Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
ID: edf5851c-d053-53d9-874f-32314b5a3b7f
STIX ID: report--edf5851c-d053-53d9-874f-32314b5a3b7f
Feed Name: Google Online Security Blog
Google Chrome will remove default trust for new TLS certificates chaining to Chunghwa Telecom (ePKI Root CA, HiPKI Root CA - G1) and Netlock (Arany/Class Gold) with earliest SCTs after July 31, 2025, beginning in Chrome 139, due to persistent compliance and integrity concerns. Affected site operators should migrate to another publicly trusted CA before the cutoff or certificate expiry; users will see interstitials for impacted sites, enterprises can locally trust these roots to override, and admins can pre-test the change using the SCTNotAfter command-line flag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
