Sustaining Digital Certificate Security - Entrust Certificate Distrust
ID: 3e333624-bbd0-5216-be26-3d00c5eb5759
STIX ID: report--3e333624-bbd0-5216-be26-3d00c5eb5759
Feed Name: Google Online Security Blog
Google’s Chrome Security Team announced that starting with Chrome 131, TLS server certificates chaining to Entrust and AffirmTrust roots will no longer be trusted by default if their earliest SCT is after 2024-11-11 23:59:59 UTC, citing years of compliance failures and lack of measurable improvement. Affected users will see interstitial warnings; website operators should migrate to another publicly trusted CA before the cutoff or certificate expiry, can test impact using a dedicated command-line flag, and enterprises can override by installing the relevant roots as locally trusted on supported platforms (Windows, macOS, ChromeOS, Android, Linux; not iOS).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
