Closed Bug 1939086 Opened 1 year ago Closed 11 months ago

Remove the S/MIME Trust Bit from the Security Communication ECC RootCA1 root cert

Categories

(NSS :: CA Certificates Code, enhancement)

enhancement

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: cainfo, Assigned: djackson)

References

Details

(Whiteboard: Removed email trust bit in NSS 3.108 and FF 136)

Attachments

(1 file)

No description provided.
  1. Subject/Issuer field values in the root certificate to be changed
    Issuer: C=JP, O=SECOM Trust Systems CO.,LTD., CN=Security Communication ECC RootCA1
    Subject: C=JP, O=SECOM Trust Systems CO.,LTD., CN=Security Communication ECC RootCA1
  2. SHA256 Fingerprint of the certificate to be changed
    E74FBDA55BD564C473A36B441AA799C8A68E077440E8288B9FA1E50E4BBACA11
    https://crt.sh/?q=E74FBDA55BD564C473A36B441AA799C8A68E077440E8288B9FA1E50E4BBACA11
  3. Specify the change to be made
    Security Communication ECC RootCA1 is a Root CA specifically for TLS Servers CAs.
    Therefore, please disable only the Trust bit for "Secure Email."
  4. Reason for requesting this change
    During the construction phase of Security Communication ECC RootCA1, we considered it as a multi-purpose Root CA.
    However, it is now a Root CA dedicated solely to TLS server certificates.
    Since we do not plan to construct any subordinate S/MIME CAs in the future, please disable the Trust bit for "Secure Email."
  5. Impact that the change may have on Mozilla users
    There is no impact to Mozilla users.

Best Regards,

ONO, Fumiaki
SECOM Trust Systems Co., Ltd.

Assignee: nobody → bwilson
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(bwilson)
Depends on: 1938250

For this CA,
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_TRUSTED_DELEGATOR needs to be changed to:
CKA_TRUST_EMAIL_PROTECTION CK_TRUST CKT_NSS_MUST_VERIFY_TRUST
Thanks,
Ben

Flags: needinfo?(bwilson)
Assignee: bwilson → djackson
Status: ASSIGNED → RESOLVED
Closed: 11 months ago
Resolution: --- → FIXED
Whiteboard: Removed email trust bit in NSS 3.108 and FF 136
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: