/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Safari will reportedly no longer accept new HTTPS certificates that are valid for more than 398 days beginning on September 1, down from 825 days

Keep your crypto below 398 days after September 1 and you're all good  —  Safari will, later this year, no longer accept new HTTPS certificates …

The Register Shaun Nichols

Context & Ripple Effects

Apple is shortening the maximum lifetime of new HTTPS certificates that Safari will accept to 398 days, down from 825, effective September 1. The move extends a pattern of browser vendors acting unilaterally on certificate policy: Google previously used Chrome's market position to strip trust from an entire CA in its distrust of Symantec-issued certificates, then enforced public Certificate Transparency logging with full-page warnings.

Within months of Apple's announcement, Chrome and Firefox adopted the same 398-day cap, leaving Certificate Authorities facing a de facto industry standard set by browser root programs rather than by any standards body.

First-order effects

  • Certificate Authorities must issue new certificates valid for no more than 398 days or see them rejected by Safari — and, following the mimicry, by Chrome and Firefox as well.
  • Site operators face roughly twice-as-frequent certificate renewals, since existing long-lived certs keep working but every new issuance falls under the cap.

Second-order effects

  • CAs that built revenue around multi-year certificate sales lose that product tier, pushing them toward automated issuance and renewal tooling to make frequent reissuance tolerable for customers.
  • Websites that still renew manually face higher operational risk of lapsed certificates and browser warnings, tilting hosting platforms and CDNs that automate renewal into a competitive advantage.

Third-order effects

  • If the pattern holds, browser root programs — not CA/Browser Forum consensus — become the binding regulator of the web's PKI, with each vendor able to impose policy unilaterally as Chrome did against Symantec and Apple has now done on lifetimes.
  • Shorter-lived certificates push the ecosystem toward continuous, automated validation of identity, eroding the one-time-purchase certificate model that commercial CAs were built on.

The trend: Browser vendors are converting their root stores into the web's de facto certificate authority regulator, imposing security policy unilaterally faster than standards bodies can.

Discussion

  • @near_nyan Near on x
    The entire personal web hosting world is slowly being eaten alive. As this number keeps dropping, every single site will become dependent on Let's Encrypt. And when it folds or certbot gets compromised ... https://www.theregister.co.uk/ ...
  • @jeremiahg Jeremiah Grossman on x
    Apple decided that Safari will invalidate TLS certs after 398 days, and ‘Asset Inventory’ becomes just that much more important. Gonna have to locate and monitor TLS websites just that much more closely. https://www.digicert.com/...
  • @techjournalist Sean Kerner on x
    Good thing the default on @letsencrypt is 90 days then.. @TechmemeChatter https://twitter.com/...
  • @hntweets @hntweets on x
    Safari will no longer trust certs valid for more than 13 months: https://www.theregister.co.uk/ ... Comments: https://news.ycombinator.com/ ...
  • @theregister @theregister on x
    Heads up: If you renew or create an HTTPS certificate after September 1, and the cert is valid for more than 13 months, Safari on a billion-plus iPhones, iPads, and Macs will reject it (Unless Apple changes its mind) https://www.theregister.co.uk/ ...