eMudhra: Transition Plan for Existing Dual-Purpose Roots
Categories
(CA Program :: CA Certificate Root Program, task)
Tracking
(Not tracked)
People
(Reporter: bwilson, Assigned: bwilson)
Details
(Whiteboard: [transition-plan])
This bug is opened to track eMudhra’s transition of dual-purpose root certificates in accordance with MRSP §7.5.3.
Background
eMudhra has indicated that it is migrating away from multi-purpose PKI hierarchies and has submitted new purpose-dedicated root certificates for inclusion (Bug #1889859; CCADB Case 00001777).
While those inclusion requests are under review, compliance with MRSP §7.5.3 requires the eventual removal of one trust bit (Websites or Email) from each dual-purpose root currently included in NSS.
The following root CA certificates are enabled with both the websites and email trust bits:
- emSign ECC Root CA - C3
- emSign ECC Root CA - G3
- emSign Root CA - C1
- emSign Root CA - G1
Summary of eMudhra's Stated Transition Plan
- TLS issuance migration completed: All new TLS server certificate issuance has transitioned to dedicated TLS-only hierarchies. Legacy dual-purpose hierarchies are no longer used for new TLS issuance.
- New purpose-built roots submitted: eMudhra has submitted TLS-dedicated root certificates (Bug 1889859; CCADB Case 00001777) to support operational separation of trust functions.
- Cessation of non-TLS issuance under dual-use roots (target: March 2026): Issuance of S/MIME and other non-TLS certificates from roots currently enabled for both TLS and Email trust will cease.
- Decommissioning of legacy subordinate CAs (target: June 15, 2026): Subordinate CAs chaining to dual-use roots for non-TLS purposes will be retired and revoked.
- Deployment of dedicated non-TLS hierarchies (2026 onward): Replacement S/MIME (and related) hierarchies are being deployed using new key material and separated PKI structures.
- Completion of trust separation: After migration, affected roots are intended to function solely in their designated role, with S/MIME services fully transitioned to distinct hierarchies.
This tracking bug is intended to coordinate and document the §7.5.3 transitions independently of the inclusion review timeline.
For each affected root, could eMudhra please provide the estimated date after which no new issuance will occur for the trust purpose being retired and a proposed date for Mozilla to either remove the corresponding trust bit or configure a distrust-after date? (For S/MIME, the "distrust-after" date applies to the issuance date of end-entity certificates and is enforced by checking the certificate’s notBefore value. For TLS, the "distrust-after" date applies to the issuance date of end-entity certificates and is enforced by checking the certificate’s notBefore value and also by rejecting SCT timestamps after the date.)
Comment 1•4 months ago
|
||
Thank you for opening this tracking bug and for the clear summary of the §7.5.3 obligations. We are committed to completing the trust separation in a timely and orderly manner.
Below, we provide the requested details for each affected root certificate — specifically, the last issuance date for the trust purpose being retired (Email/S/MIME) and our proposed distrust-after date for Mozilla to enforce.
- emSign Root CA - G1 (CN=emSign Root CA - G1, OU=emSign PKI, O=eMudhra Technologies Limited, C=IN)
- Last S/MIME / non-TLS issuance date: March 31, 2026
- Proposed Email trust bit distrust-after date (notBefore-based): To adhere to TLS-specific root requirements, we are revoking the non-TLS issuing CAs under this root by June 15, 2026. Since our purpose-based TLS root is cross-signed by emSign Root CA - G1, we request that Mozilla retain the trust bit for emSign Root CA - G1 in the Mozilla Root Store.
- All subordinate CAs under this root used for non-TLS purposes will be revoked by June 15, 2026
- emSign ECC Root CA - G3 (CN=emSign ECC Root CA - G3, OU=emSign PKI, O=eMudhra Technologies Limited, C=IN)
- Last S/MIME / non-TLS issuance date: March 31, 2026
- Proposed Email trust bit distrust-after date (notBefore-based): To adhere to TLS-specific root requirements, we are revoking the non-TLS issuing CAs under this root by June 15, 2026. Since our purpose-based TLS root is cross-signed by emSign ECC Root CA - G3, we request that Mozilla retain the trust bit for emSign ECC Root CA - G3 in the Mozilla Root Store.
- All subordinate CAs under this root used for non-TLS purposes will be revoked by June 15, 2026
- emSign Root CA - C1 (CN=emSign Root CA - C1, OU=emSign PKI, O=eMudhra Inc, C=US)
- Proposed Email and TLS trust bit distrust-after date (notBefore-based): June 15, 2026
- This Root Certificate may be distrusted from the Mozilla Root Store Program.
