← Entrust cases
Bugzilla #481723 Ca Certificate Compliance

entrust.net CA shows up as Verified by: "Trusted Secure Certificate Authority"

RESOLVED INVALID Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was filed because the user believed the CA display name shown in Firefox (“Verified by: "Trusted Secure Certificate Authority"”) was misleading or insufficiently informative. The reporter argued that the CA name string did not clearly identify the responsible organization and that users would need to view certificates directly to get more information. Mozilla staff and other participants explained that the string “Trusted Secure Certificate Authority” comes from the issuer’s certificate fields (CN/O) and that PSM/NSS displays the issuing CA name rather than a Mozilla-applied “friendly name.” Participants noted that the issue may relate to the intermediate CA’s naming practices and suggested checking the CA’s CPS and/or discouraging such naming conventions. Frank Hecker concluded that this is not actually a Mozilla bug and closed the bug as INVALID, while indicating that the policy angle would be tracked by adding the practice to a list of “problematic practices.”

Model: gpt-5.4-nano Generated: 2026-06-13 12:12 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.86 8 comments
Chronology
  1. A bug was opened alleging that Firefox displays a misleading CA name (“Verified by: Trusted Secure Certificate Authority”) for an entrust.net-related CA.
  2. Mozilla staff closed the bug as INVALID and noted a policy-tracking action for problematic CA naming practices.
Thread Activity
  1. Jengr representative — Reported that Firefox shows “Verified by: "Trusted Secure Certificate Authority"” and argued the name is vague/misleading and should display the validating corporation.
  2. Johnath representative — Suggested that changing a “friendly name” would be an NSS-level change and that the question is a CA Certificates policy issue.
  3. Bolyard representative — Disagreed that this is a Mozilla “friendly name” issue, stating the displayed string is the issuer’s certificate name (CN/O).
  4. Startcom representative — Said the intermediate CA’s naming should be checked against its CPS and that such naming conventions should be discouraged and added to Mozilla CA Policy.
  5. Johnath representative — Acknowledged the issue is likely with enTrust rather than Mozilla and asked whether to close or track the policy question.
  6. Startcom representative — Proposed an alternative of always showing the root CA as the issuer, noting it would be a PSM issue.
  7. Jengr representative — Added a note about MD5 collision policy context and reiterated concern about the generic root certificate name.
  8. Hecker representative — Closed the bug as INVALID because it is not a Mozilla bug, and said he would add the practice to a list of “problematic practices” while rejecting showing the root CA as issuer.
Participants
Jengr representative Johnath representative Bolyard representative Startcom representative Hecker representative
External References
Similar Local Cases
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 59% similar
GlobalSign: CRL contains invalid signature algorithm
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 59% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
#1475563 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2018-07-13 · Closed 2022-11-14 · 59% similar
GDCA: Misissuance of certificates with IP address
#1268225 RESOLVED Ca Certificate Compliance Opened 2016-04-27 · Closed 2022-11-14 · 59% similar
entrust: Invalid Teletext strings
#2002281 RESOLVED Ca Certificate Compliance Opened 2025-11-25 · Closed 2025-12-11 · 59% similar
Asseco DS / Certum: Irregularities in Xinchacha/Xcc Brand SSL Certificates
#1620727 RESOLVED Ca Certificate Compliance Incident Opened 2020-03-07 · Closed 2023-02-22 · 58% similar
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#1532112 RESOLVED Ca Certificate Compliance Opened 2019-03-03 · Closed 2023-02-22 · 58% similar
KIR S.A.: O > 64 characters
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 58% similar
KIR S.A.: Invalid organizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action