Remove Websites Trust Bit from SwissSign Gold CA - G2
Categories
(NSS :: CA Certificates Code, task)
Tracking
(nss 3.123)
| Tracking | Status | |
|---|---|---|
| nss | --- | 3.123 |
People
(Reporter: bwilson, Assigned: bwilson)
References
Details
Attachments
(1 file)
On or around 4/15/2026, remove the websites trust bit from the following root CA certificate:
CN=SwissSign Gold CA - G2; O=SwissSign AG; C=CH
Serial: 00BB401C43F55E4FB0
Sha1 Hash: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761
Sha2 Hash: 62DD0BE9B9F50A163EA0F8E75C053B1ECA57EA55C8688F647C6881F2C8357B95
| Assignee | ||
Comment 1•6 months ago
|
||
Current average daily validations (validations_on_day) for certificates under this Root CA is 197,340.
Comment 2•6 months ago
|
||
Dear Ben,
Thanks for this information.
Are we correct in interpreting this in the following way: Firefox is using the (longer) path via the cross-certificate to the old Gold root, even though the (shorter) path to the new TLS root is also valid?
Regards
Roman
| Assignee | ||
Comment 3•6 months ago
|
||
Hi Roman,
I believe that is correct. I'll see if I can find more information.
Ben
Comment 4•6 months ago
|
||
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/84a138e70475
Remove Websites Trust Bit from SwissSign Gold CA - G2 r=bwilson
Updated•5 months ago
|
Description
•