Notice of Intent to Approve eMudhra's Root Inclusion Request

255 views
Skip to first unread message

Ben Wilson

unread,
Oct 2, 2026, 3:57:59 PM (8 days ago) Oct 2
to dev-secur...@mozilla.org
All,

Public discussion regarding inclusion of the following eMudhra root CA certificates concluded on the CCADB Public list on September 21, 2026:

  • emSign Root SMIME CA - G1
  • emSign Root SMIME CA - G3
  • emSign Root TLS CA - G1
  • emSign Root TLS CA - G3

See https://groups.google.com/a/ccadb.org/g/public/c/xXOcxhZHmuk/m/pAsNrrfVAgAJ

Additional details concerning eMudhra's request may be found in the above-referenced discussion, in Bugzilla Case #1889859, and in CCADB Case No. 1777.

Mozilla's root inclusion process is outlined here: 

https://wiki.mozilla.org/CA/Application_Process#Process_Overview

Additional information about application review may be found here:

https://wiki.mozilla.org/CA/Application_Verification

This notice states Mozilla's intent to approve eMudhra's root inclusion request. This begins a 7-day “last call” period ending on October 9, 2026, for any final objections.

Thanks,

Ben

Mike Shaver

unread,
Oct 2, 2026, 6:29:21 PM (8 days ago) Oct 2
to Ben Wilson, dev-secur...@mozilla.org
I think this is a good example of where an overview of relevant incidents would be helpful for community members determining whether or not inclusion is appropriate.

I have not been particularly impressed by eMudhra’s performance in recent incidents, but I also have not followed all of them, so an ideally-non-AI summary of the full set would be welcome.

How could we make that happen?

Mike

--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtaYcxp3-zPJ9s9JpcNdfLdHO9AGAzZj7VDJgTNnO37cO%2BQ%40mail.gmail.com.

Ben Wilson

unread,
Oct 5, 2026, 12:23:45 PM (6 days ago) Oct 5
to Mike Shaver, dev-secur...@mozilla.org

Hi Mike,

Thanks for your suggestions. As noted in my response regarding GoDaddy, the CCADB Public discussion kickoff emails already link to the CA’s incident history. We could consider ways to make that information easier for community reviewers to navigate, although I don’t have the capacity to prepare detailed incident summaries for each inclusion request.

Regarding AI, I think accuracy, verification against the underlying record, and human accountability are the key considerations, regardless of the tools used.

I’ll raise your suggestions with the root store operators participating in the CCADB public discussions so we can consider practical improvements to the process.

Thanks again,
Ben


Reply all
Reply to author
Forward
0 new messages