← eMudhra Technologies Limited cases
Bugzilla #2018979 Remediation Tracking Self Reported Incident

eMudhra: Transition Plan for Existing Dual-Purpose Roots

ASSIGNED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This bug tracks eMudhra’s transition of dual-purpose root certificates in accordance with MRSP §7.5.3. eMudhra stated it is migrating away from multi-purpose PKI hierarchies and submitted purpose-dedicated root certificates for inclusion (Bug 1889859; CCADB Case 00001777), which are under review. While inclusion is pending, eMudhra identified four roots enabled with both Websites and Email trust bits (emSign ECC Root CA - C3, emSign ECC Root CA - G3, emSign Root CA - C1, and emSign Root CA - G1) and provided last non-TLS issuance dates and proposed distrust-after dates for Mozilla to enforce. eMudhra stated that non-TLS (S/MIME and other non-TLS) issuance under the dual-use roots would cease with a target of March 2026, and that non-TLS subordinate CAs chaining to the multi-purpose roots would be decommissioned and revoked by June 15, 2026. On June 17, 2026, eMudhra confirmed that revocation of all Non-TLS subordinate CA certificates chaining to emSign Root CA - G1 and emSign ECC Root CA - G3 has been completed as of June 15, 2026, and provided a table of revoked subordinate CA certificates with revocation dates and reasons. The bug remains in ASSIGNED status with no resolution recorded in the thread.

Model: gpt-5.4-nano Generated: 2026-06-13 21:32 UTC Revised: 2026-06-19 19:32 UTC Confidence: 0.86 3 comments
Chronology
  1. Mozilla opened a tracking bug for eMudhra’s MRSP §7.5.3 transition plan for dual-purpose roots.
  2. eMudhra provided last non-TLS issuance dates and proposed distrust-after dates for the affected dual-purpose roots’ trust bits.
  3. eMudhra completed revocation of all Non-TLS subordinate CA certificates chaining to the multi-purpose roots emSign Root CA - G1 and emSign ECC Root CA - G3.
Thread Activity
  1. Mozilla representative — Opened the bug to track eMudhra’s §7.5.3 transition obligations for dual-purpose roots and requested estimated dates for when no new issuance would occur and when Mozilla should remove trust bits or configure distrust-after.
  2. Emudhra representative — Provided last S/MIME/non-TLS issuance dates and proposed notBefore-based distrust-after dates for Email and/or TLS trust bits for each listed root, including requests to retain trust bits for emSign Root CA - G1 and emSign ECC Root CA - G3 due to cross-signing by their purpose-based TLS roots.
  3. Emudhra representative — Confirmed that revocation of all Non-TLS (S/MIME, Client Auth, Code Signing, Timestamping, and Device) subordinate CA certificates chaining to emSign Root CA - G1 and emSign ECC Root CA - G3 was completed as of June 15, 2026, and provided a revocation details table.
Participants
Mozilla representative Emudhra representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032047 ASSIGNED Dedicated Root Transition Remediation Tracking Single Ca Owner Opened 2026-04-15 Still Open · 60% similar
Actalis: Transition Plan for Existing Dual-Purpose Root
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 48% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 40% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 40% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 40% similar
IdenTrust: Improper encoding of wildcard certificate
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 40% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1565494 RESOLVED Audit Finding Self Reported Incident Repository Issue Opened 2019-07-12 · Closed 2024-06-30 · 39% similar
CFCA: Missed annual CPS update publication on website in 2018
#1954889 RESOLVED Self Reported Incident Revocation Issue Opened 2025-03-19 · Closed 2025-03-28 · 39% similar
Certainly: Early CRL Entry Removal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action