www.mozilla.org has stopped using an EV certificate, so the root we need to use has changed. Ideally we might pin to something that will necessarily have a stable root certificate over time, such as https://extended-validation.badssl.com.