Google: Chrome will no longer trust Symantec certificates, 30% of the web will need to switch Certificate Authorities

Let’s Encrypt is an automated system which proves that you control the domain as part of the certificate-signing process.

By comparison, Symantec admits to having generated certificates for domains not controlled by those who requested or received the certificates. For example, signed certificates covering both “google.com” and “www.google.com” were generated by Symantec back in October 2015, not on behalf of Google.

(Symantec’s position on the above seems to be that these certificates were generated for testing purposes only, never made it out onto the Internet, were generated in violation of company policies, the employees who generated them have been terminated, and everything is hunky-dory again now so please everybody just put down your pitchforks and enjoy your certificates.)

3 Likes