This is also true for the USERTrust cert: USERTrust RSA Certification Authority C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority 68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b
https://platform.censys.io/certificates/e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2 https://platform.censys.io/certificates/1a5174980a294a528a110726d5855650266c48d9883bea692b67b6d726da98c5 notBefore 2000-05-30? Wrong or very old key material? SwissSign RSA SMIME Root CA 2022 - 1 C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1 5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2 Root not on Censys due to SMIME: https://crt.sh/?id=7044154542 SwissSign RSA SMIME Root CA 2021 - 1 C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1 bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07 Root not on Censys due to SMIME: https://crt.sh/?id=5011200301 So after all of the false positives and Censys oddities we're left with: 1. AC Sector Público C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Sector Público 8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498 2. AC Unidades de Sellado de Tiempo C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Unidades de Sellado de Tiempo 9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea - Wayne On Monday, July 20, 2026 at 7:30:29 AM UTC+1 Wayne wrote: > Exact same issue for Globalsign, if you know the root you can find the > certificate: > > > https://platform.censys.io/certificates/2CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF69 > > But searching for it by SHA256, SPKI, etc yields nothing. > > - Wayne > > On Monday, July 20, 2026 at 7:07:27 AM UTC+1 Wayne wrote: > >> Okay something's odd with Censys. For the Digicert one checking elsewhere >> I can find the root... >> >> >> https://platform.censys.io/certificates/cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f >> >> However searching for that by SPKI SHA256, or its own SHA256 fingerprint >> yields no results for the root: >> cert.parsed.subject_key_info.fingerprint_sha256: >> "8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26" >> > 34 results, however no self-signed >> >> cert.fingerprint_sha256: >> "cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f" >> > 0 results >> >> I'm wondering if this was imported into Censys in an odd way to break it >> appearing in searches. >> >> - Wayne >> >> On Monday, July 20, 2026 at 6:02:32 AM UTC+1 Wayne wrote: >> >>> Yup my bad had the notBefore >=2019-01-01 still active on the checks. >>> Here is a revised list being more conservative on any self-signs: >>> >>> Layout: ID, Subject CN, Subject DN, SHA256s matching >>> >>> *1. AC Sector Público* >>> C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, >>> CN=AC Sector Público >>> 8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498 >>> >>> >>> *2. AC Unidades de Sellado de Tiempo* >>> C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, >>> CN=AC Unidades de Sellado de Tiempo >>> 9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea >>> >>> >>> *3. DigiCert Global Root G2* >>> >>> C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2 >>> 6523c34f1e879add7603cb2048a898a5e2f0c6c4b512c0d22782b85d43ae3371 >>> 79d57b15dfa65c2870eafe11b637765909cfe937b49c15ce7f194030cab395ad >>> a0d609a7e3c434e878a9a1c1bd065b8dcf33aa7efee1b11bc75cce5e5a042080 >>> caf8ad697f7bda712ab127a8ad8b83f74a91a0de1784a1b483fef9ac79b67513 >>> >>> >>> *4. GlobalSign* >>> >>> OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign >>> c84e1378b974a991acdcdd733421e3061e6fa21a0491c8902bafde3855e0063e >>> dda8da736187d76f4f0ed5a5f667b54d99a98ae06091d0e3a01714e9221695ad >>> >>> >>> *5. SwissSign RSA SMIME Root CA 2022 - 1* >>> >>> C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1 >>> 5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2 >>> >>> >>> *6. SwissSign RSA SMIME Root CA 2021 - 1* >>> >>> C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1 >>> bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07 >>> >>> >>> *7. USERTrust RSA Certification Authority* >>> >>> C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, >>> CN=USERTrust RSA Certification Authority >>> 68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b >>> >>> - Wayne >>> >>> On Monday, July 20, 2026 at 4:45:35 AM UTC+1 Michael Stone wrote: >>> >>>> Hi Wayne, >>>> >>>> Good day. >>>> >>>> Regarding the certificates