HTTPS certificate industry phasing out less secure domain validation methods
ID: 3c6a27f4-2c04-55b1-8cd1-130cee68c7b9
STIX ID: report--3c6a27f4-2c04-55b1-8cd1-130cee68c7b9
Feed Name: Google Online Security Blog
**Chrome Root Program** and the **CA/Browser Forum** have approved ballots SC-080, SC-090, and SC-091 to retire 11 legacy Domain Control Validation methods, replacing weaker email/phone/reverse-lookup practices with automated, cryptographically verifiable mechanisms (e.g., ACME) on a phased schedule culminating by March 2028, thereby strengthening HTTPS certificate issuance and reducing opportunities for attacker abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
