/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple's decision in Feb. to limit HTTPS certs' lifespan to 398 days in Safari has been mimicked by Chrome and Firefox to the dismay of Certificate Authorities

Apple, Google, and Mozilla reduce the lifespan for HTTPS certificates to 398 days, against the wishes of Certificate Authorities.

ZDNet Catalin Cimpanu

Context & Ripple Effects

When Safari announced it would stop accepting new certificates valid beyond 398 days starting September 1 — down from 825 — it looked like a unilateral browser-vendor move. With Chrome and Firefox now adopting the same limit, it has become a coordinated industry standard imposed on Certificate Authorities without a CA/Browser Forum ballot.

This continues a pattern established years earlier, when Google moved to distrust all Symantec-issued certs beginning with Chrome 66 after the extended-validation revocation episode, showing that browser makers will act unilaterally when they judge CAs' practices insufficiently rigorous.

First-order effects

  • Certificate Authorities lose the ability to sell multi-year certificates (up to 825 days) to website operators from September 1, forcing shorter renewal cycles across their entire customer base.
  • Website administrators face more frequent renewal and deployment cycles for TLS certificates on Chrome, Firefox, and Safari alike.

Second-order effects

  • CAs' recurring-revenue models shift toward automation: shorter lifespans push buyers toward ACME-style automated issuance and management tools, favoring CAs and vendors that can deliver hands-free renewals over those selling long-dated manual certificates.
  • Browser vendors gain further precedent for setting policy by fiat; the same coalition later demonstrated its reach by jointly banning Kazakhstan's government root certificate used to intercept HTTPS traffic (the four-browser ban) rather than routing disputes through formal bodies.

Third-order effects

  • If the pattern holds, trust decisions for the web effectively migrate from the CA/Browser Forum's consensus process to whatever Apple, Google, Microsoft, and Mozilla agree among themselves — making browser market share, not CA accreditation, the real seat of authority over web encryption.
  • Certificate economics compress toward high-volume, low-margin automated issuance, consolidating the CA industry around players who can operate at scale.

The trend: Web PKI governance is steadily shifting from industry-standard-setting bodies to the major browser vendors acting as a de facto policy bloc.

Discussion

  • @campuscodi Catalin Cimpanu on x
    NEW: Apple strong-armed entire CA industry into one-year certificate lifespans - Starting Sep 2020, TLS certs must have a validity period of 398 days - Mozilla & Google announced similar rules as well https://www.zdnet.com/... https://twitter.com/...
  • @worldwise001 Sarah on x
    strong-armed might be a harsh word here; the big reason for the reduction in validity period is because revocation is hard and folks have been talking about short-lived certs for at least half a decade. so tl;dr this is actually good news for everyone. https://twitter.com/...