Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1
Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … Read more The post Improving Transparency and Assurance in the Web PKI: Mozilla Root Store
Executive Summary
Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … Read more
The post Improving Transparency and Assurance in the Web PKI: Mozilla Root Store
Technical Context
Modern web infrastructure requires continuous validation of certificate lifecycle states. Industry requirements from Apple, Google, and the CA/Browser Forum continue to tighten TLS validation rules, root trust programs, and certificate lifespans.
Key Considerations for Infrastructure Teams
- Certificate Transparency Compliance: Verify that all issued certificates are logged in at least two independent CT logs to avoid browser rejection. - Automated Revocation Checking: Monitor OCSP responder availability and CRL distribution points. - Intermediate Chain Integrity: Confirm that complete intermediate bundles are delivered during the TLS handshake.Recommended Mitigation Steps
1. Audit active public endpoints for certificate expiration deadlines within the next 30 days. 2. Verify that automated renewal hooks (Certbot, cert-manager) reload web server configs upon renewal. 3. Configure real-time rogue certificate detection across your domain names.Are Your Certificates Protected from Unintended Revocations?
Scan your domain using our free SSL Checker to inspect chain integrity, cipher suites, and Certificate Transparency posture.