← Entrust cases
Bugzilla #849833 Root Removal

Basic Constraint Extension (BCE) fix: remove old Entrust 2048 root and add replacement intermediate

RESOLVED DUPLICATE Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns an Entrust 2048 root certificate in Mozilla’s root store that lacks a “Basic Constraint Extension” (BCE), which was causing problems for an application consuming the Mozilla root list. The reporter proposed removing the old root certificate (serial 0x3863b966) and adding a replacement intermediate certificate (serial 0x469e911a) that contains the correct BCE. Entrust confirmed it had re-issued a certificate to address the BCE issue and said it started the process to include the replacement in Mozilla, but that the process was not completed due to actions required by Entrust. Entrust also referenced another Mozilla request (bug 694536) as the related process and discussed timing considerations for trust changes. Kathleen Wilson asked about the time frame and suggested separating the root replacement request from an unrelated new root request in bug 694536. The bug was ultimately resolved as a duplicate of bug 694536 because the replacement plan in that other bug made this proposal unnecessary.

Model: gpt-5.4-nano Generated: 2026-06-13 13:01 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.86 6 comments
Chronology
  1. Reporter proposed replacing an Entrust 2048 root lacking BCE with a BCE-correct replacement intermediate in Mozilla’s root store.
Thread Activity
  1. Kuix representative — Reported that a specific Entrust root certificate in Mozilla’s store lacks BCE and proposed removing the old root and adding a replacement intermediate with BCE.
  2. Kuix representative — Asked Entrust for comments on the proposal, including whether Entrust had issued still-valid certificates using the old root and how long the old root would need to remain valid.
  3. Entrust representative — Confirmed Entrust had re-issued the certificate with the correct BCE, said inclusion in Mozilla was started but not completed due to Entrust actions, and referenced bug 694536 as the request.
  4. Mozilla representative — Asked for a time frame and suggested separating the root replacement request from an unrelated new root request in bug 694536 to resolve the BCE issue first.
  5. Kuix representative — Agreed to separate the root replacement request and finish the approval process to resolve the issue for a product scheduled to ship in June 2013.
  6. Kuix representative — Resolved the bug as a duplicate of bug 694536 because the replacement plan there made this proposal unnecessary.
Participants
Kuix representative Mozilla representative Entrust representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#694536 RESOLVED Root Update Request Opened 2011-10-14 · Closed 2022-11-14 · 68% similar
Replace Entrust.net Certification Authority (2048) root certificate
#380067 RESOLVED Root Removal Root Inclusion Opened 2007-05-08 · Closed 2022-11-14 · 58% similar
Delete Visa International Root - GP2 and add Visa International Root - InfoDelivery
#406794 RESOLVED Root Removal Opened 2007-12-04 · Closed 2022-11-14 · 57% similar
Refresh the GlobalSign Root CA cert (will be EV)
#1455053 RESOLVED Root Removal Opened 2018-04-18 · Closed 2022-11-14 · 49% similar
Add some Firmaprofesional SubCAs to OneCRL
#605187 RESOLVED Root Removal Opened 2010-10-18 · Closed 2022-11-14 · 49% similar
Remove AOL Time Warner root certs
#1841551 RESOLVED Root Removal Opened 2023-07-03 · Closed 2023-07-11 · 48% similar
Remove duplicate Firmaprofesional root certificate
#416544 RESOLVED Ev Enablement Opened 2008-02-09 · Closed 2022-11-14 · 47% similar
Enable Entrust roots for EV
#1420855 RESOLVED Root Removal Opened 2017-11-27 · Closed 2022-11-14 · 47% similar
Remove CA Disig Root R1

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action