Google Online Security Blog
Follow
Sustaining Digital Certificate Security - Entrust Certificate Distrust
- Chrome will distrust TLS certificates issued by Entrust and AffirmTrust CA roots dated after October 31, 2024.
- Chrome's action aims to preserve the integrity of the Web PKI ecosystem due to concerns about Entrust's compliance failures and lack of improvement.
- The change will affect Chrome 127 and higher on Windows, macOS, ChromeOS, Android, and Linux.
- Website operators using Entrust certificates should transition to a different CA to avoid user disruptions.
- Websites can check for impact using the Chrome Certificate Viewer.
- A command-line flag is available to simulate the distrust constraint for testing purposes.
- Enterprises can override the distrust by installing Entrust's root certificate as a locally-trusted root.
- The action will not impact certificates from other CAs.
- The change is scheduled to take effect on November 1, 2024.
- Other Google products may release their own updates in the future.
- The Chrome Root Program prioritizes security and expects CA owners to adhere to security expectations.