CA/Root CA Lifecycles: Difference between revisions

From MozillaWiki
< CA
Jump to navigation Jump to search
(Add Table of Distrusted CAs)
(→‎2027 Websites Trust Bit Removals: Added some Sectigo CAs)
 
(5 intermediate revisions by the same user not shown)
Line 41: Line 41:
CA operators are strongly urged to apply to Mozilla for inclusion of their next generation root certificate at least 2 years before the distrust date of the CA certificate they wish to replace.
CA operators are strongly urged to apply to Mozilla for inclusion of their next generation root certificate at least 2 years before the distrust date of the CA certificate they wish to replace.


== 2025 Webtrust Bit Removals ==
== 2027 Websites Trust Bit Removals ==


In accordance with the schedule above, and Bug #1937338 https://bugzilla.mozilla.org/show_bug.cgi?id=1937338, Mozilla will remove the websites trust bit for these eight (8) CAs on April 15, 2025:
In accordance with the schedule above, Mozilla will remove the websites trust bit for following Root CAs on April 15, 2027:
 
{| class="wikitable"
| '''Root Certification Authority'''
| '''SHA-256 Certificate Hash'''
|-
| COMODO ECC Certification Authority                       
| 1793927A0614549789ADCE2F8F34F7F0B66D0F3AE3A3B84D21EC15DBBA4FADC7
|-
| COMODO RSA Certification Authority
| 52F0E1C4E58EC629291B60317F074671B85D7EA80D5B07273463534B32B40234
|-
| USERTrust ECC Certification Authority
| 4FF460D54B9C86DABFBCFC5712E0400D2BED3FBC4D4FBDAA86E06ADCD2A9AD7A
|-
| USERTrust RSA Certification Authority
| E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD2
|-
| TWCA Root Certification Authority                       
| BFD88FE1101C41AE3E801BF8BE56350EE9BAD1A6B9BD515EDC5C6D5B8711AC44
|-
| T-TeleSec GlobalRoot Class 3                             
| FD73DAD31C644FF1B43BEF0CCDDA96710B9CD9875ECA7E31707AF3E96D522BBD
|-
| T-TeleSec GlobalRoot Class 2                             
| 91E2F5788D5810EBA7BA58737DE1548A8ECACD014598BC0B143E041B17052552
|-
| Certum Trusted Network CA                               
| 5C58468D55F58E497E743982D2B50010B6D165374ACF83A7D4A32DB768C4408E
|-
| FNMT-RCM - SHA256                                       
| EBC5570C29018C4D67B1AA127BAF12F703B4611EBC17B7DAB5573894179B93FA
|-
| NetLock Arany (Class Gold) Főtanúsítvány             
| 6C61DAC3A2DEF031506BE036D2A6FE401994FBD13DF9C8D466599274C446EC98
|-
| GlobalSign Root CA - R3                                 
| CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B
|-
| Autoridad de Certificacion Firmaprofesional CIF A62634068
| 04048028BF1F2864D48F9AD4D83294366A828856553F3B14303F90147F5D40EF
|-
| Security Communication RootCA2                           
| 513B2CECB810D4CDE5DD85391ADFC6C2DD60D87BB736D2B521484AA47A0EBEF6
|-
| Microsec e-Szigno Root CA 2009                           
| 3C5F81FEA5FAB82C64BFA2EAECAFCDE8E077FC8620A7CAE537163DF36EDBF378
|-
| Starfield Services Root Certificate Authority - G2       
| 568D6905A2C88708A4B3025190EDCFEDB1974A606A13C6E5290FCB2AE63EDAB5
|-
| Go Daddy Root Certificate Authority - G2                 
| 45140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA
|-
| Starfield Root Certificate Authority - G2               
| 2CE1CB0BF9D2F9E102993FBE215152C3B2DD0CABDE1C68E5319B839154DBB7F5
|-
| D-TRUST Root Class 3 CA 2 2009                           
| 49E7A442ACF0EA6287050054B52564B650E4F49E42E348D6AA38E039E957B1C1
|-
| D-TRUST Root Class 3 CA 2 EV 2009                       
| EEC5496B988CE98625B934092EEC2908BED0B0F316C2D4730C84EAF1F3D34881
|-
|}
 
== 2026 Websites Trust Bit Removals ==
 
The following websites trust bit removals occurred in 2026.


