Closed Bug 2032939 Opened 10 days ago Closed 15 hours ago

NETLOCK: Transition Plan for Mozilla Root Store Policy 7.5 by Deadline

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: kaluha.roland, Assigned: kaluha.roland)

Details

(Whiteboard: [ca-compliance] [policy-failure])

Preliminary Incident Report

Summary

  • Incident description:
    The NETLOCK Arany (Gold) Class Root CA certificate currently includes both TLS server authentication and S/MIME email protection trust bits. According to Mozilla Root Store Policy Section 7.5, Certification Authorities must transition away from combined trust bits, with a compliance deadline of December 31, 2028.

    However, the affected root CA certificate has a validity end date of December 6, 2028, which is prior to the stated compliance deadline. This creates ambiguity regarding whether active remediation steps (such as trust bit separation or root replacement) are required, or whether natural expiration of the root certificate satisfies the policy requirements.

    This situation introduces a potential policy interpretation and compliance risk.

  • Relevant policies:

    • Mozilla Root Store Policy – Section 7.5 (Separation of TLS and S/MIME trust bits)
    • Mozilla Root Store Policy – General compliance requirements and timelines
  • Source of incident disclosure:
    The issue was identified internally following Mozilla’s public communication regarding the Section 7.5 transition plan deadline of April 15.

Assignee: nobody → kaluha.roland
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Summary: NETLOCK did not submit Transition Plan for Mozilla Root Store Policy 7.5 by Deadline → NETLOCK: Transition Plan for Mozilla Root Store Policy 7.5 by Deadline
Whiteboard: [ca-compliance] [policy-failure]

See bug #2033033, which I believe satisfies as a Transition Plan. Netlock still needs to prepare a full incident report.

Dear Community Members,

please proceed with closing this ticket.

The issue will be further handled under ticket #2033033. We will upload the full incident report there shortly.

This ticket will be set to be closed on or about 2026-04-27.

Whiteboard: [ca-compliance] [policy-failure] → [close on 2026-04-27] [ca-compliance] [policy-failure]
Status: ASSIGNED → RESOLVED
Closed: 15 hours ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-04-27] [ca-compliance] [policy-failure] → [ca-compliance] [policy-failure]
You need to log in before you can comment on or make changes to this bug.