← ComSign cases
Bugzilla #675060 Root Inclusion

ComSign Global Root CA inclusion request and public discussion

RESOLVED WONTFIX ComSign
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ComSign requested Mozilla inclusion of a new root certificate, ComSign Global Root CA, initially described as a SHA-256 root with a 4096-bit public key. The request evolved over time as ComSign clarified that the new root was intended to replace its existing ComSign CA root, and Mozilla asked for supporting information including test websites, trust bits, CP/CPS documents, audit statements, and verification procedures. The discussion also covered OCSP/revocation testing, updated CPS versions, and a BR self-assessment that ComSign later provided. Mozilla ultimately denied the inclusion request after public discussion concerns, and stated that ComSign may submit a newly generated root and key-pair for inclusion. The bug was then moved to on-hold pending submission of the new root.

Model: gpt-5.4-mini Generated: 2026-06-13 12:17 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.96 62 comments
Chronology
  1. ComSign requested inclusion of a new ComSign Global Root CA certificate.
  2. ComSign provided an audit report for the root request.
  3. Mozilla opened public discussion for the ComSign Global Root CA request with Websites and Email trust bits.
  4. ComSign submitted a BR self-assessment and announced CPS version 4.0.
  5. Mozilla denied the inclusion request and said ComSign may submit a newly generated root and key-pair.
Thread Activity
  1. Mozilla representative — Mozilla recorded ComSign's request to include a new root certificate with SHA-256 and a 4096-bit key.
  2. Comda representative — ComSign said the new root would replace its current Comsign CA root and that the CPS was the same as the one used for the first root.
  3. Comda representative — ComSign corrected the case information, listed its company website, described the root hierarchy, and said the root was for email signing only at that time.
  4. Mozilla representative — Mozilla opened public discussion for the request and said the root would eventually replace the ComSign CA root already included in NSS.
  5. Mozilla representative — Mozilla said the WebTrust audit statements had been confirmed by the auditor and that the remaining action item was an updated/restructured CPS.
  6. Comda representative — ComSign said it had completed the BR self-assessment and published CPS version 4.0 with several links.
  7. Mozilla representative — Mozilla said it had verified CPS v4.0 and the BR self-assessment and updated CCADB accordingly.
  8. Fastly representative — Mozilla said it was denying the inclusion request due to concerns raised during public discussion and moved the bug on hold pending a newly generated root and key-pair.
Participants
Mozilla representative Comda representative ComSign Fastly representative Earthlink representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#420705 RESOLVED Root Inclusion Opened 2008-03-03 · Closed 2022-11-14 · 100% similar
add Comsign CA certs
#1265683 RESOLVED Root Inclusion Opened 2016-04-19 · Closed 2026-05-21 · 90% similar
Add [Certigna Root CA] root certificate(s)
#636557 RESOLVED Root Inclusion Opened 2011-02-24 · Closed 2022-11-14 · 89% similar
Add Visa Information Delivery Root CA certificate
#1277336 RESOLVED Root Inclusion Trust Bit Enablement Ev Enablement Opened 2016-06-01 · Closed 2022-11-14 · 89% similar
Add SSL.com root certificate(s)
#1128392 RESOLVED Root Inclusion Opened 2015-02-02 · Closed 2022-11-14 · 89% similar
Add GDCA Root Certificate
#1341604 RESOLVED Root Inclusion Certificate Misissuance Opened 2017-02-22 · Closed 2022-11-14 · 89% similar
Add Renewed Chunghwa Telecom eCA root certificate (ePKI Root Certification Authority - G2)
#848766 RESOLVED Root Inclusion Opened 2013-03-07 · Closed 2023-02-24 · 87% similar
Add OATI's Root CA Certificate to Mozilla's trusted root list
#1313982 RESOLVED Ca Certificate Root Program Root Inclusion Opened 2016-10-31 · Closed 2025-04-02 · 85% similar
Add SECOM root certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action