Request to remove CNNIC root certificate from NSS after public concerns about trust and policy compliance
This case concerns a request to remove the CNNIC CA root certificate from NSS after a third party filed a bug asking Mozilla to remove it. The thread quickly filled with public comments alleging CNNIC was untrustworthy and raising concerns about government influence, possible policy violations, and the security impact of trusting the root. Mozilla staff responded that Bugzilla was not the right venue for advocacy, asked for concrete evidence of policy violations, and pointed users to the certificate manager for disabling trust locally. Kathleen Wilson later summarized that Mozilla had received reports of possible Mozilla CA Certificate Policy violations by CNNIC, said Mozilla had previously reviewed and accepted the root, and asked for substantiated evidence and professional discussion. The bug was ultimately resolved as INCOMPLETE, and the thread does not record a removal of CNNIC from the Mozilla root store.
- A third party filed a request to remove the CNNIC CA root certificate from NSS.
- Mozilla stated it had received reports of possible Mozilla CA Certificate Policy violations by CNNIC and asked for concrete evidence.
- Mozilla provided instructions for users to disable a root certificate authority by editing trust bits in the certificate manager.
- The bug remained resolved as INCOMPLETE.
- Community commenter — The reporter opened the bug and asked Mozilla to remove the CNNIC root certificate.
- Startcom representative — Eddy Nigg said the discussion belonged on mozilla.dev.security.policy and asked for evidence rather than advocacy.
- Mozilla representative — Kathleen Wilson said Mozilla had received reports of possible policy violations by CNNIC, had previously reviewed and accepted the root, and wanted substantiated evidence and professional input.
- Rossde representative — David E. Ross said the approval of CNNIC should be withdrawn until a thorough review and discussion could occur with participation from users in China.
- Mozilla representative — Kathleen Wilson posted step-by-step instructions for disabling a root CA by editing its trust bits in Firefox, Thunderbird, or SeaMonkey.
- Mozilla representative — Gerv noted that Chrome also trusts CNNIC on all platforms.