Re: CCADB Update: Unified Audit Document Downloads, BIMI Trust Bits, Automated Status Propagation, and Case UI Enhancements
2026/09/03 -- CCADB Support
2026/09/03 -- CCADB Support
2026/09/01 -- 'Preston Locke' via dev-security-policy@mozilla.org
2026/09/01 -- Jeffrey Walton
2026/09/01 -- Suchan Seo
D-Trust reported a self-disclosed compliance incident involving its TLS issuance controls under CA/Browser Forum TLS Baseline Requirements Section 4.3.1.2. The company said its RA-side and CA-side pre-sign checks did not…
D-Trust self-reported that it had issued S/MIME certificates in violation of Section 4.3.1.2 of the S/MIME Baseline Requirements because required pre-sign linting was not implemented for specific S/MIME issuing CAs. The …
Microsoft PKI Services self-reported that its third-party code signing CPS missed its annual review/update deadline and failed to list four Issuing CAs. The company said it became aware of the issue on 2026-07-30 and tha…
This case is a third-party Certificate Problem Report about invalid subject stateOrProvinceName values in SSL.com certificates. SSL.com says a business-registry lookup tool used during organization validation auto-filled…
Certainly reported a self-discovered compliance incident involving missing audit log entries for certificates issued during planned capacity characterization testing on 2026-04-01 and 2026-04-02. The incident affected 5,…
Certainly reported a self-disclosed incident affecting its BR §2.2 test websites. Between 2026-08-01 and 2026-08-05, four of its six test websites presented Subscriber Certificates whose validity periods had expired. Cer…
SSL.com opened this case after receiving a third-party Certificate Problem Report about invalid combinations of countryName, stateOrProvinceName, and localityName attributes in four OV TLS certificates. SSL.com said it i…
Actalis is the subject of a third-party Certificate Problem Report about publicly trusted TLS server certificates that were issued with both serverAuth and clientAuth EKUs, contrary to Actalis’s CP/CPS commitment to use …
This case remains Certum’s self-disclosed incident about certificates containing incorrect geographic subject fields, beginning with an incorrect country value and extending to other address attributes such as state, loc…
2026/08/28 -- CCADB Support
GlobalSign reported a single TLS end-entity certificate incident involving a Unicode replacement character (U+FFFD) in the Subject distinguished name stateOrProvinceName field. The case was triggered by a third-party Cer…
eMudhra opened this bug to disclose a certificate incident after receiving two external Certificate Problem Reports about publicly trusted OV and EV TLS server certificates issued by emSign. The reports described invalid…
FNMT reported that two intermediate CA certificates issued on 2019-11-28 under the AC RAIZ FNMT-RCM hierarchy lacked the Extended Key Usage extension required by Mozilla Root Store Policy. The affected intermediates are …
Amazon Trust Services reported that its CP/CPS did not explicitly state adherence to the latest published version of the Chrome Root Program Policy and the CCADB Policy, as required by Chrome Root Program Policy v1.8 Sec…
This case concerns D-Trust’s incident report about four Intermediate CA certificate records in CCADB whose disclosed CRL URLs did not exactly match the CRL Distribution Point URLs encoded in corresponding certificates, c…
2026/08/27 -- 'Ben Wilson' via dev-security-policy@mozilla.org
This case concerns Disig’s TLS Subscriber Certificates and a mismatch between its published CP/CPS and its actual issuance practice for the keyUsage extension criticality flag. The issue was first reported by a third par…
Sectigo reported a misissued QWAC certificate after receiving a Certificate Problem Report on 2026-08-07. The issue was a mismatch between the organization’s French jurisdictionCountry information and the German country …
This case concerns an EV subscriber certificate, also described as a Qualified Web Authentication Certificate (QWAC), whose jurisdiction attributes did not match the underlying registration information. DigiCert said a c…
2026/08/27 -- Wayne
2026/08/27 -- 'Adriano Santoni' via dev-security-policy@mozilla.org
