Following years of documented mis-issuance incidents by Symantec (then one of the largest CAs, having acquired VeriSign's certificate business), Google announced in 2017 a phased plan to distrust Symantec-issued certificates across Chrome — one of the largest CA distrust actions in browser history, given Symantec's scale.
How the phase-out worked
Rather than an immediate cutoff, Chrome implemented a gradual reduction in trust duration for existing Symantec certificates, giving site owners a defined migration window to obtain replacement certificates from a different CA — DigiCert ultimately acquired Symantec's certificate business partway through this process and managed the technical transition for affected customers.
Why it mattered industry-wide
The scale of the Symantec distrust — affecting a meaningful share of the web's certificates at the time — demonstrated concretely that even a very large, established CA isn't immune to losing browser trust if repeated issuance problems go unaddressed, reinforcing the CA/Browser Forum's compliance requirements as genuinely enforceable rather than largely theoretical.
Which specific brands were affected beyond the Symantec name itself
Because Symantec's certificate business had grown partly through acquiring other established CAs over the years, including GeoTrust, Thawte, and RapidSSL, the distrust affected certificates issued under all of these brand names, not just ones explicitly labeled Symantec, which caused genuine confusion for site owners who didn't realize their GeoTrust or Thawte certificate was actually part of the affected infrastructure.
How DigiCert managed the technical transition after acquiring the business
DigiCert's acquisition included migrating the underlying issuance and validation infrastructure to DigiCert's own systems over a defined transition period, while initially preserving the legacy brand names for continuity — customers with existing Symantec-lineage certificates were generally offered free reissuance onto DigiCert's genuinely new infrastructure well ahead of the final browser-imposed distrust deadlines.
How affected organizations discovered whether they were impacted
Many affected organizations first learned about the issue through direct communication from Symantec or DigiCert, industry news coverage, or by running their existing certificates through updated SSL scan tools that had begun flagging Symantec-lineage certificates specifically — the distributed, sometimes indirect nature of this discovery process contributed to some organizations missing early migration windows.
Lasting changes to how Google specifically evaluates CA trustworthiness
Following the Symantec episode, Google's own public communications about CA trust decisions became notably more detailed and technical, publishing specific timelines, evidence, and reasoning for proposed distrust actions — a transparency practice that's continued in subsequent, smaller CA trust discussions since, setting a higher bar for how browser vendors publicly justify trust decisions.
Where to check if this history still affects any certificate you manage
Running any older certificate through a current SSL scan tool will immediately flag a Symantec-lineage issuer if one remains in the chain — a quick, low-effort way to confirm this specific historical episode has no remaining relevance to your current infrastructure.
How this episode is now taught as a case study in enterprise vendor risk management
Beyond its specific certificate-industry context, the Symantec distrust has become a frequently cited case study in broader enterprise risk management and vendor-concentration discussions, illustrating concretely how depending heavily on a single vendor relationship for critical infrastructure, even one as seemingly stable and established as a major, long-standing CA, carries genuine, sometimes underappreciated continuity risk.
A final industry-wide takeaway from the episode
The Symantec case ultimately reinforced, at a scale and visibility no smaller incident could have, that browser vendor trust decisions are genuinely consequential and enforceable even against the largest incumbents — a lesson that continues to shape how every CA, regardless of size or market position, approaches its own compliance and transparency practices today.
The Symantec episode remains the clearest large-scale demonstration that browser vendor trust decisions carry real, enforceable consequences.