Open Bug 2017182 Opened 5 months ago Updated 3 months ago

Sectigo: Transition Plan for Existing Dual-Purpose Roots

Categories

(CA Program :: CA Certificate Root Program, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: rob, Assigned: bwilson)

References

Details

(Whiteboard: [transition-plan])

Pursuant to section 7.5.3 of the Mozilla Root Store Policy, here is Sectigo's transition plan to migrate our dual-purpose roots to S/MIME-only before 2029.

Per Mozilla's Root CA Lifecycle Transition Schedule, all but one of our existing dual-purpose roots are already due to lose the Websites trust bit before 2029 due to the age of their Key Generation Dates:

Root Certificate Websites Trust Bit Removal Email Trust Bit Removal
COMODO Certification Authority Due 2026-04-15 Due 2029-04-15
COMODO ECC Certification Authority Due 2027-04-15 Due 2030-04-15
COMODO RSA Certification Authority Due 2027-04-15 Due 2030-04-15
USERTrust RSA Certification Authority Due 2027-04-15 Due 2030-04-15
USERTrust ECC Certification Authority Due 2027-04-15 Due 2030-04-15
Entrust Root Certification Authority - G2 Due 2027-04-15 Due 2030-04-15
Entrust Root Certification Authority - EC1 Due 2029-04-15 Due 2032-04-15

Before ownership was transferred to Sectigo, those two Entrust roots were distrusted for Server certificates where notBefore>=2024-11-30. Since more than 398 days have elapsed since that distrust date, it is safe to assume that there are now zero Subscriber certificates relying on the Websites trust bit for those two Entrust roots in Firefox.

Ben, please remove the Websites trust bit from the Entrust G2 and EC1 roots at your earliest convenience.

Note: Whilst we intend all of these Root CAs to become trusted for S/MIME only within the Mozilla Root Store according to the timeline laid out above, this should not be interpreted as a commitment to completely stop issuance of Server certificates under these hierarchies. Any such issuance remains at the discretion of Sectigo.

Flags: needinfo?(bwilson)

Thank you for providing Sectigo’s transition plan pursuant to section 7.5.3 of the Mozilla Root Store Policy.

We acknowledge receipt of Sectigo's plan and its alignment with Mozilla's Root CA Lifecycle Transition Schedules.

In response, we will proceed with an NSS bug to remove the Websites trust bit for the following three root CA certificates:

  • COMODO Certification Authority
  • Entrust Root Certification Authority – G2
  • Entrust Root Certification Authority – EC1

The removal of the Websites trust bit for these roots will result in their transition to S/MIME-only trust.

Further trust bit removals for the remaining dual-purpose roots will be handled according to the schedule published in Comment #0.

Assignee: nobody → bwilson
Status: NEW → ASSIGNED
Flags: needinfo?(bwilson)
Whiteboard: [transition-plan]
See Also: → 2017345
See Also: → 2017348

In NSS 3.123 and Firefox 151, the websites trust bit was removed from the following three root CA certificates:

  • COMODO Certification Authority
  • Entrust Root Certification Authority – G2
  • Entrust Root Certification Authority – EC1

CCADB records have been updated accordingly.

You need to log in before you can comment on or make changes to this bug.