Google Online Security Blog
Follow
HTTPS certificate industry phasing out less secure domain validation methods
The Chrome Root Program and the CA/Browser Forum have implemented new security requirements for HTTPS certificate issuers to create a more secure internet. These initiatives aim to retire outdated Domain Control Validation methods that rely on weaker verification signals, such as physical mail, phone calls, or emails. The deprecation of these methods will be phased in, with full security value realized by March 2028, allowing website operators to transition smoothly. Domain Control Validation is a security-critical process that ensures certificates are only issued to the legitimate domain operator, preventing unauthorized entities from obtaining a certificate. The process involves a Certification Authority verifying that the requestor controls the domain, often through challenge-response mechanisms. Historically, other methods validated control through indirect means, which have been proven vulnerable to attacks. The recently passed CA/Browser Forum Server Certificate Working Group Ballots introduce a phased sunset of weaker Domain Control Validation methods, replacing them with robust, automated alternatives. The sunsetted methods include those relying on email, phone, and reverse lookup, which will be replaced by standardized, modern, and auditable methods. These changes will make it harder for attackers to trick a CA into issuing a certificate for a domain they don't control, reducing the risk of stale or indirect signals being abused. The ultimate goal of these initiatives is to create a safer browsing experience for everyone by removing weak links in how trust is established on the internet.