Add GlobalSign's ECC Roots to Mozilla's root store
GlobalSign opened this bug to request embedding of its ECC root certificates (“GlobalSign Root CA - R4” and “GlobalSign Root CA - R5”) into Mozilla’s root store. The submission included requested trust bits and technical details for both roots, along with URLs for the root certificates and a test site. GlobalSign later withdrew the application, stating that Symantec engineering reviewed the ECC roots and offline highlighted a potential flaw involving encoded null values. GlobalSign said it would recreate the roots and re-submit, and asked for a new bug when ready. A Mozilla participant questioned why GlobalSign believed the issue was not a problem for RFC 5758, citing RFC language and pointing out that the roots (and the end-entity test certificates) included NULL parameters. GlobalSign responded that browsers had accepted the certificates despite non-compliance and clarified that it agreed the roots should respect RFC 5758 and would re-cut them. The bug is currently resolved as WONTFIX.
- GlobalSign submitted a request to include its ECC root certificates (R4 and R5) in Mozilla’s root store.
- GlobalSign withdrew the ECC root inclusion request after identifying a potential encoded-null flaw highlighted during external review.
- Mozilla participants discussed the RFC 5758 compliance concern and GlobalSign clarified its understanding and next steps.
- GlobalSign nv-sa — Opened the bug to embed GlobalSign ECC roots and indicated additional checklist information would be added.
- GlobalSign nv-sa — Provided general information and technical details for Root CA R4 and R5, including certificate URLs, fingerprints, validity, revocation/OCSP notes, and requested trust bits.
- GlobalSign nv-sa — Withdrew the application, saying Symantec engineering highlighted a potential flaw with encoded null values, and stated GlobalSign would recreate the roots and re-submit.
- Mozilla representative — Asked to file a new bug when the recreated roots were ready.
- Velox representative — Questioned GlobalSign’s rationale about RFC 5758 and cited RFC requirements, noting NULL parameters in the roots and test end-entity certificates.
- GlobalSign nv-sa — Clarified that browsers accepted the certificates despite non-compliance, agreed the roots should respect RFC 5758, and said GlobalSign would re-cut them.