Skip to main content

Google shares plan to distrust Symantec Certificates beginning with Chrome 66 in 2018

Over the years, Chrome has removed digital certificates from Authorities that it does not trust to guarantee security. Google today announced finalized plans to remove trust from certifications signed by Symantec due to security lapses that jeopardize the web’s system for identifying websites.

A Certificate Authority issues digital certificates that authenticate and ensure you are visiting a legitimate site as often denoted by the HTTPS lock.

Symantec’s questionable security decisions date back to 2015, but finally came to a head earlier this year. Due to various Symantec Certificate Authorities not following industry standards, as well as Symantec being aware of the flaws, the Chrome team lost “confidence in the trustworthiness of Symantec’s infrastructure, and as a result, the certificates that have been or will be issued from it.”

For its part, Symantec decided to transfer management to an “independently-operated Managed Partner Infrastructure” and sell its division to DigiCert, while rebuilding its infrastructure. Throughout this process, site operators need to take steps to replace their old Symantec certificates or face users encountering a warning.

After much debate in the community about the time frame to phase out the Symantec certificates, Google is widely sharing its plan. Beginning with version 66 set to hit the stable channel in April of 2018, Chrome will begin removing trust in Symantec-issued certificates prior to June 2016.

Meanwhile, as Symantec completes its transfer to DigiCert, certificates issued by the older Symantec infrastructure will no longer be trusted. Google ultimately plans to remove trust in the older certificates by October 2018 with the release of Chrome 70.


Check out 9to5Google on YouTube for more news:

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Google — experts who break news about Google and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Google on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Abner Li Abner Li

Editor-in-chief. Interested in the minutiae of Google and Alphabet. Tips/talk: abner@9to5g.com

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications