Closed Bug 2017471 Opened 7 months ago Closed 5 months ago

Remove Websites Trust Bit from SwissSign Gold CA - G2

Categories

(NSS :: CA Certificates Code, task)

Tracking

(nss 3.123)

RESOLVED FIXED
Tracking Status
nss --- 3.123

People

(Reporter: bwilson, Assigned: bwilson)

References

Details

Attachments

(1 file)

On or around 4/15/2026, remove the websites trust bit from the following root CA certificate:

CN=SwissSign Gold CA - G2; O=SwissSign AG; C=CH
Serial: 00BB401C43F55E4FB0
Sha1 Hash: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761
Sha2 Hash: 62DD0BE9B9F50A163EA0F8E75C053B1ECA57EA55C8688F647C6881F2C8357B95

Blocks: 2017317

Current average daily validations (validations_on_day) for certificates under this Root CA is 197,340.

Dear Ben,
Thanks for this information.
Are we correct in interpreting this in the following way: Firefox is using the (longer) path via the cross-certificate to the old Gold root, even though the (shorter) path to the new TLS root is also valid?

Regards
Roman

Hi Roman,
I believe that is correct. I'll see if I can find more information.
Ben

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/84a138e70475
Remove Websites Trust Bit from SwissSign Gold CA - G2 r=bwilson

Status: ASSIGNED → RESOLVED
Closed: 5 months ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: