Trust Bit Disablement Opened 2024-04-15 · Closed 2026-02-13 · 47% similar
Chunghwa Telecom: Postpone removal of ePKI Root CA's websites trust bit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action