Open Bug 2018979 Opened 6 months ago Updated 2 months ago

eMudhra: Transition Plan for Existing Dual-Purpose Roots

Categories

(CA Program :: CA Certificate Root Program, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: bwilson, Assigned: bwilson)

Details

(Whiteboard: [transition-plan])

This bug is opened to track eMudhra’s transition of dual-purpose root certificates in accordance with MRSP §7.5.3.

Background

eMudhra has indicated that it is migrating away from multi-purpose PKI hierarchies and has submitted new purpose-dedicated root certificates for inclusion (Bug #1889859; CCADB Case 00001777).

While those inclusion requests are under review, compliance with MRSP §7.5.3 requires the eventual removal of one trust bit (Websites or Email) from each dual-purpose root currently included in NSS.

The following root CA certificates are enabled with both the websites and email trust bits:

  • emSign ECC Root CA - C3
  • emSign ECC Root CA - G3
  • emSign Root CA - C1
  • emSign Root CA - G1

Summary of eMudhra's Stated Transition Plan

  • TLS issuance migration completed: All new TLS server certificate issuance has transitioned to dedicated TLS-only hierarchies. Legacy dual-purpose hierarchies are no longer used for new TLS issuance.
  • New purpose-built roots submitted: eMudhra has submitted TLS-dedicated root certificates (Bug 1889859; CCADB Case 00001777) to support operational separation of trust functions.
  • Cessation of non-TLS issuance under dual-use roots (target: March 2026): Issuance of S/MIME and other non-TLS certificates from roots currently enabled for both TLS and Email trust will cease.
  • Decommissioning of legacy subordinate CAs (target: June 15, 2026): Subordinate CAs chaining to dual-use roots for non-TLS purposes will be retired and revoked.
  • Deployment of dedicated non-TLS hierarchies (2026 onward): Replacement S/MIME (and related) hierarchies are being deployed using new key material and separated PKI structures.
  • Completion of trust separation: After migration, affected roots are intended to function solely in their designated role, with S/MIME services fully transitioned to distinct hierarchies.

This tracking bug is intended to coordinate and document the §7.5.3 transitions independently of the inclusion review timeline.

For each affected root, could eMudhra please provide the estimated date after which no new issuance will occur for the trust purpose being retired and a proposed date for Mozilla to either remove the corresponding trust bit or configure a distrust-after date? (For S/MIME, the "distrust-after" date applies to the issuance date of end-entity certificates and is enforced by checking the certificate’s notBefore value. For TLS, the "distrust-after" date applies to the issuance date of end-entity certificates and is enforced by checking the certificate’s notBefore value and also by rejecting SCT timestamps after the date.)

Thank you for opening this tracking bug and for the clear summary of the §7.5.3 obligations. We are committed to completing the trust separation in a timely and orderly manner.
Below, we provide the requested details for each affected root certificate — specifically, the last issuance date for the trust purpose being retired (Email/S/MIME) and our proposed distrust-after date for Mozilla to enforce.

  1. emSign Root CA - G1 (CN=emSign Root CA - G1, OU=emSign PKI, O=eMudhra Technologies Limited, C=IN)
  • Last S/MIME / non-TLS issuance date: March 31, 2026
  • Proposed Email trust bit distrust-after date (notBefore-based): To adhere to TLS-specific root requirements, we are revoking the non-TLS issuing CAs under this root by June 15, 2026. Since our purpose-based TLS root is cross-signed by emSign Root CA - G1, we request that Mozilla retain the trust bit for emSign Root CA - G1 in the Mozilla Root Store.
  • All subordinate CAs under this root used for non-TLS purposes will be revoked by June 15, 2026
  1. emSign ECC Root CA - G3 (CN=emSign ECC Root CA - G3, OU=emSign PKI, O=eMudhra Technologies Limited, C=IN)
  • Last S/MIME / non-TLS issuance date: March 31, 2026
  • Proposed Email trust bit distrust-after date (notBefore-based): To adhere to TLS-specific root requirements, we are revoking the non-TLS issuing CAs under this root by June 15, 2026. Since our purpose-based TLS root is cross-signed by emSign ECC Root CA - G3, we request that Mozilla retain the trust bit for emSign ECC Root CA - G3 in the Mozilla Root Store.
  • All subordinate CAs under this root used for non-TLS purposes will be revoked by June 15, 2026
  1. emSign Root CA - C1 (CN=emSign Root CA - C1, OU=emSign PKI, O=eMudhra Inc, C=US)
  • Proposed Email and TLS trust bit distrust-after date (notBefore-based): June 15, 2026
  • This Root Certificate may be distrusted from the Mozilla Root Store Program.
  1. emSign ECC Root CA - C3 (CN=emSign ECC Root CA - C3, OU=emSign PKI, O=eMudhra Inc, C=US)
  • Proposed Email and TLS trust bit distrust-after date (notBefore-based): June 15, 2026
  • This Root Certificate may be distrusted from the Mozilla Root Store Program.