{| class="wikitable"
{| class="wikitable"
Line 49: Line 116:
| '''SHA 256 Hash'''
| '''SHA 256 Hash'''
|-
|-
| Baltimore CyberTrust Root (expires 5/12/2025)
| certSIGN ROOT CA
| 16AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB
| EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB
|-
| SwissSign Gold CA - G2
| 62DD0BE9B9F50A163EA0F8E75C053B1ECA57EA55C8688F647C6881F2C8357B95
|-
| Secure Global CA
| 4200F5043AC8590EBB527D209ED1503029FBCBD41CA1B506EC27F15ADE7DAC69
|-
| SecureTrust CA
| F1C1B50AE5A20DD8030EC9F6BC24823DD367B5255759B4E71B61FCE9F7375D73
|-
| DigiCert Assured ID Root CA
| 3E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C
|-
| DigiCert Global Root CA
| 4348A0E9444C78CB265E058D5E8944B4D84F9662BD26DB257F8934A443C70161
|-
| DigiCert High Assurance EV Root CA
| 7431E5F4C3C1CE4690774F0B61E05440883BA9A01ED00BA6ABD7806ED3B118CF
|-
| QuoVadis Root CA 2
| 85A0DD7DD720ADB7FF05F83D542B209DC7FF4528F7D677B18389FEA5E5C49E86
|-
|-
| Entrust.net Certification Authority (2048)
| QuoVadis Root CA 3
| 6DC47172E01CBCB0BF62580D895FE2B8AC9AD4F873801E0C10B9C837D21EB177
| 18F1FC7F205DF8ADDDEB7FE007DD57E3AF375A9C4D8D73546BF4F1FED1E18D35
|-
|-
| AAA Certificate Services
| Entrust Root Certification Authority
| D7A7A0FB5D7E2731D771E9484EBCDEF71D5F0C3E0A2948782BC83EE0EA699EF4
| 73C176434F1BC6D5ADF45B0E76E727287C8DE57616C1E6E6141A2B2CBC7D8E4C
|-
|-
| Go Daddy Class 2 CA
| COMODO Certification Authority
| C3846BF24B9E93CA64274C0EC67C1ECC5E024FFCACD2D74019350E81FE546AE4
| 0C2CD63DF7806FA399EDE809116B575BF87989F06518F9808C860503178BAF66
|-
|-
| Starfield Class 2 CA
| Certigna
| 1465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658
| E3B6A2DB2ED7CE48842F7AC53241C7B71D54144BFB40C11F3F1D0B42F5EEA12D
|-
|-
| XRamp Global Certification Authority
| TeliaSonera Root CA v1
| CECDDC905099D8DADFC5B1D209B737CBE2C18CFB2C10C0FF0BCF0D3286FC1AA2
| DD6936FE21F8F077C123A1A521C12224F72255B73E03A7260693E8A24B0FA389
|-
|-
| Chunghwa Telecom Co., Ltd. - ePKI Root Certification Authority
| Izenpe.com ("distrustAfter" 4/15/20-26)
| C0A6F4DC63A24BFDCF54EF2A6A082A0A72DE35803E2FF5FF527AE5D87206DFD5
| 2530CC8E98321502BAD96F9B1FBA1B099E2D299E0F4548BB914F363BC0D4531F
|-
|-
| GlobalSign Root CA
| EBD41040E4BB3EC742C9E381D31EF2A41A48B6685C96E7CEF3C1DF6CD4331C99
|}
|}



Latest revision as of 18:36, 6 May 2026

Section 7.4 of the Mozilla Root Store Policy (Root CA Lifecycles) notes:

  • For a root CA certificate trusted for server authentication, Mozilla will remove the websites trust bit when the CA key material is more than 15 years old.
  • For a root CA certificate trusted for secure email, Mozilla will set the "Distrust for S/MIME After Date" for the CA certificate to 18 years from the CA key material generation date.

