Public discussion regarding inclusion of the following eMudhra root CA certificates concluded on the CCADB Public list on September 21, 2026:
See https://groups.google.com/a/ccadb.org/g/public/c/xXOcxhZHmuk/m/pAsNrrfVAgAJ
Additional details concerning eMudhra's request may be found in the above-referenced discussion, in Bugzilla Case #1889859, and in CCADB Case No. 1777.
Mozilla's root inclusion process is outlined here:
https://wiki.mozilla.org/CA/Application_Process#Process_Overview
Additional information about application review may be found here:
https://wiki.mozilla.org/CA/Application_Verification
This notice states Mozilla's intent to approve eMudhra's root inclusion request. This begins a 7-day “last call” period ending on October 9, 2026, for any final objections.
Thanks,
Ben
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtaYcxp3-zPJ9s9JpcNdfLdHO9AGAzZj7VDJgTNnO37cO%2BQ%40mail.gmail.com.
Hi Mike,
Thanks for your suggestions. As noted in my response regarding GoDaddy, the CCADB Public discussion kickoff emails already link to the CA’s incident history. We could consider ways to make that information easier for community reviewers to navigate, although I don’t have the capacity to prepare detailed incident summaries for each inclusion request.
Regarding AI, I think accuracy, verification against the underlying record, and human accountability are the key considerations, regardless of the tools used.
I’ll raise your suggestions with the root store operators participating in the CCADB public discussions so we can consider practical improvements to the process.
Thanks again,
Ben