Skip to main content

Why is Sectigo's AAA Certificate Services root certificate no longer issuing certificates?

This is due to policy adjustments implemented by the Mozilla and Chrome root programs.

Starting April 15, 2025, the trust bit for TLS certificates associated with the AAA Certificate Services root CA is omitted in subsequent versions. These policy changes limit the validity period of root CA certificates to a maximum of 15 years after private key generation, aimed at strengthening security measures and improving flexibility.

The AAA Certificate Services root CA is included in the initial batch of affected root certificates. Certificates issued by subordinate CAs directly chained to this root will no longer be trusted in new versions of Firefox, NSS, and Chrome released after April 15, 2025.