Transition Schedule

For transition purposes, root CA certificates in the Mozilla root store will be distrusted according to the following schedule:

Key Material Created Removal of Websites Trust Bit Distrust for S/MIME After Date
Before 2006 April 15, 2025 April 15, 2028
2006-2007 April 15, 2026 April 15, 2029
2008-2009 April 15, 2027 April 15, 2030
2010-2011 April 15, 2028 April 15, 2031
2012- April 14, 2014 April 15, 2029 April 15, 2032
April 15, 2014 - present 15 years from creation 18 years from creation

This schedule is subject to change if underlying algorithms become more susceptible to cryptanalytic attack or if other circumstances arise that make this schedule obsolete.

CA operators are strongly urged to apply to Mozilla for inclusion of their next generation root certificate at least 2 years before the distrust date of the CA certificate they wish to replace.

2027 Websites Trust Bit Removals

In accordance with the schedule above, Mozilla will remove the websites trust bit for following Root CAs on April 15, 2027:

Root Certification Authority SHA-256 Certificate Hash
COMODO ECC Certification Authority 1793927A0614549789ADCE2F8F34F7F0B66D0F3AE3A3B84D21EC15DBBA4FADC7
COMODO RSA Certification Authority 52F0E1C4E58EC629291B60317F074671B85D7EA80D5B07273463534B32B40234
USERTrust ECC Certification Authority 4FF460D54B9C86DABFBCFC5712E0400D2BED3FBC4D4FBDAA86E06ADCD2A9AD7A
USERTrust RSA Certification Authority E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD2
TWCA Root Certification Authority BFD88FE1101C41AE3E801BF8BE56350EE9BAD1A6B9BD515EDC5C6D5B8711AC44
T-TeleSec GlobalRoot Class 3 FD73DAD31C644FF1B43BEF0CCDDA96710B9CD9875ECA7E31707AF3E96D522BBD
T-TeleSec GlobalRoot Class 2 91E2F5788D5810EBA7BA58737DE1548A8ECACD014598BC0B143E041B17052552
Certum Trusted Network CA 5C58468D55F58E497E743982D2B50010B6D165374ACF83A7D4A32DB768C4408E
FNMT-RCM - SHA256 EBC5570C29018C4D67B1AA127BAF12F703B4611EBC17B7DAB5573894179B93FA
NetLock Arany (Class Gold) Főtanúsítvány 6C61DAC3A2DEF031506BE036D2A6FE401994FBD13DF9C8D466599274C446EC98
GlobalSign Root CA - R3 CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B
Autoridad de Certificacion Firmaprofesional CIF A62634068 04048028BF1F2864D48F9AD4D83294366A828856553F3B14303F90147F5D40EF
Security Communication RootCA2 513B2CECB810D4CDE5DD85391ADFC6C2DD60D87BB736D2B521484AA47A0EBEF6
Microsec e-Szigno Root CA 2009 3C5F81FEA5FAB82C64BFA2EAECAFCDE8E077FC8620A7CAE537163DF36EDBF378
Starfield Services Root Certificate Authority - G2 568D6905A2C88708A4B3025190EDCFEDB1974A606A13C6E5290FCB2AE63EDAB5
Go Daddy Root Certificate Authority - G2 45140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA
Starfield Root Certificate Authority - G2 2CE1CB0BF9D2F9E102993FBE215152C3B2DD0CABDE1C68E5319B839154DBB7F5
D-TRUST Root Class 3 CA 2 2009 49E7A442ACF0EA6287050054B52564B650E4F49E42E348D6AA38E039E957B1C1
D-TRUST Root Class 3 CA 2 EV 2009 EEC5496B988CE98625B934092EEC2908BED0B0F316C2D4730C84EAF1F3D34881

2026 Websites Trust Bit Removals

The following websites trust bit removals occurred in 2026.