- emSign ECC Root CA - C3 (CN=emSign ECC Root CA - C3, OU=emSign PKI, O=eMudhra Inc, C=US)
- Proposed Email and TLS trust bit distrust-after date (notBefore-based): June 15, 2026
- This Root Certificate may be distrusted from the Mozilla Root Store Program.
We will continue to provide updates in this bug as milestones are completed. Please let us know if additional information or clarification is needed.
Comment 2•2 months ago
|
||
Hi Ben,
As per the transition plan outlined in this bug and in compliance with MRSP §7.5.3, we confirm that the revocation of all Non-TLS (S/MIME, Client Auth, Code Signing, Timestamping, and Device) subordinate CA certificates chaining to the multi-purpose roots (emSign Root CA - G1 and emSign ECC Root CA - G3) has been completed as of June 15, 2026.
| Subject CN | Issuing CA Name | Serial Number (HEX) | Revoked | Date of Revocation | Reason for Revocation | SHA-Value |
|---|---|---|---|---|---|---|
| emSign Class 1 CA - G1 | emSign Root CA - G1 | 00D59B7C9B36A2D44922EA | Yes | 2026-06-14 13:32:05 | Cessation of Operation (5) | CF:6D:03:33:D0:BE:2C:69:A4:2D:45:39:60:DE:E9:E1:09:D9:E8:84:3E:A3:06:1A:16:71:D6:EA:F8:5E:B7:D8 |
| emSign Root SMIME CA - G3 | emSign ECC Root CA - G3 | 00B33EBCAC96AC83A823E2786D76B6D8 | Yes | 2026-06-14 13:29:56 | Cessation of Operation (5) | B4:CE:EB:A4:8E:F8:CC:C6:09:0F:6D:2A:62:A8:5D:BB:51:C5:A1:06:A7:DC:7E:C5:40:82:70:02:0F:91:C2:22 |
| emSign Root Client Auth CA - G3 | emSign ECC Root CA - G3 | 50243F8B6EE1D97C789089421ED2FD | Yes | 2026-06-14 13:28:13 | Cessation of Operation (5) | 63:08:85:38:02:8E:23:3C:61:B5:4C:5A:42:38:B7:C7:53:C0:4F:32:36:2F:1C:95:A4:28:D2:8E:9C:B6:B1:5E |
| emSign Root CS CA - G3 | emSign ECC Root CA - G3 | 14C6754E93E5D94C638D3FC90FAD76 | Yes | 2026-06-14 13:26:53 | Cessation of Operation (5) | 71:37:FA:71:AD:46:BA:68:6F:74:6D:10:14:AC:57:E8:E6:C6:E9:AF:4A:A2:F7:3C:0C:44:A5:CF:27:DE:BB:59 |
| emSign Root TSA CA - G3 | emSign ECC Root CA - G3 | 7629AFFB27C4349E7218CE483DB54B | Yes | 2026-06-14 13:25:09 | Cessation of Operation (5) | 87:3B:E6:F9:EF:30:57:22:19:28:E8:40:68:6E:2D:18:21:1A:26:80:AE:07:05:11:48:C1:1A:29:D4:1B:A9:8F |
| emSign ECC Device CA - G3 | emSign ECC Root CA - G3 | 00876282A8FD758C391EC3 | Yes | 2026-06-14 13:23:15 | Cessation of Operation (5) | 70:B9:BA:59:54:12:CF:86:14:B7:67:47:FD:68:3C:CA:27:59:F4:26:42:16:48:34:FB:EF:DD:88:50:5C:4F:1C |
| emSign ECC SMIME CA - G3 | emSign ECC Root CA - G3 | 0E906BB2267EC0FF | Yes | 2026-06-14 13:21:52 | Cessation of Operation (5) | F5:B3:E9:14:CD:E2:95:4F:65:46:4F:A8:E9:D6:9F:04:92:62:2B:3C:2A:C2:43:98:7B:11:CB:BF:1B:45:13:07 |
