Google creates Google Trust Services to operate its own Root Certification Authority
In the support of our work to implement HTTPS across all of our products (https://www.google.com/transparencyrep ort/ https/) we have been operating our own subordinate Certificate Authority (GIAG2), issued by a third-party.
Context & Ripple Effects
This move caps a two-year campaign in which Google shifted from complaining about certificate authorities to policing them. After warning in March 2015 about unauthorized TLS certificates trusted by nearly every operating system, it gave Symantec an ultimatum over misissued google.com certificates — account for them or Chrome would flag Symantec's TLS certs as unsafe.
Until now Google's own HTTPS rollout ran on GIAG2, a subordinate authority issued by a third party. Creating Google Trust Services with its own root means the company enforcing CA standards no longer sits downstream of one.
First-order effects
- Google's HTTPS-everywhere program now runs on a root it controls end-to-end, removing dependence on third-party issuers whose missteps it has repeatedly had to punish.
- Commercial CAs lose one of the web's largest certificate consumers as a customer, while gaining it as a direct competitor at the root level.
Second-order effects
- The distrust lever gets sharper: once Google issues its own roots, threats like the planned distrust of Symantec certificates starting with Chrome 66 or the WoSign and StartCom removal in Chrome 61 cost Google less operationally, since its own properties no longer depend on the CAs it removes.
- Other large HTTPS operators face pressure to follow suit or accept that their encryption chain is governed by a rival's revocation decisions.
Third-order effects
- If platform companies keep vertically integrating into trust infrastructure, the CA industry restructures around browser vendors as de facto regulators — the entities that decide which roots survive are increasingly the ones issuing their own.
- That concentration raises an unresolved governance question: who audits the auditor when the enforcer of certificate standards is itself a root operator.
The trend: Web trust infrastructure is consolidating under platform operators that both issue certificates and control the browsers deciding which roots to trust.