Google Chrome will banish Chinese certificate authority for breach of trust [Updated]
Draconian move follows the issuance of certificates masquerading as Google domains. — Google's Chrome browser will stop trusting all digital certificates issued by the China Internet Network Information …
Context & Ripple Effects
The CNNIC distrust is the opening move in what becomes Chrome's pattern of policing certificate authorities directly. Within months of this banishment, Google issues an ultimatum to Symantec over misissued google.com certificates — account for them or have TLS certs flagged as unsafe — escalating from a single state-affiliated CA to the industry's largest commercial issuer.
The pattern then hardens into policy: Chrome strips extended-validation status from Symantec certificates outright before moving to full distrust, and separately plans complete distrust of WoSign and StartCom in Chrome 61. By September 2017 Google publishes its formal schedule to remove all Symantec-issued certificates starting with Chrome 66, making clear that misissuance now carries an existential penalty rather than a negotiated fix.
First-order effects
- Sites running CNNIC-issued certificates lose browser trust in Chrome immediately, forcing Chinese web operators onto other CAs or off Chrome entirely.
- Symantec, whose own misissued google.com certificates triggered Google's ultimatum, now faces a precedent where a single breach of issuance discipline can end a CA's browser trust.
Second-order effects
- Rival certificate authorities inherit displaced CNNIC customers but also inherit the standard Google just set — every issuer's audit practices become subject to Chrome unilateral review.
- Enterprises relying on EV certificates watch Chrome's willingness to nullify valid certs overnight, raising the cost of depending on any single CA's long-term validity.
Third-order effects
- If the sequence holds — CNNIC, then Symantec, then WoSign/StartCom — browser vendors replace industry self-governance as the de facto regulators of web trust, with Chrome's user share functioning as enforcement power no CA forum possesses.
The trend: Certificate authority oversight is shifting from consensus bodies like the CA/Browser Forum to unilateral enforcement by dominant browsers, with Chrome's distrust actions setting the penalty structure for misissuance.