NETLOCK: Transition Plan for Mozilla Root Store Policy 7.5 by Deadline
This case concerns NETLOCK’s “Arany (Gold) Class Root CA” certificate, which currently includes both TLS server authentication and S/MIME email protection trust bits. NETLOCK noted that Mozilla Root Store Policy Section 7.5 requires transitioning away from combined trust bits by a compliance deadline of December 31, 2028, but the root certificate’s validity end date is December 6, 2028, creating ambiguity about whether remediation is required versus natural expiration. NETLOCK opened a preliminary incident report describing this potential policy interpretation/compliance risk and referenced Mozilla’s public communication about the Section 7.5 transition plan deadline of April 15 as the context for internal identification. Mozilla staff indicated that bug #2033033 satisfies the Transition Plan category and that NETLOCK still needs to prepare a full incident report. NETLOCK asked the community to close this ticket and stated the full incident report would be handled under ticket #2033033. The ticket was set to be closed on or about 2026-04-27 and is marked RESOLVED with resolution FIXED.
- NETLOCK identified a potential Mozilla Root Store Policy 7.5 transition compliance ambiguity for its Arany (Gold) Class Root CA trust bits.
- NETLOCK requested closure of the preliminary ticket and indicated the full incident report would be handled in bug #2033033.
- The ticket was scheduled to be closed on or about this date and is marked RESOLVED (FIXED).
- Netlock — Roland (NETLOCK) submitted a preliminary incident report describing the combined TLS and S/MIME trust bits on the NETLOCK Arany (Gold) Class Root CA and the ambiguity created by the certificate’s December 6, 2028 validity end date versus the December 31, 2028 policy deadline.
- Mozilla representative — b**********n@mozilla.com pointed to bug #2033033 as satisfying the Transition Plan category and said NETLOCK still needs to prepare a full incident report.
- Netlock — Roland asked community members to proceed with closing this ticket and stated the issue would be handled under ticket #2033033, with the full incident report to be uploaded there shortly.
- CCADB representative — i**********g@ccadb.org stated the ticket would be closed on or about 2026-04-27.