MRSP Intermediate Violations (5.3), Mass Report of 26 Subordinate CAs

1,189 views
Skip to first unread message

Wayne

unread,
Jul 19, 2026, 8:16:37 PMJul 19
to dev-secur...@mozilla.org
I have been performing some unrelated research and had a read of the Mozilla Root Store Policy.

>5.3 Intermediate Certificates
>All certificates that are capable of being used to issue new certificates and that directly or transitively chain to a CA certificate included in Mozilla’s root store MUST be operated in accordance with this policy.
>
>...
>
>Intermediate certificates created after January 1, 2019, with the exception of cross-certificates that share a private key with a corresponding root certificate:
>- MUST contain an EKU extension;
>- MUST NOT include the anyExtendedKeyUsage KeyPurposeId; and
>- MUST NOT include both the id-kp-serverAuth and id-kp-emailProtection KeyPurposeIds in the same certificate.

Thanks to Censys and the following query I've been about to check the above.
(cert.validation.nss.is_valid=true and not cert.labels="revoked" and (cert.labels = "intermediate" and not cert.labels="root")) and cert.parsed.validity_period.not_before>='2019-01-01' and not (cert.parsed.extensions.extended_key_usage.server_auth=false or cert.parsed.extensions.extended_key_usage.server_auth=true)

The following concerns all known intermediate certificates that chain to the NSS store that lack an EKU extension. No corresponding root certificate was found through checks.

Layout: ID, Subject CN, Subject DN, SHA256s matching

1. AC Sector Público
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Sector Público
8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498


2. AC Unidades de Sellado de Tiempo
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Unidades de Sellado de Tiempo
9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea


3. Amazon ECDSA 256 Root EU M1
C=DE, O=Amazon, CN=Amazon ECDSA 256 Root EU M1
9ead32c9285fe68ba2c5b0fe427d149b103fdfa1d0958d77c3da0ff246e853d3


4. Amazon ECDSA 384 Root EU M1
C=DE, O=Amazon, CN=Amazon ECDSA 384 Root EU M1
8e136ce0e77c848f2d2910abd4e3a764358bb1b7a4932202bc9b915732462d85


5. Amazon RSA 2048 Root EU M1
C=DE, O=Amazon, CN=Amazon RSA 2048 Root EU M1
eaffac50c7e3e15a68f779a5e70ec2f5e9fc4a03ff69ab337b4d6c4510432395


6. Certum EC-384 CA
C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum EC-384 CA
b72450abf5047a8af63ec9d87e331484850b1849a2550a82a86db6b41ed38760


7. Certum Trusted Network CA 2
C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA 2
08e7eac998a62c4155cc4cbc5eda32f5b41a12c012f29ab3433bd366348149f0


8. Certum Trusted Root CA
C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum Trusted Root CA
fb13890c7ab14ff7b94b2714503e31123bfdd340fc4d979743166e0469b47a88


9. CFCA Global RSA ROOT G2
C=CN, O=China Financial Certification Authority, CN=CFCA Global RSA ROOT G2
6e6eb29f5eba910affd462fc921d724e526805efe908aec45bd409b624e14c09
faa4fa0ef7056d6953bbdfb36461e3f7cdf33352af724fd8254b184d3e2c941f


10. DigiCert Assured ID Root G2
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root G2
d9ae5ed27c9c6485296c89a29d222f4ab2bc7eeca51ecc8d2d7a23fe9c1151da


11. DigiCert Global Root G2
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
6523c34f1e879add7603cb2048a898a5e2f0c6c4b512c0d22782b85d43ae3371
79d57b15dfa65c2870eafe11b637765909cfe937b49c15ce7f194030cab395ad
a0d609a7e3c434e878a9a1c1bd065b8dcf33aa7efee1b11bc75cce5e5a042080
caf8ad697f7bda712ab127a8ad8b83f74a91a0de1784a1b483fef9ac79b67513


12. DigiCert Trusted Root G4
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root G4
33846b545a49c9be4903c60e01713c1bd4e4ef31ea65cd95d69e62794f30b941


13. e-Szigno RSA TLS Root CA 2025
C=HU, L=Budapest, O=Microsec Ltd., CN=e-Szigno RSA TLS Root CA 2025
a01c4f8f68112fa9dac50b96809a791480168c8acb9e51c5482d8d3819688557


14. GlobalSign
OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
f349954e8fb6d44011bcb789d97d9a2cb2032bd5f0b598d1fb8a099f5848d523


15. GlobalSign
OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
c84e1378b974a991acdcdd733421e3061e6fa21a0491c8902bafde3855e0063e
dda8da736187d76f4f0ed5a5f667b54d99a98ae06091d0e3a01714e9221695ad


