Safari will reportedly no longer accept new HTTPS certificates that are valid for more than 398 days beginning on September 1, down from 825 days
Keep your crypto below 398 days after September 1 and you're all good — Safari will, later this year, no longer accept new HTTPS certificates …
Context & Ripple Effects
Apple is shortening the maximum lifetime of new HTTPS certificates that Safari will accept to 398 days, down from 825, effective September 1. The move extends a pattern of browser vendors acting unilaterally on certificate policy: Google previously used Chrome's market position to strip trust from an entire CA in its distrust of Symantec-issued certificates, then enforced public Certificate Transparency logging with full-page warnings.
Within months of Apple's announcement, Chrome and Firefox adopted the same 398-day cap, leaving Certificate Authorities facing a de facto industry standard set by browser root programs rather than by any standards body.
First-order effects
- Certificate Authorities must issue new certificates valid for no more than 398 days or see them rejected by Safari — and, following the mimicry, by Chrome and Firefox as well.
- Site operators face roughly twice-as-frequent certificate renewals, since existing long-lived certs keep working but every new issuance falls under the cap.
Second-order effects
- CAs that built revenue around multi-year certificate sales lose that product tier, pushing them toward automated issuance and renewal tooling to make frequent reissuance tolerable for customers.
- Websites that still renew manually face higher operational risk of lapsed certificates and browser warnings, tilting hosting platforms and CDNs that automate renewal into a competitive advantage.
Third-order effects
- If the pattern holds, browser root programs — not CA/Browser Forum consensus — become the binding regulator of the web's PKI, with each vendor able to impose policy unilaterally as Chrome did against Symantec and Apple has now done on lifetimes.
- Shorter-lived certificates push the ecosystem toward continuous, automated validation of identity, eroding the one-time-purchase certificate model that commercial CAs were built on.
The trend: Browser vendors are converting their root stores into the web's de facto certificate authority regulator, imposing security policy unilaterally faster than standards bodies can.