← Entrust cases
Bugzilla #694536 Root Update Request

Entrust request to replace the Entrust.net Certification Authority (2048) root and enable EV

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Entrust’s request to replace the existing "Entrust.net Certification Authority (2048)" root certificate while keeping its trust bits enabled and enabling EV. Entrust provided details for the existing root and a new "Entrust Root Certification Authority - G2" root, but the G2 inclusion was later split into a separate bug. Mozilla requested and reviewed CA information, discussed EV testing requirements, and asked Entrust to provide a working EV test site chained through the correct certificate path. Mozilla approved the root update for the Entrust.net Certification Authority (2048) root, and noted that EV treatment would be handled separately after successful EV testing. The thread also records that bug 856678 was filed for the actual NSS root replacement, and bug 1102519 was filed later for EV treatment.

Model: gpt-5.4-mini Generated: 2026-06-13 12:18 UTC Revised: 2026-06-16 18:30 UTC Confidence: 0.96 35 comments
Chronology
  1. Entrust requested replacement of the Entrust.net Certification Authority (2048) root certificate and provided a new G2 root for consideration.
  2. The G2 root inclusion was moved to a separate bug, leaving this bug focused on the replacement root certificate.
  3. Mozilla approved updating the Entrust.net Certification Authority (2048) root certificate and keeping all three trust bits enabled.
  4. Entrust updated the 2048 test site to use a test certificate issued from an intermediate CA, and Mozilla filed bug 1102519 for EV treatment.
Thread Activity
  1. Entrust representative — Bruce Morton opened the request and attached the Entrust.net Certification Authority (2048) root certificate and the Entrust Root Certification Authority - G2 root certificate.
  2. Mozilla representative — Kathleen Wilson said she hoped to begin information verification soon and would update the bug later.
  3. Mozilla representative — Kathleen reported an OCSP error when visiting the G2 test site and said the CRL link did not seem to work.
  4. Entrust representative — Bruce said the G2 root was not in production and that CRL or OCSP support was not currently being provided for it.
  5. Mozilla representative — Kathleen said she could start discussion for the 2048 root once there was a test website with an EV SSL cert chaining to that root and EV testing was completed.
  6. Entrust representative — Bruce provided an EV test site for the 2048 root and said the certificate had expired.
  7. Mozilla representative — Kathleen asked Bruce to issue a new certificate for the EV test site.
  8. Mozilla representative — Kathleen said the G2 root inclusion had been moved to bug 849950 and that this bug would cover only the replacement of the Entrust.net Certification Authority (2048) root certificate.
  9. Entrust representative — Bruce said the CNNIC cross-certificate had expired, the CPS documents had been updated, and OCSP responses were generated every 8 hours.
  10. Mozilla representative — Kathleen opened public discussion for Entrust’s request to replace the root, keep all three trust bits enabled, and enable EV.
  11. Mozilla representative — Kathleen approved the request to update the Entrust.net Certification Authority (2048) root certificate and said EV-enablement would wait for successful EV testing.
  12. Entrust representative — Bruce said the 2048 test site had been updated with a test certificate issued from an intermediate CA.
  13. Mozilla representative — Kathleen posted EV checking tool output showing success and said she had filed bug 1102519 for enabling EV treatment for this root.
Participants
Entrust representative Mozilla representative Kuix representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#849833 RESOLVED Root Removal Opened 2013-03-11 · Closed 2022-11-14 · 68% similar
Basic Constraint Ext: Proposal: Remove old Entrust 2048 root, add equivalent 2048 intermediate
#416544 RESOLVED Ev Enablement Opened 2008-02-09 · Closed 2022-11-14 · 49% similar
Enable Entrust roots for EV
#745671 RESOLVED Trust Bit Enablement Opened 2012-04-16 · Closed 2022-11-14 · 45% similar
Enable EV and Turn on Code Signing trust bit for TWCA Root certificate
#849950 RESOLVED Root Inclusion Opened 2013-03-11 · Closed 2022-11-14 · 42% similar
Add Entrust G2 and EC1 root certificates
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 40% similar
Entrust: Outdated audit statement for intermediate cert
#1268225 RESOLVED Ca Certificate Compliance Opened 2016-04-27 · Closed 2022-11-14 · 39% similar
entrust: Invalid Teletext strings
#794036 RESOLVED Ev Enablement Opened 2012-09-25 · Closed 2022-11-14 · 35% similar
Enable EV for Firmaprofesional

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action