you mentioned, for CFCA: >>>> >>>> - sha256 >>>> Fingerprint=6E:6E:B2:9F:5E:BA:91:0A:FF:D4:62:FC:92:1D:72:4E:52:68:05:EF:E9:08:AE:C4:5B:D4:09:B6:24:E1:4C:09 >>>> this is a root certificate, it's not in violation with MRSP 5.3 >>>> >>>> - sha256 >>>> Fingerprint=FA:A4:FA:0E:F7:05:6D:69:53:BB:DF:B3:64:61:E3:F7:CD:F3:33:52:AF:72:4F:D8:25:4B:18:4D:3E:2C:94:1F >>>> this is a cross certificate signed by CFCA EV ROOT, and within the >>>> 'exception' of MRSP 5.3. >>>> >>>> I've just checked BR, it seems not in violation with BR/MRSP. >>>> >>>> Let me know if you have any other concerns. >>>> >>>> On Monday, July 20, 2026 at 11:38:42 AM UTC+8 Matthew McPherrin wrote: >>>> >>>>> The following two entries from Let's Encrypt are not intermediate >>>>> certificates: >>>>> They are roots, pending inclusion. >>>>> I haven't validated this to be true of every entry on the list, but it >>>>> appears to me certainly the majority are either roots, or are >>>>> cross-signed >>>>> which have an explicit exemption in the policy. >>>>> >>>>> 18. Root YE - C=US, O=ISRG, CN=Root YE >>>>> e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666 >>>>> >>>>> 19. Root YR - C=US, O=ISRG, CN=Root YR >>>>> e57b7e6f150c419102e8d5c055729ff967b9d1a829bf00cec89ca604ebf4a86f >>>>> >>>>> On Sunday, July 19, 2026 at 8:16:37 PM UTC-4 Wayne wrote: >>>>> >>>>>> I have been performing some unrelated research and had a read of the >>>>>> Mozilla Root Store Policy. >>>>>> >>>>>> >5.3 Intermediate Certificates >>>>>> >All certificates that are capable of being used to issue new >>>>>> certificates and that directly or transitively chain to a CA certificate >>>>>> included in Mozilla’s root store MUST be operated in accordance with >>>>>> this >>>>>> policy. >>>>>> > >>>>>> >... >>>>>> > >>>>>> >Intermediate certificates created after January 1, 2019, with the >>>>>> exception of cross-certificates that share a private key with a >>>>>> corresponding root certificate: >>>>>> >- MUST contain an EKU extension; >>>>>> >- MUST NOT include the anyExtendedKeyUsage KeyPurposeId; and >>>>>> >- MUST NOT include both the id-kp-serverAuth and >>>>>> id-kp-emailProtection KeyPurposeIds in the same certificate. >>>>>> >>>>>> Thanks to Censys and the following query I've been about to check the >>>>>> above. >>>>>> (cert.validation.nss.is_valid=true and not cert.labels="revoked" and >>>>>> (cert.labels = "intermediate" and not cert.labels="root")) and >>>>>> cert.parsed.validity_period.not_before>='2019-01-01' and not >>>>>> (cert.parsed.extensions.extended_key_usage.server_auth=false or >>>>>> cert.parsed.extensions.extended_key_usage.server_auth=true) >>>>>> >>>>>> The following concerns all known intermediate certificates that chain >>>>>> to the NSS store that lack an EKU extension. No corresponding root >>>>>> certificate was found through checks. >>>>>> >>>>>> Layout: ID, Subject CN, Subject DN, SHA256s matching >>>>>> >>>>>> *1. AC Sector Público* >>>>>> C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, >>>>>> CN=AC Sector Público >>>>>> 8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498 >>>>>> >>>>>> >>>>>> *2. AC Unidades de Sellado de Tiempo* >>>>>> C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, >>>>>> CN=AC Unidades de Sellado de Tiempo >>>>>> 9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea >>>>>> >>>>>> >>>>>> *3. Amazon ECDSA 256 Root EU M1* >>>>>> C=DE, O=Amazon, CN=Amazon ECDSA 256 Root EU M1 >>>>>> 9ead32c9285fe68ba2c5b0fe427d149b103fdfa1d0958d77c3da0ff246e853d3 >>>>>> >>>>>> >>>>>> *4. Amazon ECDSA 384 Root EU M1* >>>>>> C=DE, O=Amazon, CN=Amazon ECDSA 384 Root EU M1 >>>>>> 8e136ce0e77c848f2d2910abd4e3a764358bb1b7a4932202bc9b915732462d85 >>>>>> >>>>>> >>>>>> *5. Amazon RSA 2048 Root EU M1* >>>>>> C=DE, O=Amazon, CN=Amazon RSA 2048 Root EU M1 >>>>>> eaffac50c7e3e15a68f779a5e70ec2f5e9fc4a03ff69ab337b4d6c4510432395 >>>>>> >>>>>> >>>>>> *6. Certum EC-384 CA* >>>>>> C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, >>>>>> CN=Certum EC-384 CA >>>>>> b72450abf5047a8af63ec9d87e331484850b1849a2550a82a86db6b41ed38760 >>>>>> >>>>>> >>>>>> *7. Certum Trusted Network CA 2* >>>>>> C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, >>>>>> CN=Certum Trusted Network CA 2 >>>>>> 08e7eac998a62c4155cc4cbc5eda32f5b41a12c012f29ab3433bd366348149f0 >>>>>> >>>>>> >>>>>> *8. Certum Trusted Root CA* >>>>>> C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, >>>>>> CN=Certum