Notice of Intent to Approve GoDaddy's Root Inclusion Request

249 views
Skip to first unread message

Ben Wilson

unread,
Oct 2, 2026, 4:07:26 PM (6 days ago) Oct 2
to dev-secur...@mozilla.org

All,

Public discussion regarding inclusion of the following GoDaddy root CA certificates concluded on the CCADB Public list on September 29, 2026:

·       Starfield TLS Root CA - R1

·       GoDaddy TLS Root CA - R1

See https://groups.google.com/a/ccadb.org/g/public/c/6hPxKjObVlc/m/WNaT8eINGwAJ

Additional details concerning GoDaddy's request may be found in the above-referenced discussion, in Bugzilla Case  #2035858, and in CCADB Case No. 3059.

Mozilla's root inclusion process is outlined here: 

https://wiki.mozilla.org/CA/Application_Process#Process_Overview

Additional information about application review may be found here:

https://wiki.mozilla.org/CA/Application_Verification

This notice states Mozilla's intent to approve GoDaddy's root inclusion request. This begins a 7-day “last call” period ending on October 9, 2026, for any final objections.

Thanks,

Ben

Wayne

unread,
Oct 2, 2026, 4:16:19 PM (6 days ago) Oct 2
to dev-secur...@mozilla.org
I'm not sure how we can make an informed decision when GoDaddy's updated CPS is due October 9th: https://bugzilla.mozilla.org/show_bug.cgi?id=2035858#c7

There was significant feedback gave almost two months ago with no visible change yet: https://bugzilla.mozilla.org/show_bug.cgi?id=2035858#c3

- Wayne

Ben Wilson

unread,
Oct 2, 2026, 4:25:19 PM (6 days ago) Oct 2
to Wayne, dev-secur...@mozilla.org
Thanks.

We’ll treat this objection as a request to extend the review period. Any approval will be deferred until at least seven days after GoDaddy submits its updated CPS, allowing time to review the changes and raise any remaining concerns.

Ben


--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/4d8fb7e4-1d30-4501-a18b-3ae71865ada8n%40mozilla.org.

Mike Shaver

unread,
Oct 2, 2026, 5:40:47 PM (6 days ago) Oct 2
to Ben Wilson, dev-secur...@mozilla.org
Hi Ben,

I think it would be helpful if, for (re)inclusion requests, that the discussion kickoff email contained a list of the relevant CA’s incidents since the last such request (if any) — especially if there are unresolved incidents. (unresolved incidents shouldn’t inherently block an inclusion request, of course, but one assumes a CA to be on their best behaviour when requesting root inclusion, so their handling of contemporary incidents could be quite informative.)

Mike

--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.

Ben Wilson

unread,
Oct 5, 2026, 12:10:44 PM (3 days ago) Oct 5
to Mike Shaver, dev-secur...@mozilla.org

Hi Mike,

Thanks for your suggestions. The CCADB Public discussion kickoff email already links to the CA’s incident history, but we could improve how we present that information to community reviewers. We’re taking your suggestions under advisement, and I’ll raise them with the root store operators participating in the CCADB public discussions so we can consider how best to incorporate them into the process.

Thanks again,

Ben

Reply all
Reply to author
Forward
0 new messages