CA Name SHA 256 Hash
certSIGN ROOT CA EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB
SwissSign Gold CA - G2 62DD0BE9B9F50A163EA0F8E75C053B1ECA57EA55C8688F647C6881F2C8357B95
Secure Global CA 4200F5043AC8590EBB527D209ED1503029FBCBD41CA1B506EC27F15ADE7DAC69
SecureTrust CA F1C1B50AE5A20DD8030EC9F6BC24823DD367B5255759B4E71B61FCE9F7375D73
DigiCert Assured ID Root CA 3E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C
DigiCert Global Root CA 4348A0E9444C78CB265E058D5E8944B4D84F9662BD26DB257F8934A443C70161
DigiCert High Assurance EV Root CA 7431E5F4C3C1CE4690774F0B61E05440883BA9A01ED00BA6ABD7806ED3B118CF
QuoVadis Root CA 2 85A0DD7DD720ADB7FF05F83D542B209DC7FF4528F7D677B18389FEA5E5C49E86
QuoVadis Root CA 3 18F1FC7F205DF8ADDDEB7FE007DD57E3AF375A9C4D8D73546BF4F1FED1E18D35
Entrust Root Certification Authority 73C176434F1BC6D5ADF45B0E76E727287C8DE57616C1E6E6141A2B2CBC7D8E4C
COMODO Certification Authority 0C2CD63DF7806FA399EDE809116B575BF87989F06518F9808C860503178BAF66
Certigna E3B6A2DB2ED7CE48842F7AC53241C7B71D54144BFB40C11F3F1D0B42F5EEA12D
TeliaSonera Root CA v1 DD6936FE21F8F077C123A1A521C12224F72255B73E03A7260693E8A24B0FA389
Izenpe.com ("distrustAfter" 4/15/20-26) 2530CC8E98321502BAD96F9B1FBA1B099E2D299E0F4548BB914F363BC0D4531F

Background

Old Roots CAs and Hierarchies do not meet Current Requirements

Mozilla's Root Store Policy and the CA/Browser Forum Baseline Requirements (CABF BRs) are constantly evolving in order to improve security on the web. As new requirements are introduced, existing CA hierarchies are grandfathered in. Over time, these CA hierarchies need to be replaced so that they become fully compliant with current policies. Having a policy about root CA lifecycles will ensure that CA hierarchies get updated and become fully compliant.
Examples of how requirements and practices have changed over time include, but are not limited to, the following:

  • Mozilla's first root store policy was published in 2004.
  • The CA/Browser Forum EV Guidelines were adopted in October 2006, and for root CA keys to be trusted for EV treatment in browsers they had to be created in an auditor-witnessed key generation ceremony.
  • In July 2012 the CA/Browser Forum Baseline Requirements became effective and required that for all publicly-trusted TLS CA hierarchies, the root CA keys had to be created in an auditor-witnessed key generation ceremony.
  • Mozilla's root store policy required that as of January 2013 CA hierarchies be audited against the CA/Browser Forum Baseline Requirements.
  • In June 2017 Mozilla's root store policy began requiring that CAs have cradle-to-grave continuous key protection and period-of-time audits without gaps.
  • Intermediate CA certificates created since January 1, 2019, must have an EKU extension and cannot have both serverAuth and emailProtection EKUs in the same CA certificate.

Cryptographic Agility

Cryptographic agility is the ability to replace cryptographic primitives, algorithms, and protocols efficiently at reasonable cost with limited impact on operations. Mozilla is committed to agile management of our root store and the timely rotation of root certificates. Without this, some root CA certificates in Mozilla's root store could otherwise still be in use after 25 years. As computer processing speed increases and technology changes, we expect that cryptographic weaknesses will be discovered, such that it will be necessary to replace aging CA hierarchies. Or there will be advances in technology supporting cryptanalysis, and it will be necessary to replace cryptographic algorithms.

Why 15 years for TLS and 18 years for S/MIME?

It typically takes 2 to 3 years for a root certificate to get included into the major root stores. Time is also needed to complete the transition from an older hierarchy to the newer hierarchy before a CA can be distrusted for TLS. Therefore, a 15-year term allows for approximately 10 years of root CA use within the Mozilla root store.

Root certificates can have the email (S/MIME) trust bit enabled for longer than the server (websites) trust bit, because S/MIME certificates have a longer lifetime (3 years) than TLS server certificates (1 year). Additionally, we will use the "Distrust for S/MIME After Date" rather than immediately turning off the email trust bit, because S/MIME certificates have a different usage scenario and risk profile (than TLS server certificates).