Closed Bug 1905072 Opened 2 years ago Closed 2 years ago

Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert

Categories

(CA Program :: CA Certificate Root Program, task)

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: gabriel.petcu, Assigned: bwilson)

Details

Steps to reproduce:
A CCADB report on Intermediate Certificates with Failed ALV Results presented a set of certSIGN CAs with missing S/MIME BR audit.
certSIGN would like to fix this problem.

Actual results:
certSIGN would like to remove the Trust Bit “Secure Email” for the following root CA:
certSIGN ROOT CA G2 with SHA256 Fingerprint: 657CFE2FA73FAA38462571F332A2363A46FCE7020951710702CDFBB6EEDA3305

The reason for this change:
certSIGN ROOT CA G2 was created on 6 Feb 2017 (will expire in 2042) with ALL Issuance policies.
certSIGN decided to migrate the Issuing CAs certSIGN Public CA and certSIGN Qualified CA – that were issuing only signature certificates – and to keep this PKI System only for TLS certificates, issued with certSIGN Web CA.
From the beginning of 2024 certSIGN is not issuing anymore with the certSIGN Public CA and certSIGN Qualified CA and these CAs are within their end-of-life cycle.
The Secure Email trust bit is only inherited from the Root as a derived bit, so certSIGN is asking for the removal of this bit from Apple and Microsoft ROOT Store Programs.

Expected results:
There is no impact on Mozilla users.
There is no urgency on this change, except of the Intermediate Certificates with Failed ALV fix.

Assignee: nobody → bwilson
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Flags: needinfo?(bwilson)
Depends on: 1908009
Flags: needinfo?(bwilson)
No longer depends on: 1908009

Closing this because the certSIGN ROOT CA G2 only has the websites bit enabled (and doesn't have the email trust bit enabled).

Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.