← GoDaddy cases
Bugzilla #1943135 Trust Bit Disablement Closure Request

Request to disable SMIME trust bit for GoDaddy and Starfield G2 roots

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy requested that Mozilla disable the SMIME “trust bit” (email and code signing trust bits) for specific GoDaddy and Starfield G2 root certificates that are active in Mozilla’s root store. In the request, GoDaddy stated that although the roots can technically support code signing and SMIME certificates, GoDaddy only uses them in trust chains for DV, OV, and EV leaf certificates, and that it no longer issues code signing certificates (last issuance in early 2021; last certificate under management expired in late 2022). GoDaddy also stated it has not used these roots for SMIME issuance and does not plan to do so. Mozilla confirmed that the Go Daddy Root Certificate Authority - G2 and the Starfield Root Certificate Authority - G2 are not enabled for email issuance in NSS, and that none of the four certificates are trusted in NSS for code signing, leaving two root certificates affected by the request. Mozilla distributed the resulting change in Nightly 139.0a1 on 2025-04-28, and the bug is marked RESOLVED with resolution FIXED. The bug was created by GoDaddy (Steven Deitte) and assigned to Ben Wilson (b**********n@mozilla.com).

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.90 5 comments
Chronology
  1. GoDaddy requested removal of SMIME (email and code signing) trust bits for specific active GoDaddy/Starfield G2 roots in Mozilla’s root store.
  2. Mozilla distributed the trust-bit change in Nightly 139.0a1 (2025-04-28).
Thread Activity
  1. GoDaddy — Steven Deitte requested removal of email and code signing trust bits for GoDaddy Class 2 and Starfield Class 2 G2 roots, explaining GoDaddy no longer issues code signing and does not plan SMIME issuance.
  2. Mozilla representative — Ben Wilson confirmed the G2 roots are not enabled for email issuance in NSS and that none are trusted for code signing, identifying the two affected root certificates.
  3. Mozilla representative — bbeurdouche created an attachment for disabling the SMIME trust bit for the GoDaddy CAs.
  4. Mozilla representative — bbeurdouche linked an NSS revision (hg-edge.mozilla.org) related to the change.
  5. Mozilla representative — Ben Wilson confirmed the change was distributed in Nightly 139.0a1 (2025-04-28).
Participants
GoDaddy Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1949895 RESOLVED Delayed Revocation Closure Request Opened 2025-02-21 · Closed 2025-05-13 · 74% similar
GoDaddy: Delayed CRL File Updates
#1905070 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-28 · 70% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 68% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#1905072 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-22 · 67% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 65% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 65% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#847604 RESOLVED Trust Bit Disablement Opened 2013-03-04 · Closed 2022-11-14 · 63% similar
Turn off websites and code signing trust bits for two IdenTrust root certs
#1465625 RESOLVED Trust Bit Disablement Opened 2018-05-30 · Closed 2022-11-14 · 61% similar
Turn off Websites trust bit for OpenTrust and Certplus root certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action