Add certSIGN Root CA G4 root certificate
This case requests inclusion of the certSIGN Root CA G4 certificate in Mozilla’s root program. The submitter states that certSIGN ROOT CA G4 was created to build a PKI system dedicated for TLS certificates intended to replace the existing “All purpose” certSIGN G2 PKI system. The thread also notes that the existing certSIGN ROOT CA G2 will be removed from the Mozilla Trusted List in April 2026 due to the age of the key material. The submitter provided a key generation ceremony report and a CCADB Self Assessment Framework document for the new root, and referenced the certSIGN ROOT CA G4 Certification Practice Statement. In the latest update, the reporter says they received the audit report for certSIGN ROOT CA G4 and added it into the corresponding CCADB fields. The bug remains in ASSIGNED status.
- certSIGN submitted a request to add the certSIGN Root CA G4 certificate to Mozilla’s root store.
- certSIGN received the audit report for certSIGN Root CA G4 and updated corresponding CCADB fields.
- certSIGN — Submitted the request to add certSIGN Root CA G4, stating it replaces the “All purpose” certSIGN G2 system and noting G2 removal from the Mozilla Trusted List in April 2026.
- certSIGN — Provided links to the key generation ceremony report and the CCADB Self Assessment Framework (vSep2025) for certSIGN Root CA G4.
- certSIGN — Referenced the certSIGN Root CA G4 Certification Practice Statement (v1.1).
- certSIGN — Reported that the audit report for certSIGN Root CA G4 was received and added into the corresponding CCADB fields.