ACCV reported a TLS certificate compliance incident after the Chrome Root Program identified discrepancies between ACCV’s binding CP/CPS and publicly trusted server TLS certificates it had issued. ACCV confirmed two disc…
GlobalSign reported that it discovered, during an internal CCADB review, one SubCA certificate that had been created with the wrong CPS Policy OID. The affected certificate was DHL Global TLS CA I6, which contained `1.3.…
Sectigo opened this bug after a third-party support request reported an incorrect jurisdictionStateOrProvinceName value in an EV Code Signing certificate. Sectigo’s incident report says the validation team changed the ju…
SC-102 alternative: align EV domain validation reuse and validity with the Baseline Requirements (#669) ## Summary This is an alternative to #661. It lets the Baseline Requirements govern EV domain re-validation rather t…
2026/08/21 -- 'Ben Wilson' via CCADB Public
2026/08/21 -- Wayne
2026/08/21 -- CCADB Public
2026/08/21 -- 'Adriano Santoni' via dev-security-policy@mozilla.org
2026/08/18 -- 'Dimitris Zacharopoulos' via dev-security-policy@mozilla.org
2026/08/18 -- 'Dimitris Zacharopoulos' via dev-security-policy@mozilla.org
2026/08/18 -- Corey Bonnell
2026/08/18 -- Suchan Seo
2026/08/17 -- 'Aaron Gable' via dev-security-policy@mozilla.org
2026/08/13 -- 'Ben Wilson' via dev-security-policy@mozilla.org
2026/08/13 -- 'Ben Wilson' via dev-security-policy@mozilla.org
2026/08/13 -- 'Aaron Gable' via dev-security-policy@mozilla.org
Ten years ago, we printed one of the nerdiest t-shirts we’ve ever made. On the front was the entire PEM encoding of ISRG Root X1 in base64. Back then, it represented a future we were working toward. Today, that sam…
2026/08/10 -- Suchan Seo
Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the … Read more The post Update…
2026/08/10 -- 'Ben Wilson' via CCADB Public
2026/08/09 -- 'Ben Wilson' via dev-security-policy@mozilla.org
SC-101v2: Clarify Authorization Domain Names (#627) BRs v2.2.9 Simplify the definition of ADN and move the algorithm in 3.2.2.4. Choosing an ADN is a precursor to doing validation. Every validation operates on an ADN. Si…
2026/07/31 -- CCADB Support
2026/07/31 -- CCADB Support
Ballot SMC017v2: Increase Minimum RSA CA Key Size (#304) * Version * Revisions table * Change to 6.1.5 * Cease date * minor typo * Update to compliance table * Change "and" to "or" * clarity of shall …
2026/07/28 -- CCADB Support
2026/07/28 -- 'Luis Osses' via dev-security-policy@mozilla.org
2026/07/27 -- 'Rob Stradling' via dev-security-policy@mozilla.org
2026/07/24 -- 'Cynthia Revström' via dev-security-policy
2026/07/23 -- 'Arman Asemani' via CCADB Public
2026/07/13 -- Corey Bonnell
2026/07/09 -- CCADB Support
SC087 - Registration Number Improvement for EV Certificates Copy file from https://raw.githubusercontent.com/cabforum/servercert/eb3b17de700b7aae63299e576adb8f00f6a5e41a/docs/EVG.md to new branch Voted on 2026-06-03 Fini…
2026/07/01 -- 大野文彰(ONO Fumiaki)
2026/07/01 -- 'Ben Wilson' via CCADB Public
2026/06/30 -- 大野文彰(ONO Fumiaki)
Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … Read more …
2026/06/24 -- 'Dustin Hollenback' via CCADB Public
2026/06/18 -- 'Dustin Hollenback' via CCADB Public
Ballot CSC-32: Make a Reserved Policy OID mandatory in the CertificatePolicies extension for Subscriber certificates (#57) * Ballot CSC-32: Make a Reserved Policy OID mandatory in the CertificatePolicies extension for Su…
SC-098: Process RFC 8657 CAA Parameters (#567) Update 3.2.2.8 to require that CAs process CAA accounturi and validationmethod parameters defined in RFC 8657 Fixes https://github.com/cabforum/servercert/issues/353 -------…
2026/06/11 -- 'Chrome Root Program' via CCADB Public
2026/06/05 -- 'Ben Wilson' via CCADB Public
2026/06/05 -- 'Ben Wilson' via CCADB Public
Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web wit…
Ballot SC-099: Improve Recording of Validation Methods (#656) The current BRs contain the following text in Sections 3.2.2.4 and 3.2.2.5: > CAs SHALL maintain a record of which [domain/IP] validation method, including…
Ballot SMC016: Equivalence with Ballots SC096 and SC097 (#300)
Update effective date based on IPR Review closure (#664)
