← AOL cases
Bugzilla #605187 Root Removal

Remove AOL Time Warner root certs

RESOLVED FIXED AOL
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is about AOL requesting removal of two AOL Time Warner root certificates from Mozilla’s CA root store. AOL stated the roots were obsolete and not in use, and that removing them would not impact Mozilla users because there were no current end-entity certificates chaining to either root. The bug was initiated with the root removal process described on Mozilla’s wiki. AOL later confirmed by email that these two specific root certificates should be removed. After the initial request, Mozilla turned off all trust bits for the two certificates, and a separate bug (#622719) was referenced as covering the actual NSS changes to remove these roots. The bug was resolved as FIXED, and the requester added documentation on restoring default root certificate settings on the Mozilla wiki.

Model: gpt-5.4-nano Generated: 2026-06-13 12:16 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.90 4 comments
Chronology
  1. AOL requested removal of two obsolete AOL Time Warner root certificates from Mozilla’s CA root store.
  2. AOL confirmed the two specific root certificates to be removed.
  3. Mozilla turned off trust bits for the two certificates and noted related profile/NSS handling concerns.
  4. Documentation was added to the Mozilla wiki about restoring default root certificate settings.
Thread Activity
  1. Mozilla representative — AOL requested removal of two obsolete AOL Time Warner roots and stated there were no current end-entity certs chaining to them, linking to the root removal process wiki page.
  2. Mozilla representative — The requester said they received an email from an AOL representative confirming the two root certificates to remove.
  3. Rossde representative — David reported that trust bits were already turned off and explained that the certificates may still exist in a separate profile database until the removal is implemented via related changes.
  4. Mozilla representative — The requester said they added a wiki section on how to restore default root certificate settings and noted that bug #622719 covers the actual NSS changes.
Participants
Mozilla representative Rossde representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1420855 RESOLVED Root Removal Opened 2017-11-27 · Closed 2022-11-14 · 71% similar
Remove CA Disig Root R1
#1301731 RESOLVED Root Removal Certificate Misissuance Opened 2016-09-09 · Closed 2022-11-14 · 66% similar
ANSSI: problematic certificates issued by AC Infrastructure
#1640819 RESOLVED Root Removal Opened 2020-05-26 · Closed 2022-11-14 · 62% similar
Remove CN=LuxTrust Global Root 2 root cert
#487150 RESOLVED Root Removal Opened 2009-04-07 · Closed 2022-11-14 · 60% similar
Removal request of StartCom 1024 bit CA root
#2024749 ASSIGNED Root Removal Opened 2026-03-19 Still Open · 58% similar
Firmaprofesional: Request for voluntary root removal - FIRMAPROFESIONAL CA ROOT-A WEB
#849833 RESOLVED Root Removal Opened 2013-03-11 · Closed 2022-11-14 · 49% similar
Basic Constraint Ext: Proposal: Remove old Entrust 2048 root, add equivalent 2048 intermediate
#1455053 RESOLVED Root Removal Opened 2018-04-18 · Closed 2022-11-14 · 49% similar
Add some Firmaprofesional SubCAs to OneCRL
#542689 RESOLVED Root Removal Incident Opened 2010-01-28 · Closed 2022-11-14 · 48% similar
Please remove CNNIC CA root certificate from NSS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action