SSL.com: Transition Plan for Existing Dual Purpose Roots
SSL.com submitted a transition plan to Mozilla pursuant to Mozilla Root Store Policy section 7.5.3 for two dual-purpose roots currently included in Mozilla’s root store: SSL.com Root Certification Authority RSA and SSL.com Root Certification Authority ECC. The plan is to migrate publicly trusted TLS issuance from these dual-purpose roots to SSL.com’s dedicated TLS hierarchies already included in Mozilla’s root store (SSL.com TLS RSA Root CA 2022 and SSL.com TLS ECC Root CA 2022). After the migration, SSL.com will request removal of the websites trust bit from the two legacy roots, with completion no later than December 31, 2028. SSL.com stated it has already established dedicated TLS successor roots and will use the period through 2028 to inventory, phase out, replace, or retire remaining TLS dependencies under the legacy roots, while maintaining continuity for email trust where applicable. The submission also notes that for dual-purpose roots attached to SSL.com’s newly acquired CA, VikingCloud, SSL.com submitted requests to remove VikingCloud root certificates, referencing Bug 2020019 and Bug 2020144. The bug is currently in ASSIGNED status.
- SSL.com submitted a transition plan for two dual-purpose roots and proposed migrating TLS issuance to dedicated TLS successor roots, with legacy websites trust bit removal targeted by Dec 31, 2028.
- SSL.com — SSL.com submitted the transition plan describing migration from the dual-purpose roots to dedicated TLS roots and a plan to request removal of the websites trust bit by December 31, 2028, with references to prior VikingCloud root removal bugs.