GlobalSign: Transition Plan for Existing Dual-Purpose Roots
This case concerns GlobalSign’s transition away from existing dual-purpose (multi-purpose) roots that currently have both website and email trust bits enabled in NSS. The CA submitted a transition plan with a commitment to complete its transition to dedicated TLS roots well in advance of Mozilla’s December 31, 2028 deadline. GlobalSign states it intends to align its approach with Chrome’s transition model. Specifically, it proposes to continue issuing TLS certificates from its multi-purpose roots until September 15, 2026, described as the latest date permitted under Chrome’s SCTNotAfter enforcement. GlobalSign indicates that certificates issued up to that date would use the maximum allowed validity period, and that no further TLS issuance from multi-purpose roots would occur after that point. The plan also states that the issued certificates would expire by approximately October 2027, after which the multi-purpose roots would no longer be needed for TLS.
- GlobalSign submitted a transition plan to move from dual-purpose roots to dedicated TLS roots ahead of Mozilla’s December 31, 2028 deadline.
- Mozilla representative — Ben Wilson reported that GlobalSign submitted a transition plan, including the four currently enabled roots in NSS and a proposed TLS issuance cutoff of September 15, 2026 under Chrome’s SCTNotAfter enforcement.