Chrome to immediately stop recognizing extended validation status of Symantec-issued certs and gradually nullify all currently valid certs of Symantec-owned CAs
Chrome to immediately stop recognizing EV status and gradually nullify all certs. — In a severe rebuke of one of the biggest suppliers …
Context & Ripple Effects
This is the escalation of a two-year standoff. In October 2015, Google gave Symantec an ultimatum to fully account for misissued google.com certificates or see its TLS certificates flagged as unsafe in Chrome — and Symantec, one of the biggest suppliers of certificates, evidently did not satisfy the browser maker.
The move also fits a pattern: Chrome had already banished a Chinese certificate authority for breach of trust in 2015, and would go on to fully distrust WoSign and StartCom in Chrome 61 before distrusting Symantec-issued certificates starting with Chrome 66 in 2018. What changes here is severity — Symantec isn't just being warned, its extended validation status is stripped immediately and every currently valid cert it issued is on a path to nullification.
First-order effects
- Symantec loses the extended-validation green-bar distinction in Chrome overnight, erasing the premium value proposition it sells enterprise customers who pay extra for EV certificates.
- Every organization running a currently valid Symantec-owned CA certificate now faces forced migration to a new certificate authority or broken TLS in Chrome as the gradual nullification proceeds.
Second-order effects
- Symantec's certificate revenue base is exposed to flight toward rival CAs, since buyers cannot risk a vendor whose certs Chrome has scheduled for nullification.
- Other browser vendors are effectively forced to decide whether to follow Chrome's distrust schedule or accept fragmentation in which sites show as trusted in some browsers and untrusted in others.
Third-order effects
- Browser makers are consolidating de facto regulatory power over the certificate authority ecosystem — with Symantec, a Chinese CA, and WoSign/StartCom all removed by Google's unilateral decisions, formal CA oversight bodies are being superseded by whatever Chrome decides to trust.
- If the pattern holds, certificate authorities become disposable infrastructure whose survival depends on browser goodwill rather than audit compliance alone, reshaping how enterprises evaluate long-term PKI vendors.
The trend: Browser vendors, led by Chrome, are replacing traditional oversight bodies as the real enforcers of trust in the web's certificate authority system.