Add IdenTrust single purpose roots
IdenTrust requested inclusion of four newly created single-purpose roots into the Mozilla root program in preparation for rolling over its current multipurpose publicly trusted root, IdenTrust Commercial Root CA 1. The four roots listed were IdenTrust Commercial Root TLS RSA CA 2, IdenTrust Commercial Root SMIME RSA CA 2, IdenTrust Commercial Root TLS ECC CA 2, and IdenTrust Commercial Root SMIME ECC CA 2. As part of the root inclusion request process, IdenTrust created and submitted CCADB cases for RSA and ECC roots (Case #00002171 and Case #00002181). The thread later notes an incident being addressed: an issue where “IdenTrust Commercial Root TLS ECC CA 2” was missing from the relevant audit report, with an updated audit report provided via a referenced attachment. Mozilla staff asked IdenTrust to fix the “Bugzilla Bug (Link)” field in both CCADB cases so it points to this bug (https://bugzilla.mozilla.org/show_bug.cgi?id=1960408). IdenTrust created updated audit report attachments (Standard, CodeSigning, EVG, and SMIME) and confirmed that the Bugzilla URL in CCADB cases 2171/2181 was updated. The bug is currently marked as ASSIGNED.
- IdenTrust submitted a Mozilla root program inclusion request for four single-purpose roots as part of a rollover preparation.
- An issue was addressed regarding an audit report gap for IdenTrust Commercial Root TLS ECC CA 2, with an updated audit report referenced.
- Mozilla staff requested correction of the Bugzilla link field in the related CCADB cases to point to this bug.
- IdenTrust confirmed the Bugzilla URL update was resolved in CCADB cases 2171/2181.
- IdenTrust created updated audit report attachments for multiple audit types (Standard, CodeSigning, EVG, SMIME).
- IdenTrust Services, LLC — IdenTrust requested inclusion of four single-purpose roots and stated they submitted CCADB cases #00002171 (RSA) and #00002181 (ECC) on April 14, 2025.
- IdenTrust Services, LLC — IdenTrust stated the incident addressed an audit-report issue where “IdenTrust Commercial Root TLS ECC CA 2” was missing, and provided links to the updated audit report and related CCADB cases.
- Mozilla representative — Mozilla staff asked IdenTrust to fix the “Bugzilla Bug (Link)” field in CCADB cases 2171 and 2181 to use this bug’s URL.
- IdenTrust Services, LLC — IdenTrust confirmed that the URL in CCADB cases 2171/2181 was updated to https://bugzilla.mozilla.org/show_bug.cgi?id=1960408.
- IdenTrust Services, LLC — IdenTrust created attachments for updated Standard, CodeSigning, EVG, and SMIME audit reports (2023–2024).