New security requirements adop... Note

New security requirements adopted by HTTPS certificate industry

The Chrome Root Program, launched in 2022, aims to enhance secure network connections in Chrome by promoting technologies that strengthen TLS security. The program's vision, "Moving Forward, Together," focuses on themes like modern infrastructure, simplicity, automation, and reducing mis-issuance, all of which complement Chrome's core principles. Two "Moving Forward, Together" initiatives, Multi-Perspective Issuance Corroboration (MPIC) and linting, have become required practices in the CA/Browser Forum Baseline Requirements. MPIC enhances domain control validation by verifying requests from multiple geographic locations to mitigate routing attacks. Linting automates the analysis of X.509 certificates to prevent errors and ensure compliance with industry standards. Both MPIC and linting will be mandatory for CAs issuing publicly-trusted certificates starting March 15, 2025. The Chrome Root Program recently updated its policy to align with "Moving Forward, Together" goals. Weaker domain control validation methods will be prohibited beginning July 15, 2025. The program emphasizes ongoing collaboration with web security professionals to improve the Web PKI ecosystem. Future plans include exploring a reimagined Web PKI with stronger security assurances for the post-quantum cryptography era.