← IdenTrust Services, LLC cases
Bugzilla #847604 Trust Bit Disablement

Turn off websites and code signing trust bits for two IdenTrust root certificates

RESOLVED DUPLICATE IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust requested that Mozilla disable the websites and code signing trust bits for two specific IdenTrust root certificates. The request identified the roots by friendly name and SHA-1 fingerprints, and stated that only the email trust bit should remain enabled for both certificates. Mozilla asked for confirmation that the provided information was correct, and IdenTrust confirmed the requested changes were on the correct roots. Later, a comment noted that Bug 1205108 removed the roots in question and that this bug was marked as a duplicate of Bug 1205108. The bug is currently resolved as DUPLICATE.

Model: gpt-5.4-nano Generated: 2026-06-13 13:00 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.86 4 comments
Chronology
  1. IdenTrust requested Mozilla disable websites and code signing trust bits for two IdenTrust root certificates, leaving only the email trust bit enabled.
  2. IdenTrust confirmed the requested trust-bit changes were applied to the correct root certificates.
  3. The roots in question were removed in the referenced work, and this bug was marked as a duplicate.
Thread Activity
  1. Mozilla representative — IdenTrust asked Mozilla to turn off the websites and code signing trust bits for two specified root certificates and to enable only the email trust bit for both.
  2. Mozilla representative — A request was made to confirm the information in the prior message was correct.
  3. Community commenter — IdenTrust confirmed the requested changes were on the correct roots.
  4. Community commenter — It was noted that Bug 1205108 removed the roots in question and that this bug was marked as a duplicate of Bug 1205108.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1465625 RESOLVED Trust Bit Disablement Opened 2018-05-30 · Closed 2022-11-14 · 64% similar
Turn off Websites trust bit for OpenTrust and Certplus root certs
#1943135 RESOLVED Trust Bit Disablement Closure Request Opened 2025-01-22 · Closed 2025-05-25 · 63% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#1905070 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-28 · 62% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA cert
#2052090 ASSIGNED Trust Bit Disablement Incident Opened 2026-07-02 Still Open · 60% similar
Remove the Email (S/MIME) trust bit for ePKI Root Certification Authority
#1684158 RESOLVED Trust Bit Disablement Opened 2020-12-24 · Closed 2022-11-14 · 60% similar
PKIoverheid: Removal of websites trust bit for "Staat der Nederlanden Root CA – G3"
#1905072 RESOLVED Trust Bit Disablement Opened 2024-06-27 · Closed 2024-08-22 · 60% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#1655074 RESOLVED Trust Bit Disablement Opened 2020-07-24 · Closed 2022-11-14 · 58% similar
Add several ICAs of Firmaprofesional to OneCRL
#1347882 RESOLVED Trust Bit Disablement Certificate Misissuance Opened 2017-03-16 · Closed 2023-01-25 · 47% similar
GlobalSign: Remove EV bit from ex-GS roots now owned by GTS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action