Firefox 136.0.2 Update: Mozilla's New Requirements for Certificate Authorities

A fix release of Firefox 136.0.2 is available that fixes several issues:

  • Fixed a bug that caused options to be enabled to delete cookies, site data, and page cache contents after upgrading to Firefox 136 if the options to clear browsing history or site settings during shutdown were previously enabled in the settings.
  • Fixed an issue where the master password prompt was displayed in situations where it was not required.
  • Fixed issues with displaying radio buttons in web forms on pages with a dark background.
  • Resolved a Windows-specific issue that caused high CPU usage when locking the screen or closing the laptop lid.

Additionally, it is worth noting the publication of the third version of the Mozilla Root Store Policy (MRSP). The changes came into effect on March 15 and are aimed at solving problems with delays in certificate revocation by certification authorities. New requirements have been added to ensure prompt revocation of certificates, the ability to obtain a deferment of certificate revocation in certain situations has been removed, and the conditions for tracking the life cycle of private keys have been expanded.

In addition, a clause has been added that abolishes dual-use root certificates that have trust parameters set for both website and mail certificates (separation of certificate hierarchies for TLS and S/MIME). Certification authorities that already use such root certificates must submit a plan for transitioning to separate hierarchies by April 15, 2026, and complete the migration by December 31, 2028.

Source: opennet.ru