eMudhra: Transition Plan for Existing Dual-Purpose Roots
This bug tracks eMudhra’s transition of dual-purpose root certificates in accordance with MRSP §7.5.3. eMudhra stated it is migrating away from multi-purpose PKI hierarchies and submitted purpose-dedicated root certificates for inclusion (Bug 1889859; CCADB Case 00001777), which are under review. While inclusion is pending, eMudhra identified four roots enabled with both Websites and Email trust bits (emSign ECC Root CA - C3, emSign ECC Root CA - G3, emSign Root CA - C1, and emSign Root CA - G1) and provided last non-TLS issuance dates and proposed distrust-after dates for Mozilla to enforce. eMudhra stated that non-TLS (S/MIME and other non-TLS) issuance under the dual-use roots would cease with a target of March 2026, and that non-TLS subordinate CAs chaining to the multi-purpose roots would be decommissioned and revoked by June 15, 2026. On June 17, 2026, eMudhra confirmed that revocation of all Non-TLS subordinate CA certificates chaining to emSign Root CA - G1 and emSign ECC Root CA - G3 has been completed as of June 15, 2026, and provided a table of revoked subordinate CA certificates with revocation dates and reasons. The bug remains in ASSIGNED status with no resolution recorded in the thread.
- Mozilla opened a tracking bug for eMudhra’s MRSP §7.5.3 transition plan for dual-purpose roots.
- eMudhra provided last non-TLS issuance dates and proposed distrust-after dates for the affected dual-purpose roots’ trust bits.
- eMudhra completed revocation of all Non-TLS subordinate CA certificates chaining to the multi-purpose roots emSign Root CA - G1 and emSign ECC Root CA - G3.
- Mozilla representative — Opened the bug to track eMudhra’s §7.5.3 transition obligations for dual-purpose roots and requested estimated dates for when no new issuance would occur and when Mozilla should remove trust bits or configure distrust-after.
- Emudhra representative — Provided last S/MIME/non-TLS issuance dates and proposed notBefore-based distrust-after dates for Email and/or TLS trust bits for each listed root, including requests to retain trust bits for emSign Root CA - G1 and emSign ECC Root CA - G3 due to cross-signing by their purpose-based TLS roots.
- Emudhra representative — Confirmed that revocation of all Non-TLS (S/MIME, Client Auth, Code Signing, Timestamping, and Device) subordinate CA certificates chaining to emSign Root CA - G1 and emSign ECC Root CA - G3 was completed as of June 15, 2026, and provided a revocation details table.