We will continue to provide updates in this bug as milestones are completed. Please let us know if additional information or clarification is needed.

Hi Ben,
As per the transition plan outlined in this bug and in compliance with MRSP §7.5.3, we confirm that the revocation of all Non-TLS (S/MIME, Client Auth, Code Signing, Timestamping, and Device) subordinate CA certificates chaining to the multi-purpose roots (emSign Root CA - G1 and emSign ECC Root CA - G3) has been completed as of June 15, 2026.

Subject CN Issuing CA Name Serial Number (HEX) Revoked Date of Revocation Reason for Revocation SHA-Value
emSign Class 1 CA - G1 emSign Root CA - G1 00D59B7C9B36A2D44922EA Yes 2026-06-14 13:32:05 Cessation of Operation (5) CF:6D:03:33:D0:BE:2C:69:A4:2D:45:39:60:DE:E9:E1:09:D9:E8:84:3E:A3:06:1A:16:71:D6:EA:F8:5E:B7:D8
emSign Root SMIME CA - G3 emSign ECC Root CA - G3 00B33EBCAC96AC83A823E2786D76B6D8 Yes 2026-06-14 13:29:56 Cessation of Operation (5) B4:CE:EB:A4:8E:F8:CC:C6:09:0F:6D:2A:62:A8:5D:BB:51:C5:A1:06:A7:DC:7E:C5:40:82:70:02:0F:91:C2:22
emSign Root Client Auth CA - G3 emSign ECC Root CA - G3 50243F8B6EE1D97C789089421ED2FD Yes 2026-06-14 13:28:13 Cessation of Operation (5) 63:08:85:38:02:8E:23:3C:61:B5:4C:5A:42:38:B7:C7:53:C0:4F:32:36:2F:1C:95:A4:28:D2:8E:9C:B6:B1:5E
emSign Root CS CA - G3 emSign ECC Root CA - G3 14C6754E93E5D94C638D3FC90FAD76 Yes 2026-06-14 13:26:53 Cessation of Operation (5) 71:37:FA:71:AD:46:BA:68:6F:74:6D:10:14:AC:57:E8:E6:C6:E9:AF:4A:A2:F7:3C:0C:44:A5:CF:27:DE:BB:59
emSign Root TSA CA - G3 emSign ECC Root CA - G3 7629AFFB27C4349E7218CE483DB54B Yes 2026-06-14 13:25:09 Cessation of Operation (5) 87:3B:E6:F9:EF:30:57:22:19:28:E8:40:68:6E:2D:18:21:1A:26:80:AE:07:05:11:48:C1:1A:29:D4:1B:A9:8F
emSign ECC Device CA - G3 emSign ECC Root CA - G3 00876282A8FD758C391EC3 Yes 2026-06-14 13:23:15 Cessation of Operation (5) 70:B9:BA:59:54:12:CF:86:14:B7:67:47:FD:68:3C:CA:27:59:F4:26:42:16:48:34:FB:EF:DD:88:50:5C:4F:1C
emSign ECC SMIME CA - G3 emSign ECC Root CA - G3 0E906BB2267EC0FF Yes 2026-06-14 13:21:52 Cessation of Operation (5) F5:B3:E9:14:CD:E2:95:4F:65:46:4F:A8:E9:D6:9F:04:92:62:2B:3C:2A:C2:43:98:7B:11:CB:BF:1B:45:13:07
emSign ECC Class 2 CA - G3 emSign ECC Root CA - G3 23E1BA02DFF3E900EDDD Yes 2026-06-14 13:20:15 Cessation of Operation (5) 4E:9B:73:15:67:17:7E:17:76:A9:6D:66:D9:12:0B:3D:EB:28:B8:00:93:7E:A4:66:25:65:B3:EF:5E:C8:00:0B
