KIR SA: Transition Plan for Existing Dual-Purpose Roots
This case documents Krajowa Izba Rozliczeniowa S.A. (KIR)’s transition away from an existing dual-purpose root, SZAFIR ROOT CA2, which is currently trusted for both TLS (Websites) and S/MIME (Email). KIR states that in 2026 it generated separate single-purpose PKI hierarchies: SZAFIR ROOT CA3 TLS for TLS-only issuance and SZAFIR ROOT CA5 SMIME for S/MIME-only issuance. KIR plans to submit root inclusion requests for the new single-purpose roots in Q2 2026 after completion of annual WebTrust audits (starting 9 April 2026 and expected to end mid-June 2026). KIR expects that by Q1 2027 all newly issued TLS certificates will be issued exclusively under SZAFIR ROOT CA3 TLS, and issuance under SZAFIR ROOT CA2 will end, with the Websites trust bit removal requested no later than the expiration date of the last subscriber TLS certificate issued under SZAFIR ROOT CA2. For S/MIME, KIR similarly plans that by Q1 2027 newly issued S/MIME certificates will be issued exclusively under SZAFIR ROOT CA5 SMIME, with a request for distrust for S/MIME on SZAFIR ROOT CA2 no later than the expiration date of the last subscriber S/MIME certificate issued under SZAFIR ROOT CA2 and in any case no later than December 31, 2028. KIR also states that completion of the operational transition is expected within 90 days of trust store inclusion of the new root CA certificates.
- KIR submitted a transition plan to move from dual-purpose root SZAFIR ROOT CA2 to dedicated single-purpose TLS and S/MIME roots.
- Kir representative — Patryk Czychewicz submitted the transition plan describing the dual-purpose root SZAFIR ROOT CA2, the creation of SZAFIR ROOT CA3 TLS and SZAFIR ROOT CA5 SMIME, and the planned migration and distrust/removal timelines.