16. GTS Root R1
C=US, O=Google Trust Services LLC, CN=GTS Root R1
3ee0278df71fa3c125c4cd487f01d774694e6fc57e0cd94c24efd769133918e5


17. Microsoft TLS RSA Root G2
C=US, O=Microsoft Corporation, CN=Microsoft TLS RSA Root G2
6a170583db584151e1c454eeca2a64cc5d8e484a5bd1156e720b4458654ee9e5


18. Root YE
C=US, O=ISRG, CN=Root YE
e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666


19. Root YR
C=US, O=ISRG, CN=Root YR
e57b7e6f150c419102e8d5c055729ff967b9d1a829bf00cec89ca604ebf4a86f


20. SSL.com EV Root Certification Authority ECC
C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority ECC
60ef412eabe7c3fc6399eed1b633b777747515b29d721b963dd258bc498ab292


21. SSL.com Root Certification Authority ECC

C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority ECC
06b9722a699c57dff1869f430b479bb6eb49aae1184eac9c5325c1334a34ea4c


22. SwissSign RSA SMIME Root CA 2021 - 1
C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1
bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07


23. SwissSign RSA SMIME Root CA 2022 - 1
C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1
5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2


24. TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 2
C=TR, ST=Kocaeli, O=TUBITAK Kamu Sertifikasyon Merkezi, CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 2
ec6431ba9fc13e405df80ade58a048136f789a03fdca4cf5daa4336ac522225b


25. USERTrust ECC Certification Authority
C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
a6cf64dbb4c8d5fd19ce48896068db03b533a8d1336c6256a87d00cbb3def3ea


26. USERTrust RSA Certification Authority
C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b


Whether directly or indirectly because of chaining these are currently in violation of the Mozilla Root Store Policy.

- Wayne

Matthew McPherrin

unread,
Jul 19, 2026, 11:38:42 PMJul 19
to dev-secur...@mozilla.org, Wayne
The following two entries from Let's Encrypt are not intermediate certificates:
They are roots, pending inclusion.
I haven't validated this to be true of every entry on the list, but it appears to me certainly the majority are either roots, or are cross-signed which have an explicit exemption in the policy.

18. Root YE - C=US, O=ISRG, CN=Root YE
e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666

19. Root YR - C=US, O=ISRG, CN=Root YR
e57b7e6f150c419102e8d5c055729ff967b9d1a829bf00cec89ca604ebf4a86f

Michael Stone

unread,
Jul 19, 2026, 11:45:35 PMJul 19
to dev-secur...@mozilla.org, Wayne
Hi Wayne,

Good day.

Regarding the certificates you mentioned, for CFCA:

- sha256 Fingerprint=6E:6E:B2:9F:5E:BA:91:0A:FF:D4:62:FC:92:1D:72:4E:52:68:05:EF:E9:08:AE:C4:5B:D4:09:B6:24:E1:4C:09
this is a root certificate, it's not in violation with MRSP 5.3

- sha256 Fingerprint=FA:A4:FA:0E:F7:05:6D:69:53:BB:DF:B3:64:61:E3:F7:CD:F3:33:52:AF:72:4F:D8:25:4B:18:4D:3E:2C:94:1F
this is a cross certificate signed by CFCA  EV  ROOT, and within the 'exception' of MRSP 5.3.

I've just checked BR, it seems not in violation with BR/MRSP. 

Let me know if you have any other concerns.

Wayne

unread,
Jul 20, 2026, 1:02:32 AMJul 20
to dev-secur...@mozilla.org, Michael Stone, Wayne
Yup my bad had the notBefore >=2019-01-01 still active on the checks. Here is a revised list being more conservative on any self-signs:

Layout: ID, Subject CN, Subject DN, SHA256s matching

1. AC Sector Público
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Sector Público
8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498


2. AC Unidades de Sellado de Tiempo
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Unidades de Sellado de Tiempo
9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea


3. DigiCert Global Root G2

C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
6523c34f1e879add7603cb2048a898a5e2f0c6c4b512c0d22782b85d43ae3371
79d57b15dfa65c2870eafe11b637765909cfe937b49c15ce7f194030cab395ad
a0d609a7e3c434e878a9a1c1bd065b8dcf33aa7efee1b11bc75cce5e5a042080
caf8ad697f7bda712ab127a8ad8b83f74a91a0de1784a1b483fef9ac79b67513


4. GlobalSign

OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
c84e1378b974a991acdcdd733421e3061e6fa21a0491c8902bafde3855e0063e
dda8da736187d76f4f0ed5a5f667b54d99a98ae06091d0e3a01714e9221695ad


