Sectigo: Transition Plan for Existing Dual-Purpose Roots
This case documents Sectigo’s transition plan to migrate its existing dual-purpose roots to S/MIME-only trust before 2029, pursuant to section 7.5.3 of the Mozilla Root Store Policy. The trigger for the transition is that, according to Mozilla’s Root CA Lifecycle Transition Schedule, the Websites trust bit for all but one of Sectigo’s dual-purpose roots was due to be removed before 2029 due to the age of their key generation dates. Mozilla acknowledged receipt of Sectigo’s plan and stated it would proceed with an NSS bug to remove the Websites trust bit for three specific root CA certificates: COMODO Certification Authority, Entrust Root Certification Authority – G2, and Entrust Root Certification Authority – EC1. Mozilla also stated that removing the Websites trust bit would transition these roots to S/MIME-only trust, with further trust bit removals for the remaining dual-purpose roots handled according to the published schedule. On 2026-04-15, the CA Program reported that in NSS 3.123 and Firefox 151 the Websites trust bit was removed from those three root CA certificates and that CCADB records were updated accordingly. The bug remains in ASSIGNED status.
- Sectigo submitted a transition plan to migrate dual-purpose roots to S/MIME-only trust before 2029.
- Mozilla acknowledged the plan and indicated it would remove the Websites trust bit for three specified roots via an NSS change.
- Mozilla removed the Websites trust bit for the three specified roots in NSS 3.123/Firefox 151 and updated CCADB records.
- Sectigo — Rob Stradling provided Sectigo’s transition plan for migrating dual-purpose roots to S/MIME-only before 2029 and requested removal of the Websites trust bit from the Entrust G2 and EC1 roots at the earliest convenience.
- Mozilla representative — Ben Wilson acknowledged receipt of the plan and said Mozilla would proceed with an NSS bug to remove the Websites trust bit for COMODO, Entrust G2, and Entrust EC1, transitioning them to S/MIME-only trust.
- Mozilla representative — Ben Wilson reported that in NSS 3.123 and Firefox 151 the Websites trust bit was removed from COMODO, Entrust G2, and Entrust EC1, and that CCADB records were updated accordingly.