← Netlock cases
Bugzilla #2032939 Operational Change

NETLOCK: Transition Plan for Mozilla Root Store Policy 7.5 by Deadline

RESOLVED FIXED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns NETLOCK’s “Arany (Gold) Class Root CA” certificate, which currently includes both TLS server authentication and S/MIME email protection trust bits. NETLOCK noted that Mozilla Root Store Policy Section 7.5 requires transitioning away from combined trust bits by a compliance deadline of December 31, 2028, but the root certificate’s validity end date is December 6, 2028, creating ambiguity about whether remediation is required versus natural expiration. NETLOCK opened a preliminary incident report describing this potential policy interpretation/compliance risk and referenced Mozilla’s public communication about the Section 7.5 transition plan deadline of April 15 as the context for internal identification. Mozilla staff indicated that bug #2033033 satisfies the Transition Plan category and that NETLOCK still needs to prepare a full incident report. NETLOCK asked the community to close this ticket and stated the full incident report would be handled under ticket #2033033. The ticket was set to be closed on or about 2026-04-27 and is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:03 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.86 4 comments
Chronology
  1. NETLOCK identified a potential Mozilla Root Store Policy 7.5 transition compliance ambiguity for its Arany (Gold) Class Root CA trust bits.
  2. NETLOCK requested closure of the preliminary ticket and indicated the full incident report would be handled in bug #2033033.
  3. The ticket was scheduled to be closed on or about this date and is marked RESOLVED (FIXED).
Thread Activity
  1. Netlock — Roland (NETLOCK) submitted a preliminary incident report describing the combined TLS and S/MIME trust bits on the NETLOCK Arany (Gold) Class Root CA and the ambiguity created by the certificate’s December 6, 2028 validity end date versus the December 31, 2028 policy deadline.
  2. Mozilla representative — b**********n@mozilla.com pointed to bug #2033033 as satisfying the Transition Plan category and said NETLOCK still needs to prepare a full incident report.
  3. Netlock — Roland asked community members to proceed with closing this ticket and stated the issue would be handled under ticket #2033033, with the full incident report to be uploaded there shortly.
  4. CCADB representative — i**********g@ccadb.org stated the ticket would be closed on or about 2026-04-27.
Participants
Netlock Mozilla representative CCADB representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2033033 ASSIGNED Operational Change Opened 2026-04-17 Still Open · 99% similar
Netlock: Transition Plan for Existing Dual-Purpose Root
#2032170 ASSIGNED Operational Change Opened 2026-04-15 Still Open · 67% similar
SSL.com: Transition Plan for Existing Dual Purpose Roots
#2032051 ASSIGNED Operational Change Opened 2026-04-15 Still Open · 67% similar
DiSig: Transition Plan for Existing Dual-Purpose Roots
#2018158 ASSIGNED Dedicated Root Transition Operational Change Opened 2026-02-20 Still Open · 66% similar
OISTE: Transition Plan for Existing Dual-Purpose Root
#2031663 ASSIGNED Operational Change Opened 2026-04-14 Still Open · 59% similar
ACCV: Transition Plan for Existing Root
#2018979 ASSIGNED Remediation Tracking Self Reported Incident Opened 2026-02-24 Still Open · 59% similar
eMudhra: Transition Plan for Existing Dual-Purpose Roots
#2031732 ASSIGNED Operational Change Opened 2026-04-14 Still Open · 57% similar
DigiCert: Transition Plan for Existing Dual-Purpose Roots
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 48% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action