Chrome to immediately stop recognizing extended validation status of Symantec-issued certs and gradually nullify all currently valid certs of Symantec-owned CAs
Chrome to immediately stop recognizing EV status and gradually nullify all certs. — In a severe rebuke of one of the biggest suppliers …
Context & Ripple Effects
This is the escalation of a two-year standoff. In October 2015, Google gave Symantec an ultimatum to fully account for misissued google.com certificates or see Chrome flag its TLS certificates as unsafe — and Symantec-owned CAs kept issuing through 2017. The move also follows Chrome's banishment of the Chinese certificate authority over a breach of trust in 2015 and Google's plan to completely distrust WoSign and StartCom with Chrome 61.
What changes now is severity and speed: rather than warning or flagging, Chrome immediately strips extended validation status from every Symantec-issued cert and begins nullifying all currently valid ones — trust is being revoked retroactively, not just withheld going forward.
First-order effects
- Every site operator running a Symantec-issued certificate loses EV treatment in Chrome today and faces forced reissuance from another CA as the gradual nullification proceeds.
- Symantec's certificate business — one of the biggest suppliers of TLS certs — sees its inventory of valid credentials converted into liabilities inside the world's dominant browser.
Second-order effects
- Rival certificate authorities absorb displaced Symantec customers, and surviving CAs now operate knowing Chrome has demonstrated it will nullify valid certs wholesale, raising the compliance bar for everyone.
- Symantec's path forward runs through accepting external oversight or exiting the CA business entirely, since Google's September follow-up plan to distrust Symantec certs starting with Chrome 66 shows the pressure does not relent after this announcement.
Third-order effects
- Browser vendors are consolidating de facto regulatory authority over web PKI: a single vendor's release schedule can now determine whether a major CA's entire output is trusted, making CA survival contingent on browser-maker approval rather than audit bodies alone.
- If the pattern holds — CNNIC, WoSign/StartCom, now Symantec — the CA market structurally consolidates toward a small set of issuers that can satisfy Chrome's enforcement cadence, and 'validly issued' ceases to guarantee continued recognition.
The trend: Chrome is converting certificate-authority trust from a permanent grant into a revocable privilege enforced unilaterally by browser release cycles.