5. SwissSign RSA SMIME Root CA 2022 - 1

C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1
5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2


6. SwissSign RSA SMIME Root CA 2021 - 1

C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1
bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07


7. USERTrust RSA Certification Authority

C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b

- Wayne

Wayne

unread,
Jul 20, 2026, 2:07:27 AMJul 20
to dev-secur...@mozilla.org
Okay something's odd with Censys. For the Digicert one checking elsewhere I can find the root...

https://platform.censys.io/certificates/cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f

However searching for that by SPKI SHA256, or its own SHA256 fingerprint yields no results for the root:
cert.parsed.subject_key_info.fingerprint_sha256: "8bb593a93be1d0e8a822bb887c547890c3e706aad2dab76254f97fb36b82fc26"
> 34 results, however no self-signed

cert.fingerprint_sha256: "cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f"
> 0 results

I'm wondering if this was imported into Censys in an odd way to break it appearing in searches.

- Wayne

Wayne

unread,
Jul 20, 2026, 2:30:29 AMJul 20
to dev-secur...@mozilla.org, Wayne
Exact same issue for Globalsign, if you know the root you can find the certificate:


But searching for it by SHA256, SPKI, etc yields nothing.

- Wayne

Wayne

unread,
Jul 20, 2026, 2:49:02 AMJul 20
to dev-secur...@mozilla.org
This is also true for the USERTrust cert:


USERTrust RSA Certification Authority
C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b

https://platform.censys.io/certificates/e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2
https://platform.censys.io/certificates/1a5174980a294a528a110726d5855650266c48d9883bea692b67b6d726da98c5 notBefore 2000-05-30? Wrong or very old key material?



SwissSign RSA SMIME Root CA 2022 - 1
C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1
5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2

Root not on Censys due to SMIME: https://crt.sh/?id=7044154542



SwissSign RSA SMIME Root CA 2021 - 1
C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1
bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07

Root not on Censys due to SMIME: https://crt.sh/?id=5011200301


So after all of the false positives and Censys oddities we're left with:


1. AC Sector Público
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Sector Público
8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498


2. AC Unidades de Sellado de Tiempo
C=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Unidades de Sellado de Tiempo
9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea

- Wayne

Roman Fischer

unread,
Jul 20, 2026, 4:09:05 AMJul 20
to Wayne, dev-secur...@mozilla.org, Compliance

Dear Wayne,

 

Both SwissSign certificates mentioned are roots that are cross-signed by our "SwissSign Gold CA – G2" and thus fall under the exception of MRSP 5.3.

The corresponding self-signed roots can be found e.g. here:

 

Kind regards
Roman

--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/b0f2201f-7f37-4378-a26c-94f817f95dc2n%40mozilla.org.

Rob Stradling

unread,
Jul 27, 2026, 10:45:45 AMJul 27
to Wayne, dev-secur...@mozilla.org
Hi Wayne.

> This is also true for the USERTrust cert:
>
> USERTrust RSA Certification Authority
> C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
> 68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b

> https://platform.censys.io/certificates/e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2

This is a self-signed root certificate.  The key material was generated on 1st July 2009.
This is a cross-certificate (for the same Subject CA as above) that has its notBefore timestamp backdated to match the notBefore timestamp of the root that issued it.  This backdating is compliant even with the current TLS BRs:
"7.1.2.2.1 (Cross‑Certified Subordinate CA Validity)
notBefore - Minimum - The earlier of one day prior to the time of signing or the earliest notBefore date of the existing CA Certificate(s)"

When faced with multiple certification paths, Windows CryptoAPI prefers a newer notBefore timestamp.  Backdating a cross-certificate's notBefore timestamp helps to ensure that the shortest chain to the newest root will be selected and used (when that shortest chain is trusted).



Subject: Re: MRSP Intermediate Violations (5.3), Mass Report of 26 Subordinate CAs
This is also true for the USERTrust cert: USERTrust RSA Certification Authority C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority 68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b
ZjQcmQRYFpfptBannerStart
This Message Is From an External Sender
This message came from outside your organization.
 
ZjQcmQRYFpfptBannerEnd
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.

Luis Osses

unread,
Jul 28, 2026, 10:25:50 AMJul 28
to dev-secur...@mozilla.org, Wayne
Hello Wayne,

Thanks for dedicating the time for this research!

Understanding that you already did a re-evaluation of the list, but for the sake of confirmation from Amazon's side, the entries mentioned in the initial list are roots that have been cross-signed, therefore fall under the exception of the clause §5.3 of the MRSP.

Best regards,
Luis Osses
Sr. Security Industry Specialist
Amazon Trust Services
Reply all
Reply to author
Forward
0 new messages