/00 — boot sequence

Hello.

Article

Mozilla Root Store Policy 2.9: Key Changes and Developer Impact

July 3, 2026•4 min read
Mozilla Root Store Policy MRSP Certificate Authority TLS S/MIME SHA-1 CCADB PKI security root certificate

For developers managing certificate infrastructure or building applications that rely on trusted root certificates, changes to Mozilla's Root Store Policy (MRSP) can have ripple effects on everything from TLS handshake behavior to email encryption workflows. Version 2.9 of the MRSP, published on September 13, 2023, introduces several important updates that aim to tighten security, streamline compliance, and phase out outdated cryptography.

Let's break down what's new and why it matters for the developer community.

Root CA Certificate Lifetimes Now Capped

Historically, root Certificate Authority (CA) certificates could have validity periods of 25 years or more. With rapid advances in computing power, such long-lived keys become increasingly vulnerable to cryptanalytic attacks. The new section 7.4 of the MRSP addresses this by enforcing a practical lifespan:

  • Website (TLS) trust bit removal occurs when the CA key material reaches 15 years of age.
  • Email (S/MIME) trust bit receives a "Distrust for S/MIME After Date" set at 18 years from key generation.

A transition schedule (detailed in the Mozilla wiki) phases in these limits for root certificates created before April 14, 2014. For developers, this means:

  • If you manage your own CA, you'll need to plan for key rotation and certificate re-issuance before these deadlines.
  • Applications that hardcode trust anchors may need updates to reflect removed trust bits.
  • Monitoring tools should watch for upcoming trust bit removals to avoid service disruptions.

Mandatory S/MIME Baseline Requirements

With the CA/Browser Forum's Baseline Requirements for S/MIME certificates taking effect on September 1, 2023, the MRSP now mandates full compliance (section 2.3). This affects any developer:

  • Using S/MIME for email signing or encryption.
  • Building applications that validate S/MIME certificates.
  • Operating a CA that issues S/MIME certificates.

Period-of-time audits to confirm compliance are required for audit periods ending after October 30, 2023. Transition guidance is available on Mozilla's wiki. Expect stricter validation of organization identity and key usage extensions in S/MIME paths.

Security Incident and Vulnerability Disclosure

A new section 2.4 adds clear procedures for reporting security incidents and serious vulnerabilities affecting CAs. This is a direct call for developers and CA operators to:

  • Establish internal incident response processes aligned with Mozilla's expectations.
  • Use the designated Mozilla wiki for disclosure rather than ad-hoc communication.
  • Ensure timely reporting to maintain trustworthiness in the root store.

If you maintain a CA in Mozilla's program, review the vulnerability disclosure page and update your security policies accordingly.

Annual CCADB Self-Assessment Now Mandatory (Starting January 2024)

Previously, CAs were required to perform an annual self-assessment but not necessarily submit it. The MRSP 2.9 changes that: beginning January 2024, CA operators with website trust bits enabled must complete and submit the CCADB Compliance Self-Assessment within 92 calendar days after their audit period ends.

This increased transparency means:

  • Developers can verify a CA's compliance status via CCADB.
  • CAs must keep meticulous records of their practices and be ready to demonstrate conformance.
  • Non-submission can lead to trust bit removal.

Final Nail in the Coffin for SHA-1

SHA-1 has been deprecated for TLS since 2017, but version 2.9 takes further steps to root out any remaining usage. Under the new policy, SHA-1 is permitted only for:

  • End-entity certificates that are completely outside the MRSP scope.
  • Very specific, limited circumstances like duplicating an existing SHA-1 intermediate CA certificate.

Any other use of SHA-1 in certificates affecting Mozilla trust store is now prohibited. For developers, this means:

  • Audit your internal CAs for any SHA-1 intermediates or end-entity certs.
  • Ensure all CI/CD pipelines and internal PKI use SHA-256 or stronger.
  • Libraries that validate certificate chains should reject SHA-1 signatures (except in the narrow exceptions above).

Key Takeaways

  • Root CA key lifetimes are now capped at 15 years (TLS) and 18 years (S/MIME), with phased transition for older keys.
  • S/MIME certificates must comply with CA/B Forum Baseline Requirements; audits start October 2023.
  • Security incident reporting is formalized in the policy—CA operators must have a disclosure process.
  • Annual compliance self-assessments become mandatory and must be submitted to CCADB from January 2024.
  • SHA-1 is essentially banned except for narrow, documented exceptions.

Conclusion

Mozilla's MRSP 2.9 represents a forward-looking tightening of security baselines for the entire web PKI. For developers, the immediate actions include reviewing CA key ages, ensuring S/MIME certificate compliance, establishing incident disclosure workflows, and purging SHA-1 from your certificate chains. These changes may require updates to tooling, monitoring, and internal processes, but they ultimately strengthen the ecosystem for everyone.

Engage with the Mozilla dev-security-policy community and CCADB to stay informed and contribute to a safer internet.


Source: Version 2.9 of the Mozilla Root Store Policy

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links