Sustaining Digital Certificate... Note

Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store

Google Chrome has announced the removal of default trust of Chunghwa Telecom and Netlock due to patterns of concerning behavior observed over the past year. The Chrome Root Program Policy requires Certification Authority certificates to provide value to Chrome end users that exceeds the risk of their continued inclusion. Chrome's confidence in the reliability of Chunghwa Telecom and Netlock as CA Owners has diminished, leading to a loss of integrity and trust. As a result, Chrome will no longer trust new TLS certificates issued by these CAs starting from August 1, 2025, in versions 139 and higher. This change will affect certificates issued after July 31, 2025, but will not impact existing certificates issued before this date. Website operators can determine if they are affected by using the Chrome Certificate Viewer and are recommended to transition to a new publicly-trusted CA Owner as soon as possible. To minimize disruption, Chrome has introduced a command-line flag that allows administrators and power users to simulate the effect of the change before it takes effect. Enterprises can override Chrome Root Store constraints by installing the corresponding root CA certificate as a locally-trusted root on the platform Chrome is running. The change will occur in versions of Chrome 139 and greater on Windows, macOS, ChromeOS, Android, and Linux, but will not affect Chrome for iOS due to Apple policies. Overall, the goal of this change is to safeguard Chrome users and preserve the integrity of the Chrome Root Store by ensuring that only trusted and reliable CA Owners are included.