Apple's decision in Feb. to limit HTTPS certs' lifespan to 398 days in Safari has been mimicked by Chrome and Firefox to the dismay of Certificate Authorities
Apple, Google, and Mozilla reduce the lifespan for HTTPS certificates to 398 days, against the wishes of Certificate Authorities.
Context & Ripple Effects
When Safari announced it would stop accepting new certificates valid beyond 398 days starting September 1 — down from 825 — it looked like a unilateral browser-vendor move. With Chrome and Firefox now adopting the same limit, it has become a coordinated industry standard imposed on Certificate Authorities without a CA/Browser Forum ballot.
This continues a pattern established years earlier, when Google moved to distrust all Symantec-issued certs beginning with Chrome 66 after the extended-validation revocation episode, showing that browser makers will act unilaterally when they judge CAs' practices insufficiently rigorous.
First-order effects
- Certificate Authorities lose the ability to sell multi-year certificates (up to 825 days) to website operators from September 1, forcing shorter renewal cycles across their entire customer base.
- Website administrators face more frequent renewal and deployment cycles for TLS certificates on Chrome, Firefox, and Safari alike.
Second-order effects
- CAs' recurring-revenue models shift toward automation: shorter lifespans push buyers toward ACME-style automated issuance and management tools, favoring CAs and vendors that can deliver hands-free renewals over those selling long-dated manual certificates.
- Browser vendors gain further precedent for setting policy by fiat; the same coalition later demonstrated its reach by jointly banning Kazakhstan's government root certificate used to intercept HTTPS traffic (the four-browser ban) rather than routing disputes through formal bodies.
Third-order effects
- If the pattern holds, trust decisions for the web effectively migrate from the CA/Browser Forum's consensus process to whatever Apple, Google, Microsoft, and Mozilla agree among themselves — making browser market share, not CA accreditation, the real seat of authority over web encryption.
- Certificate economics compress toward high-volume, low-margin automated issuance, consolidating the CA industry around players who can operate at scale.
The trend: Web PKI governance is steadily shifting from industry-standard-setting bodies to the major browser vendors acting as a de facto policy bloc.