logo

How to Detect Issuer Certificates and Comply with Google Chrome’s New Entrust Certificate Policy Using Qualys Certificate View

ID: 71f675d2-f7ef-507c-96ca-b9743f802b52

STIX ID: report--71f675d2-f7ef-507c-96ca-b9743f802b52

Feed Name: Qualys Blog

Date Published: 2024-07-12

Date Updated: 2026-04-28

Author: Russ Sanderlin

...
...

Google announced that Chrome 127+ will distrust certain Entrust and AffirmTrust TLS certificates issued after October 31, 2024, prompting security warnings and potential service disruption unless impacted certificates are replaced; certificates issued on or before that date remain valid until expiry. The report advises urgent migration to a trusted CA and highlights how Qualys Certificate View can inventory and flag affected certs (e.g., via `certificate:(browserDistrust:potential)`), monitor expirations, and streamline renewal/deployment, with upcoming enhancements for root/intermediate visibility and ACME-based automation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.