Certigna: Transition Plan for Existing Dual-Purpose Root
This case documents Certigna’s transition plan for existing dual-purpose root(s) that are expiring in 2027 and 2033. For the Certigna CA expiring in 2027, Certigna states it will stop issuing publicly recognized TLS end-user certificates after June 15, 2026, with 90-day certificates expiring no later than September 15, 2026, and that the TLS bit may be removed as of September 15, 2026. For SMIME, Certigna states it no longer issues SMIME certificates and that it is replaced by the “Certigna Root CA” root CA, with the SMIME bit to be removed for this root CA. For the “Certigna Root CA” expiring in 2033, Certigna states it will also stop issuing publicly recognized TLS end-user certificates after June 15, 2026 (90-day validity, expiring no later than September 15, 2026) and that the TLS bit may be removed as of September 15, 2026. Certigna further states that it issues SMIME certificates and that its “Certigna Email Protection Root CA” and “Certigna Email Protection EU Root CA” authorities will be submitted for integration in 2026 unless a decision is made to cease issuing publicly recognized SMIME certificates.
- Certigna submitted a transition plan for its expiring dual-purpose root(s), including timelines to stop issuing TLS and SMIME and potential trust-bit removals.
- Mozilla representative — Ben Wilson posted Certigna’s transition plan, specifying issuance cutoffs for TLS and SMIME and when TLS/SMIME bits may be removed, plus SMIME integration plans for 2026.