Google details plan to distrust Symantec-issued certificates starting with Chrome 66 in 2018
This post is a broader announcement of plans already finalized on the blink-dev mailing list. — At the end of July, the Chrome team and the PKI community converged upon a plan to reduce …
Context & Ripple Effects
This announcement closes a two-year escalation between Google and Symantec. It began when Google demanded a full accounting of misissued google.com certificates under threat of flagging Symantec's TLS output as unsafe, then escalated in March when Chrome stopped recognizing the extended-validation status of Symantec-issued certificates outright.
The July convergence on blink-dev set the terms, and this post formalizes them: a staged nullification of currently valid Symantec-owned CA certificates culminating in Chrome 66. Coming weeks after Google moved to distrust WoSign and StartCom in Chrome 61 for its own misissuance record, it confirms distrust is no longer a last resort but a standard enforcement tool.
First-order effects
- Every site operator running a Symantec-owned certificate faces forced replacement on a Chrome-published timeline or visible connection warnings for Chrome users once Chrome 66 ships.
- Symantec's certificate business loses its distribution channel in the world's largest browser, converting a trust dispute into an immediate revenue problem.
Second-order effects
- Competing certificate authorities become the default landing spot for Symantec's displaced customer base, and replacement volume shifts pricing power toward CAs with clean audit records.
- Other browser vendors face pressure to match Chrome's timeline, since a fragmented distrust schedule would leave Symantec certs trusted in Firefox or Edge but broken in Chrome — an untenable position for large deployers.
Third-order effects
- If the pattern holds — WoSign, StartCom, now Symantec — browser vendors, not the CA/Browser Forum process, become the effective regulators of web trust, with misissuance punished by market exclusion rather than negotiated remediation.
- The certificate authority market structurally consolidates around a small set of high-compliance issuers, raising the barrier that keeps new entrants viable and making any single CA failure a systemic event rather than a contained one.
The trend: Browser vendors are replacing industry-consensus governance of the web's public key infrastructure with unilateral, escalating distrust as their primary enforcement mechanism.