Have you ever needed to make sure your website has a broken certificate? While many tools exist to help run an HTTPS server with valid certificates, there aren’t tools to make sure your certificate is revoked or ex…
Cleanup 2025 (#628) BR 2.2.6, approved by ballot SC095v3
SMC015v2 - mDL Authentication of Individual Identity (#290) * Version * Revision table * References * Attribute collection * Validation of mDL * Numbering fix * Reference update * eIDAS reference * Update eIDAS link * Up…
Nick Silverman is a Senior Infrastructure Engineer on the Edge Infrastructure team at Shopify, where he maintains the systems that provision, renew, and publish SSL certificates for millions of merchants’ custom do…
This was also posted on EFF’s blog. As we announced earlier this year, Let’s Encrypt now issues IP address and six-day certificates to the general public. The Certbot team at the Electronic Frontier Foundatio…
Ballot SC-097 (V1): "Sunset all remaining use of SHA-1 signatures in Certificates and CRLs" (#645) **Purpose of Ballot SC-097:** This ballot proposes updates to the Baseline Requirements for the Issuance and Ma…
As previously announced, over the next two years we will be switching the default certificate lifetime from 90 days to 64 days, and then 45 days. This will ultimately double the number of certificate renewal requests eac…
When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who prefer not to …
Ballot SC-96: Carve-out for DNSSEC verification logging requirements (#641) BRs 2.2.4
SC94: Add partial exception for DNSSEC checks for email DCV methods (#637) BRs version 2.2.3
Update build-guidelines-action to version 2.2.1 (#299) * Update build-guidelines-action to version 2.2.1 * Update action to use Docker image for build guidelines
In a recent conversation with a Let’s Encrypt subscriber, we asked them to guess how many people work at ISRG, the nonprofit behind Let’s Encrypt (and Prossimo and Divvi Up). Their guess was about 100; they&r…
Update: March 11, 2026 If you use Certbot, see Six-Day and IP Address Certificates Available in Certbot for details on requesting these certificates. Short-lived and IP address certificates are now generally available fr…
SC-090: "Gradually sunset all remaining email-based, phone-based, and ‘crossover’ validation methods from Sections 3.2.2.4 and 3.2.2.5" (#616) BRs v2.2.2 **Notes:** - As of 09 September 2025, this proposal is *…
This letter was originally published in our 2025 Annual Report. This year was the 10th anniversary of Let’s Encrypt. We’ve come a long way! Today we’re serving more than 700 million websites, issuing te…
Ballot SC-91: Sunset 3.2.2.5.3 Reverse Address Lookup Validation, proposal of new DNS-based validation using Persistent DCV TXT Record for IP addresses (#626) BRs v 2.2.1 ## Ballot SC-91: “Sunset 3.2.2.5.3 Reverse Addres…
SC-86: Sunset the Inclusion of Domain Names with an IP Reverse Zone Suffix (#573) BRs 2.2.0
On September 14, 2015, our first publicly-trusted certificate went live. We were proud that we had issued a certificate that a significant majority of clients could accept, and had done it using automated software. Of co…
Let’s Encrypt will be reducing the validity period of the certificates we issue. We currently issue certificates valid for 90 days, which will be cut in half to 45 days by 2028. This change is being made along with the r…
In a ceremony held in September, Let’s Encrypt generated two new Root Certification Authorities (CAs) and six new Intermediate CAs, which we’re collectively calling the “Generation Y” hierarchy. Now we’re moving to begin…
CSC-31: Maximum Validity Reduction (#48) (#51) * CSC-31: Maximum Validity Reduction (#48) * Update CSBR.md for proposed validity period change Updating to mostly match ian's original verbiage. However, given that we …
SC088v3: DNS TXT Record with Persistent Value DCV Method
SC092: Sunset use of Precertificate Signing CAs (#630) * Sunset precert signing cas (#629) * Update version and revision table * Fix formatting * fix formatting * Change order of effective dates in table 1.2.2. * One mor…
v1.0.12 - Ballot SMC014 (#285) The Intellectual Property Review (IPR) period for Ballot SMC014 (DNSSEC for CAA) has completed. No IPR Exclusion Notices were filed, and the ballot is adopted as of October 13, 2025.
