Please remove Wells Fargo from Mozilla's list of trusted root CAs
The bug was opened by an external party requesting that Mozilla remove Wells Fargo from its listing of trusted root CAs. The opener claimed the situation was a “security vulnerability” and argued that CA trust should account for responsible disclosure and integrity. Mozilla staff responded that Wells Fargo’s CA had passed the required parts of Mozilla’s CA inclusion policy and that the root had been included based on required audits and conformance checks, noting that other major browsers also support the root. The Mozilla staff also pointed to Mozilla’s root inclusion policy and referenced a prior bug where the inclusion decision had been requested and approval granted. The opener later asked for details of the CA inclusion policy and the criteria used to allow or disallow CAs. The bug was marked INVALID and later noted as a duplicate of bug 545986.
- An external reporter requested removal of Wells Fargo’s root CA from Mozilla’s trusted root list, alleging a security vulnerability.
- Mozilla staff reiterated that Wells Fargo’s root met Mozilla’s CA inclusion policy requirements and provided references to the policy and prior inclusion decision.
- The bug was marked as a duplicate of bug 545986.
- Wcdean representative — Requested that Wells Fargo be removed from Mozilla’s list of root CAs, asserting it was a security vulnerability.
- Mozilla representative — Responded that Wells Fargo’s CA passed Mozilla’s CA inclusion policy requirements and asked for specific issues to be cited, pointing to the inclusion policy and related bugs.
- Community commenter — Said they looked at bug 342996 and marked the case verified.
- Wcdean representative — Asked for details of Mozilla’s CA inclusion policy and the criteria for allowing or disallowing CA roots.
- Community commenter — Provided a link to Mozilla’s CA/root inclusion policy page.
- Mozilla representative — Pointed to a specific bug comment for information about the decision to include Wells Fargo’s root.
- Mozilla representative — Asked the reporter to share or clarify the rationale explaining why the reporter believed there was an issue.
- Wcdean representative — Argued that SSL-related attacks and lack of disclosure after PKI exposure raised concerns, and urged Mozilla to re-review its requirements.
- Johnath representative — Responded that the discussion included handwaving and asked for concrete information to share.
- Mversen representative — Noted that bug 545986 was marked as a duplicate of this bug.