← Wells Fargo Bank N.A. cases
Bugzilla #543881 Externally Reported Incident Security Incident Audit Finding

Please remove Wells Fargo from Mozilla's list of trusted root CAs

VERIFIED INVALID Wells Fargo Bank N.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by an external party requesting that Mozilla remove Wells Fargo from its listing of trusted root CAs. The opener claimed the situation was a “security vulnerability” and argued that CA trust should account for responsible disclosure and integrity. Mozilla staff responded that Wells Fargo’s CA had passed the required parts of Mozilla’s CA inclusion policy and that the root had been included based on required audits and conformance checks, noting that other major browsers also support the root. The Mozilla staff also pointed to Mozilla’s root inclusion policy and referenced a prior bug where the inclusion decision had been requested and approval granted. The opener later asked for details of the CA inclusion policy and the criteria used to allow or disallow CAs. The bug was marked INVALID and later noted as a duplicate of bug 545986.

Model: gpt-5.4-nano Generated: 2026-06-13 12:14 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.86 10 comments
Chronology
  1. An external reporter requested removal of Wells Fargo’s root CA from Mozilla’s trusted root list, alleging a security vulnerability.
  2. Mozilla staff reiterated that Wells Fargo’s root met Mozilla’s CA inclusion policy requirements and provided references to the policy and prior inclusion decision.
  3. The bug was marked as a duplicate of bug 545986.
Thread Activity
  1. Wcdean representative — Requested that Wells Fargo be removed from Mozilla’s list of root CAs, asserting it was a security vulnerability.
  2. Mozilla representative — Responded that Wells Fargo’s CA passed Mozilla’s CA inclusion policy requirements and asked for specific issues to be cited, pointing to the inclusion policy and related bugs.
  3. Community commenter — Said they looked at bug 342996 and marked the case verified.
  4. Wcdean representative — Asked for details of Mozilla’s CA inclusion policy and the criteria for allowing or disallowing CA roots.
  5. Community commenter — Provided a link to Mozilla’s CA/root inclusion policy page.
  6. Mozilla representative — Pointed to a specific bug comment for information about the decision to include Wells Fargo’s root.
  7. Mozilla representative — Asked the reporter to share or clarify the rationale explaining why the reporter believed there was an issue.
  8. Wcdean representative — Argued that SSL-related attacks and lack of disclosure after PKI exposure raised concerns, and urged Mozilla to re-review its requirements.
  9. Johnath representative — Responded that the discussion included handwaving and asked for concrete information to share.
  10. Mversen representative — Noted that bug 545986 was marked as a duplicate of this bug.
Participants
Wcdean representative Mozilla representative Community commenter Johnath representative Mversen representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 66% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1710206 RESOLVED Externally Reported Incident Certificate Misissuance Opened 2021-05-08 · Closed 2022-11-14 · 59% similar
Asseco DS / Certum: Incorrect localityName
#2049960 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-06-24 Still Open · 58% similar
Actalis: Undisclosed Subordinate CA Certificate
#2048995 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 Still Open · 57% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 57% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#1620772 RESOLVED Security Incident Opened 2020-03-07 · Closed 2023-02-22 · 57% similar
SSL.com: Issued precertificate with Debian Weak Key
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 56% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 56% similar
CFCA: OCSP Service return unauthorized responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action