I have been performing some unrelated research and had a read of the Mozilla Root Store Policy.
>5.3 Intermediate Certificates
>All certificates that are capable of being used to issue new certificates and that directly or transitively chain to a CA certificate included in Mozilla’s root store MUST be operated in accordance with this policy.
>
>...
>
>Intermediate certificates created after January 1, 2019, with the exception of cross-certificates that share a private key with a corresponding root certificate:
>- MUST contain an EKU extension;
>- MUST NOT include the anyExtendedKeyUsage KeyPurposeId; and
>- MUST NOT include both the id-kp-serverAuth and id-kp-emailProtection KeyPurposeIds in the same certificate.
Thanks to Censys and the following query I've been about to check the above.
(cert.validation.nss.is_valid=true and not cert.labels="revoked" and (cert.labels = "intermediate" and not cert.labels="root")) and cert.parsed.validity_period.not_before>='2019-01-01' and not (cert.parsed.extensions.extended_key_usage.server_auth=false or cert.parsed.extensions.extended_key_usage.server_auth=true)
The following concerns all known intermediate certificates that chain to the NSS store that lack an EKU extension. No corresponding root certificate was found through checks.
Layout: ID, Subject CN, Subject DN, SHA256s matching
1. AC Sector PúblicoC=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Sector Público
8265756dd5cd8a37ee61e40351288e4b16a89dd248c1ec4eba25aaf161abf498
2. AC Unidades de Sellado de TiempoC=ES, O=FNMT-RCM, OU=Ceres, organizationIdentifier=VATES-Q2826004J, CN=AC Unidades de Sellado de Tiempo
9ce630b35f8ae2c6419e734ad9d2fa30476dd9e7394b1e93b27f83f776a024ea
3. Amazon ECDSA 256 Root EU M1C=DE, O=Amazon, CN=Amazon ECDSA 256 Root EU M1
9ead32c9285fe68ba2c5b0fe427d149b103fdfa1d0958d77c3da0ff246e853d3
4. Amazon ECDSA 384 Root EU M1C=DE, O=Amazon, CN=Amazon ECDSA 384 Root EU M1
8e136ce0e77c848f2d2910abd4e3a764358bb1b7a4932202bc9b915732462d85
5. Amazon RSA 2048 Root EU M1C=DE, O=Amazon, CN=Amazon RSA 2048 Root EU M1
eaffac50c7e3e15a68f779a5e70ec2f5e9fc4a03ff69ab337b4d6c4510432395
6. Certum EC-384 CAC=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum EC-384 CA
b72450abf5047a8af63ec9d87e331484850b1849a2550a82a86db6b41ed38760
7. Certum Trusted Network CA 2C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA 2
08e7eac998a62c4155cc4cbc5eda32f5b41a12c012f29ab3433bd366348149f0
8. Certum Trusted Root CAC=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum Trusted Root CA
fb13890c7ab14ff7b94b2714503e31123bfdd340fc4d979743166e0469b47a88
9. CFCA Global RSA ROOT G2C=CN, O=China Financial Certification Authority, CN=CFCA Global RSA ROOT G2
6e6eb29f5eba910affd462fc921d724e526805efe908aec45bd409b624e14c09
faa4fa0ef7056d6953bbdfb36461e3f7cdf33352af724fd8254b184d3e2c941f
10. DigiCert Assured ID Root G2C=US, O=DigiCert Inc, OU=
www.digicert.com, CN=DigiCert Assured ID Root G2
d9ae5ed27c9c6485296c89a29d222f4ab2bc7eeca51ecc8d2d7a23fe9c1151da
11. DigiCert Global Root G2C=US, O=DigiCert Inc, OU=
www.digicert.com, CN=DigiCert Global Root G2
6523c34f1e879add7603cb2048a898a5e2f0c6c4b512c0d22782b85d43ae3371
79d57b15dfa65c2870eafe11b637765909cfe937b49c15ce7f194030cab395ad
a0d609a7e3c434e878a9a1c1bd065b8dcf33aa7efee1b11bc75cce5e5a042080
caf8ad697f7bda712ab127a8ad8b83f74a91a0de1784a1b483fef9ac79b67513
12. DigiCert Trusted Root G4C=US, O=DigiCert Inc, OU=
www.digicert.com, CN=DigiCert Trusted Root G4
33846b545a49c9be4903c60e01713c1bd4e4ef31ea65cd95d69e62794f30b941
13. e-Szigno RSA TLS Root CA 2025C=HU, L=Budapest, O=Microsec Ltd., CN=e-Szigno RSA TLS Root CA 2025
a01c4f8f68112fa9dac50b96809a791480168c8acb9e51c5482d8d3819688557
14. GlobalSignOU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
f349954e8fb6d44011bcb789d97d9a2cb2032bd5f0b598d1fb8a099f5848d523
15. GlobalSignOU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
c84e1378b974a991acdcdd733421e3061e6fa21a0491c8902bafde3855e0063e
dda8da736187d76f4f0ed5a5f667b54d99a98ae06091d0e3a01714e9221695ad
16. GTS Root R1C=US, O=Google Trust Services LLC, CN=GTS Root R1
3ee0278df71fa3c125c4cd487f01d774694e6fc57e0cd94c24efd769133918e5
17. Microsoft TLS RSA Root G2C=US, O=Microsoft Corporation, CN=Microsoft TLS RSA Root G2
6a170583db584151e1c454eeca2a64cc5d8e484a5bd1156e720b4458654ee9e5
18. Root YEC=US, O=ISRG, CN=Root YE
e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666
19. Root YRC=US, O=ISRG, CN=Root YR
e57b7e6f150c419102e8d5c055729ff967b9d1a829bf00cec89ca604ebf4a86f
20. SSL.com EV Root Certification Authority ECCC=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority ECC
60ef412eabe7c3fc6399eed1b633b777747515b29d721b963dd258bc498ab292
21. SSL.com Root Certification Authority ECCC=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority ECC
06b9722a699c57dff1869f430b479bb6eb49aae1184eac9c5325c1334a34ea4c
22. SwissSign RSA SMIME Root CA 2021 - 1C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2021 - 1
bc8bbd7d279d2e5f070bcef6faf3aab1bef30da3eb2875424295ad147f2aef07
23. SwissSign RSA SMIME Root CA 2022 - 1C=CH, O=SwissSign AG, CN=SwissSign RSA SMIME Root CA 2022 - 1
5a84c94054d340d650a29985ef97bb396352e215aed6c0b33ca7ffdd3bd5d2a2
24. TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 2C=TR, ST=Kocaeli, O=TUBITAK Kamu Sertifikasyon Merkezi, CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 2
ec6431ba9fc13e405df80ade58a048136f789a03fdca4cf5daa4336ac522225b
25. USERTrust ECC Certification AuthorityC=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
a6cf64dbb4c8d5fd19ce48896068db03b533a8d1336c6256a87d00cbb3def3ea
26. USERTrust RSA Certification AuthorityC=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
68b9c761219a5b1f0131784474665db61bbdb109e00f05ca9f74244ee5f5f52b
Whether directly or indirectly because of chaining these are currently in violation of the Mozilla Root Store Policy.
- Wayne