Certigna: Transition Plan for Existing Dual-Purpose Root
Categories
(CA Program :: CA Certificate Root Program, task)
Tracking
(Not tracked)
People
(Reporter: bwilson, Assigned: bwilson)
Details
(Whiteboard: [transition-plan])
For the Certigna CA expiring in 2027:
-
TLS: The CA will no longer issue publicly recognized TLS end-user certificates after June 15, 2026, with certificates valid for 90 days (expiring no later than September 15, 2026). The TLS bit may be removed from this CA as of September 15, 2026.
-
SMIME: The CA no longer issues SMIME certificates and is replaced by the “Certigna Root CA” root CA in accordance with previous discussions regarding the removal of the “Certigna” root CA. The SMIME bit may now be removed for this root CA.
For the “Certigna Root CA”, which will expire in 2033:
-
TLS: The CA will no longer issue publicly recognized TLS end-user certificates after June 15, 2026, with certificates valid for 90 days (expiring no later than September 15, 2026). The TLS bit may be removed from this root CA as of September 15, 2026.
-
SMIME: The CA issues SMIME certificates, and our “Certigna Email Protection Root CA” and “Certigna Email Protection EU Root CA” authorities will be submitted for integration in 2026, unless a decision is made to cease issuing publicly recognized SMIME certificates.
Description
•