Trusted Root CA >>>>>> fb13890c7ab14ff7b94b2714503e31123bfdd340fc4d979743166e0469b47a88 >>>>>> >>>>>> >>>>>> *9. CFCA Global RSA ROOT G2* >>>>>> C=CN, O=China Financial Certification Authority, CN=CFCA Global RSA >>>>>> ROOT G2 >>>>>> 6e6eb29f5eba910affd462fc921d724e526805efe908aec45bd409b624e14c09 >>>>>> faa4fa0ef7056d6953bbdfb36461e3f7cdf33352af724fd8254b184d3e2c941f >>>>>> >>>>>> >>>>>> *10. DigiCert Assured ID Root G2* >>>>>> C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID >>>>>> Root G2 >>>>>> d9ae5ed27c9c6485296c89a29d222f4ab2bc7eeca51ecc8d2d7a23fe9c1151da >>>>>> >>>>>> >>>>>> *11. DigiCert Global Root G2* >>>>>> C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2 >>>>>> 6523c34f1e879add7603cb2048a898a5e2f0c6c4b512c0d22782b85d43ae3371 >>>>>> 79d57b15dfa65c2870eafe11b637765909cfe937b49c15ce7f194030cab395ad >>>>>> a0d609a7e3c434e878a9a1c1bd065b8dcf33aa7efee1b11bc75cce5e5a042080 >>>>>> caf8ad697f7bda712ab127a8ad8b83f74a91a0de1784a1b483fef9ac79b67513 >>>>>> >>>>>> >>>>>> *12. DigiCert Trusted Root G4* >>>>>> C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root >>>>>> G4 >>>>>> 33846b545a49c9be4903c60e01713c1bd4e4ef31ea65cd95d69e62794f30b941 >>>>>> >>>>>> >>>>>> *13. e-Szigno RSA TLS Root CA 2025* >>>>>> C=HU, L=Budapest, O=Microsec Ltd., CN=e-Szigno RSA TLS Root CA 2025 >>>>>> a01c4f8f68112fa9dac50b96809a791480168c8acb9e51c5482d8d3819688557 >>>>>> >>>>>> >>>>>> *14. GlobalSign* >>>>>> OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign >>>>>> f349954e8fb6d44011bcb789d97d9a2cb2032bd5f0b598d1fb8a099f5848d523 >>>>>> >>>>>> >>>>>> *15. GlobalSign* >>>>>> OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign >>>>>> c84e1378b974a991acdcdd733421e3061e6fa21a0491c8902bafde3855e0063e >>>>>> dda8da736187d76f4f0ed5a5f667b54d99a98ae06091d0e3a01714e9221695ad >>>>>> >>>>>> >>>>>> *16. GTS Root R1* >>>>>> C=US, O=Google Trust Services LLC, CN=GTS Root R1 >>>>>> 3ee0278df71fa3c125c4cd487f01d774694e6fc57e0cd94c24efd769133918e5 >>>>>> >>>>>> >>>>>> *17. Microsoft TLS RSA Root G2* >>>>>> C=US, O=Microsoft Corporation, CN=Microsoft TLS RSA Root G2 >>>>>> 6a170583db584151e1c454eeca2a64cc5d8e484a5bd1156e720b4458654ee9e5 >>>>>> >>>>>> >>>>>> *18. Root YE* >>>>>> C=US, O=ISRG, CN=Root YE >>>>>> e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666 >>>>>> >>>>>> >>>>>> *19. Root YR* >>>>>> C=US, O=ISRG, CN=Root YR >>>>>> e57b7e6f150c419102e8d5c055729ff967b9d1a829bf00cec89ca604ebf4a86f >>>>>> >>>>>> >>>>>> *20. SSL.com EV Root Certification Authority ECC* >>>>>> C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root >>>>>> Certification Authority ECC >>>>>> 60ef412eabe7c3fc6399eed1b633b777747515b29d721b963dd258bc498ab292 >>>>>> >>>>>> >>>>>> *21. SSL.com Root Certification Authority ECC* >>>>>> C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root >>>>>> Certification Authority ECC >>>>>> 06b9722a699c57dff1869f430b479bb6eb49aae1184eac9c5325c1334a34ea4c >>>>>> >>>>>> >>>>>> *22. SwissSign RSA SMIME Root CA 2021 - 1* >>>>>> C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1 >>>>>> bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07 >>>>>> >>>>>> >>>>>> *23. SwissSign RSA SMIME Root CA 2022 - 1* >>>>>> C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1 >>>>>> 5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2 >>>>>> >>>>>> >>>>>> *24. TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 2* >>>>>> C=TR, ST=Kocaeli, O=TUBITAK Kamu Sertifikasyon Merkezi, CN=TUBITAK >>>>>> Kamu SM SSL Kok Sertifikasi - Surum 2 >>>>>> ec6431ba9fc13e405df80ade58a048136f789a03fdca4cf5daa4336ac522225b >>>>>> >>>>>> >>>>>> *25. USERTrust ECC Certification Authority* >>>>>> C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, >>>>>> CN=USERTrust ECC Certification Authority >>>>>> a6cf64dbb4c8d5fd19ce48896068db03b533a8d1336c6256a87d00cbb3def3ea >>>>>> >>>>>> >>>>>> *26. USERTrust RSA Certification Authority* >>>>>> C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, >>>>>> CN=USERTrust RSA Certification Authority >>>>>> 68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b >>>>>> >>>>>> >>>>>> Whether directly or indirectly because of chaining these are >>>>>> currently in violation of the Mozilla Root Store Policy. >>>>>> >>>>>> - Wayne >>>>> >>>>> -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/9fc0a709-b81c-4c33-8054-614930cead31n%40mozilla.org.
