Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
Categories
(CA Program :: CA Certificate Root Program, task)
Tracking
(Not tracked)
People
(Reporter: gabriel.petcu, Assigned: bwilson)
Details
Steps to reproduce:
A CCADB report on Intermediate Certificates with Failed ALV Results presented a set of certSIGN CAs with missing S/MIME BR audit.
certSIGN would like to fix this problem.
Actual results:
certSIGN would like to remove the Trust Bit “Secure Email” for the following root CA:
certSIGN ROOT CA G2 with SHA256 Fingerprint: 657CFE2FA73FAA38462571F332A2363A46FCE7020951710702CDFBB6EEDA3305
The reason for this change:
certSIGN ROOT CA G2 was created on 6 Feb 2017 (will expire in 2042) with ALL Issuance policies.
certSIGN decided to migrate the Issuing CAs certSIGN Public CA and certSIGN Qualified CA – that were issuing only signature certificates – and to keep this PKI System only for TLS certificates, issued with certSIGN Web CA.
From the beginning of 2024 certSIGN is not issuing anymore with the certSIGN Public CA and certSIGN Qualified CA and these CAs are within their end-of-life cycle.
The Secure Email trust bit is only inherited from the Root as a derived bit, so certSIGN is asking for the removal of this bit from Apple and Microsoft ROOT Store Programs.
Expected results:
There is no impact on Mozilla users.
There is no urgency on this change, except of the Intermediate Certificates with Failed ALV fix.
| Assignee | ||
Updated•2 years ago
|
| Assignee | ||
Comment 1•2 years ago
|
||
Closing this because the certSIGN ROOT CA G2 only has the websites bit enabled (and doesn't have the email trust bit enabled).
Description
•