Seth Schoen was an early contributor to Let's Encrypt through his work at the Electronic Frontier Foundation. He's also one of the longest standing participants in the Let's Encrypt community support forum, so we asked h…
Let’s Encrypt has been proud to work with the IETF to maintain ACME as an open standard since we first developed the technology a decade ago. We’re happy to announce that IETF has published our latest additio…
v1.0.11 - Ballot SMC013 (#284) This text introduces specifications for the use of two post-quantum cryptography (PQC) algorithms, as standardized by the U.S. National Institute of Standards and Technology (NIST), in the …
v1.0.10 - Ballot SMC012 (#282) This text introduces a new method for validation of mailbox control, using ACME for S/MIME as defined in RFC 8823: Extensions to Automatic Certificate Management Environment for End-User S/…
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature … Read more The post Firefox Security Response to pwn2o…
v1.0.9 - Ballot SMC011 (#272) * Date * Add EUID Definition * 7.1.4.2.2 (d) add note 4 * Appendix A.1 update * Minor * Revision table * Minor update to Definition * Reconfigure Note 4 * Minor format Note 4 * Minor format …
Bump Ubuntu runner to latest (#279)
The GPG key used to sign the Firefox release manifests is expiring soon, and so we’re going to be switching over to a new signing subkey shortly. The GPG fingerprint … Read more The post Updated GPG key for signing…
Mozilla remains committed to fostering a secure, agile, and transparent Web PKI ecosystem. The new Mozilla Root Store Policy (MRSP) v3.0, effective March 15, 2025, introduces critical updates to strengthen … Read m…
Ballot SMC010 - Introduction of Multi-Perspective Issuance Corroboration (#260) This ballot includes updates for the following: • Require pre-linting of leaf end entity Certificates starting September 15, 2025 • Require …
Ballot SMC09 - Pre-Linting, WebTrust for NetSec, and Minor Updates (#257)
Update upload-artifact to v4 due to github deprecation (#262)
At Mozilla, browser security is a critical mission, and part of that mission involves responding swiftly to new threats. Tuesday, around 8 AM Eastern time, we received a heads-up from … Read more The post Behind th…
Revert to commit 3a88910dd9ac43e3278514e8359778bfec4ad723 (#256)
Merge branch 'MPIC_discussion' into main
Update to 4.2.2.2 for effective dates
CSC-26 final adjustments (#40) * CSC-26 final adjustments * Fix links
CSC-26: Timestamping Private Key Protection (#34) * Timestamp Certificate, SubCA and Key restrictions * Add log and witness requirements for key destruction * Add effective dates * Typo correction * Align date format * U…
CSC-25: Import EV Guidelines to CS Baseline Requirements (#38) * First import of EV Guidelines version 1.8.0 * Added organizationIdentifier and extension. Added EVG definitions all the way up to the term "Registered…
Most of the web already supports HTTPS: In fact, 93% of requests made by Firefox are already HTTPS. As a reminder, HTTP over TLS (HTTPS) fixes the security shortcoming of HTTP … Read more The post Firefox will upgr…
At Mozilla, we believe in an open web that is safe to use. To that end, we improve and maintain the security of people using Firefox around the world. This … Read more The post Rapidly Leveling up Firefox Security …
CSC-22: High risk changes (#31) * Restore EV guidelines version reference * Capitalize "MUST NOT" (#19) * Assign ballot number, fix ballot name * High risk ballot draft language * Restore and tweak reference to…
CSC-21: Improved signing services requirements (#12) * Fix typos * Prepare final copy assuming IPR review is clean * Import of Word doc changes to Git * Clarify that SSs are not DTPs in 8.1 * Update may to MAY * Integrat…
Bump actions/upload-artifact from 3 to 4 (#32) Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 3 to 4. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](h…
CSC-20 (#30) * Restore EV guidelines version reference * Capitalize "MUST NOT" (#19) * Assign ballot number, fix ballot name * Add effective date
To provide transparency into our ongoing efforts to protect your privacy and security on the Internet, we are releasing a security audit of Mozilla VPN that Cure53 conducted earlier this … Read more The post Mozill…
Online security is constantly evolving, and thus we are excited to announce the publication of MRSP version 2.9, demonstrating that we are committed to keep up with the advancement of … Read more The post Version 2…
Bump tooling version, fix version table formatting (#28) * Bump tooling version * Fix table
No items for this source.