| emSign ECC Class 2 CA - G3 | emSign ECC Root CA - G3 | 23E1BA02DFF3E900EDDD | Yes | 2026-06-14 13:20:15 | Cessation of Operation (5) | 4E:9B:73:15:67:17:7E:17:76:A9:6D:66:D9:12:0B:3D:EB:28:B8:00:93:7E:A4:66:25:65:B3:EF:5E:C8:00:0B |
| emSign ECC Class 3 CA - G3 | emSign ECC Root CA - G3 | 00B8EB258324DB08ACC2F5 | Yes | 2026-06-14 13:18:27 | Cessation of Operation (5) | 70:66:A0:F4:2F:53:0E:0D:B5:AF:EE:72:A3:B0:4D:E6:14:E7:D2:30:5C:67:D1:2C:75:6B:B2:15:E3:7C:B9:75 |
| emSign ECC Time Stamping CA - G3 | emSign ECC Root CA - G3 | 0084A863D6F61818464D34 | Yes | 2026-06-15 17:43:21 | Cessation of Operation (5) | C4:22:AB:86:C1:72:9E:88:9F:BC:AF:5C:D7:3F:21:7E:03:C2:9F:E2:AC:50:21:2F:45:13:07:D9:15:86:9F:47 |
| emSign ECC Class 1 CA - G3 | emSign ECC Root CA - G3 | 00FB1E21982EB1B55C5925 | Yes | 2026-06-14 13:13:42 | Cessation of Operation (5) | AB:A6:A6:5D:CE:89:55:BA:F0:68:5A:B8:88:09:B7:69:9C:17:44:96:EF:9E:E9:91:53:32:51:49:4F:43:CE:10 |
| emSign ECC EV CS CA - G3 | emSign ECC Root CA - G3 | 23BA23AB486AE7D5C0FE | Yes | 2026-06-14 13:12:07 | Cessation of Operation (5) | 0B:AD:A9:79:B7:14:02:FE:86:06:96:03:2C:F4:0E:9D:2A:3F:41:CC:B5:D0:3B:E3:3F:BB:94:A8:0D:7F:FC:7C |
| emSign ECC CS CA - G3 | emSign ECC Root CA - G3 | 35CF922FB9008249F89C | Yes | 2026-06-14 13:08:56 | Cessation of Operation (5) | 0D:68:69:A2:B4:F5:DF:77:A6:AF:B0:34:22:5E:9B:EF:34:57:43:CF:30:6E:DF:36:EE:35:B9:D0:5A:FA:D8:9C |
| emSign Root SMIME CA - G1 | emSign Root CA - G1 | 0091685541577A36E8AE09ADEBE4CFAF | Yes | 2026-06-14 13:07:07 | Cessation of Operation (5) | A6:51:60:E9:77:0D:70:D8:AC:E8:EC:36:70:A7:B4:EF:1F:87:F4:F5:07:B1:CE:3D:6F:C6:23:AD:ED:06:94:C1 |
| emSign SMIME CA - G1 | emSign Root CA - G1 | 00FE04E642637D4020947D6C5F4E0BD0 | Yes | 2026-06-14 13:05:16 | Cessation of Operation (5) | BA:9E:8A:1F:CC:41:54:B0:94:BE:73:40:35:EC:A7:E5:4E:9F:56:19:D5:11:B2:65:75:0E:EB:98:2E:2C:6D:06 |
| emSign Root Client Auth CA - G1 | emSign Root CA - G1 | 008B0DCB4D9A00ECC11B0677FC86BCC8 | Yes | 2026-06-14 13:02:38 | Cessation of Operation (5) | 6F:B7:51:90:47:74:05:C2:8A:FF:FE:25:33:8A:92:F4:97:39:56:ED:5B:1A:23:53:B2:4B:62:04:E0:4D:4C:F9 |
| emSign Class 2 CA - G1 | emSign Root CA - G1 | 3C5BDA55C0A236A744CD | Yes | 2026-06-15 17:07:56 | Cessation of Operation (5) | 63:A8:36:9D:C8:24:A4:2B:C7:AE:6E:E5:D2:6A:AF:D3:2D:F4:AF:67:7C:A1:8B:94:1B:7A:57:E3:3B:1E:35:59 |
| emSign Class 3 CA - G1 | emSign Root CA - G1 | 00A08870825A326BED9611 | Yes | 2026-06-15 17:53:29 | Cessation of Operation (5) | 42:DA:1C:56:2F:80:E4:6D:A7:A3:21:24:4E:FC:23:D0:FA:A9:FE:BB:B7:AA:03:77:D9:6B:42:D9:E8:8A:B2:00 |
| emSign Device CA - G1 | emSign Root CA - G1 | 0465835247364A904A8E | Yes | 2026-06-14 12:31:25 | Cessation of Operation (5) | 4C:91:98:B6:73:55:08:58:79:9A:D2:74:4C:C0:83:C1:BA:00:27:E7:7D:3B:8F:D6:D5:6C:F5:36:20:D0:99:E2 |
Description
•