emSign ECC Class 3 CA - G3 emSign ECC Root CA - G3 00B8EB258324DB08ACC2F5 Yes 2026-06-14 13:18:27 Cessation of Operation (5) 70:66:A0:F4:2F:53:0E:0D:B5:AF:EE:72:A3:B0:4D:E6:14:E7:D2:30:5C:67:D1:2C:75:6B:B2:15:E3:7C:B9:75
emSign ECC Time Stamping CA - G3 emSign ECC Root CA - G3 0084A863D6F61818464D34 Yes 2026-06-15 17:43:21 Cessation of Operation (5) C4:22:AB:86:C1:72:9E:88:9F:BC:AF:5C:D7:3F:21:7E:03:C2:9F:E2:AC:50:21:2F:45:13:07:D9:15:86:9F:47
emSign ECC Class 1 CA - G3 emSign ECC Root CA - G3 00FB1E21982EB1B55C5925 Yes 2026-06-14 13:13:42 Cessation of Operation (5) AB:A6:A6:5D:CE:89:55:BA:F0:68:5A:B8:88:09:B7:69:9C:17:44:96:EF:9E:E9:91:53:32:51:49:4F:43:CE:10
emSign ECC EV CS CA - G3 emSign ECC Root CA - G3 23BA23AB486AE7D5C0FE Yes 2026-06-14 13:12:07 Cessation of Operation (5) 0B:AD:A9:79:B7:14:02:FE:86:06:96:03:2C:F4:0E:9D:2A:3F:41:CC:B5:D0:3B:E3:3F:BB:94:A8:0D:7F:FC:7C
emSign ECC CS CA - G3 emSign ECC Root CA - G3 35CF922FB9008249F89C Yes 2026-06-14 13:08:56 Cessation of Operation (5) 0D:68:69:A2:B4:F5:DF:77:A6:AF:B0:34:22:5E:9B:EF:34:57:43:CF:30:6E:DF:36:EE:35:B9:D0:5A:FA:D8:9C
emSign Root SMIME CA - G1 emSign Root CA - G1 0091685541577A36E8AE09ADEBE4CFAF Yes 2026-06-14 13:07:07 Cessation of Operation (5) A6:51:60:E9:77:0D:70:D8:AC:E8:EC:36:70:A7:B4:EF:1F:87:F4:F5:07:B1:CE:3D:6F:C6:23:AD:ED:06:94:C1
emSign SMIME CA - G1 emSign Root CA - G1 00FE04E642637D4020947D6C5F4E0BD0 Yes 2026-06-14 13:05:16 Cessation of Operation (5) BA:9E:8A:1F:CC:41:54:B0:94:BE:73:40:35:EC:A7:E5:4E:9F:56:19:D5:11:B2:65:75:0E:EB:98:2E:2C:6D:06
emSign Root Client Auth CA - G1 emSign Root CA - G1 008B0DCB4D9A00ECC11B0677FC86BCC8 Yes 2026-06-14 13:02:38 Cessation of Operation (5) 6F:B7:51:90:47:74:05:C2:8A:FF:FE:25:33:8A:92:F4:97:39:56:ED:5B:1A:23:53:B2:4B:62:04:E0:4D:4C:F9
emSign Class 2 CA - G1 emSign Root CA - G1 3C5BDA55C0A236A744CD Yes 2026-06-15 17:07:56 Cessation of Operation (5) 63:A8:36:9D:C8:24:A4:2B:C7:AE:6E:E5:D2:6A:AF:D3:2D:F4:AF:67:7C:A1:8B:94:1B:7A:57:E3:3B:1E:35:59
emSign Class 3 CA - G1 emSign Root CA - G1 00A08870825A326BED9611 Yes 2026-06-15 17:53:29 Cessation of Operation (5) 42:DA:1C:56:2F:80:E4:6D:A7:A3:21:24:4E:FC:23:D0:FA:A9:FE:BB:B7:AA:03:77:D9:6B:42:D9:E8:8A:B2:00
emSign Device CA - G1 emSign Root CA - G1 0465835247364A904A8E Yes 2026-06-14 12:31:25 Cessation of Operation (5) 4C:91:98:B6:73:55:08:58:79:9A:D2:74:4C:C0:83:C1:BA:00:27:E7:7D:3B:8F:D6:D5:6C:F5:36:20:D0:99:E2
You need to log in before you can comment on or make changes to this bug.