HARICA Revokes Hundreds of Thousands of Certificates Over Compliance Gaps
July 26, 2026 · Mozilla Bugzilla / public incident reports

HARICA Revokes Hundreds of Thousands of Certificates Over Compliance Gaps

Two separate CP/CPS violations — one involving the same clientAuth EKU issue rippling across the industry this year, another over a missing OCSP extension — forced back-to-back mass revocations.

HARICA Faces Scrutiny Over Certificates Issued to Sanctioned Russian Banks
July 17, 2026 · Mozilla Bugzilla / public incident report

HARICA Faces Scrutiny Over Certificates Issued to Sanctioned Russian Banks

A security researcher's Bugzilla report documented active certificates issued to EU-sanctioned entities including Sberbank and VTB — and HARICA initially declined to revoke them.

Chrome Begins Distrusting Public Certificates With the Client Authentication EKU
June 16, 2026 · Chrome Root Program

Chrome Begins Distrusting Public Certificates With the Client Authentication EKU

Chrome Root Program Policy v1.6 enforcement started June 15 — new public TLS certificates with both server and client authentication purposes are no longer trusted by default.

Let's Encrypt Commits to Merkle Tree Certificates for Post-Quantum Authentication
June 6, 2026 · Let's Encrypt

Let's Encrypt Commits to Merkle Tree Certificates for Post-Quantum Authentication

The world's largest certificate authority is targeting a late-2026 staging rollout for MTCs — the same post-quantum architecture Google and Cloudflare proposed earlier this year.

Let's Encrypt Launches Generation Y Root Hierarchy
May 14, 2026 · Let's Encrypt

Let's Encrypt Launches Generation Y Root Hierarchy

New roots, general availability for short-lived certificates, and the default classic ACME profile switching over — all landing in the same week.

DigiCert's G1 Roots Lose Browser Trust — Affecting RapidSSL, GeoTrust, and Thawte Too
April 16, 2026 · DigiCert / Chrome & Mozilla root programs

DigiCert's G1 Roots Lose Browser Trust — Affecting RapidSSL, GeoTrust, and Thawte Too

Chrome and Firefox stopped trusting DigiCert's older G1 root certificates on April 15 — a change that reaches every brand under the DigiCert umbrella, not just certificates sold directly under the DigiCert name.

Sectigo Launches Private PQC for Testing Post-Quantum Certificates
April 15, 2026 · Sectigo

Sectigo Launches Private PQC for Testing Post-Quantum Certificates

A new feature in Sectigo Certificate Manager lets enterprises issue and manage post-quantum certificates inside their existing workflows — without new infrastructure or tools.

Industry Analysts Warn October 2026 Could Bring a Wave of Certificate Outages
March 31, 2026 · TechRadar Pro

Industry Analysts Warn October 2026 Could Bring a Wave of Certificate Outages

TechRadar Pro's analysis connects a specific date to the first 200-day certificates issued under this year's new validity rules: many of them expire in early October, all around the same time.

The 200-Day Certificate Cap Is Now in Effect
March 16, 2026 · CA/Browser Forum

The 200-Day Certificate Cap Is Now in Effect

March 15 marked the first enforcement milestone of the CA/Browser Forum's phased plan to shrink maximum TLS certificate validity from 398 days down to 47 by 2029.

Certbot Adds Support for IP Address Certificates
March 12, 2026 · EFF / Certbot

Certbot Adds Support for IP Address Certificates

Certbot 5.3 and 5.4 add flags for requesting certificates that secure a bare IP address rather than a domain name — a capability Let's Encrypt enabled for general use earlier this year.

Let's Encrypt Stops Including Client Authentication in Default Certificates
February 12, 2026 · Let's Encrypt

Let's Encrypt Stops Including Client Authentication in Default Certificates

As of February 11, Let's Encrypt's default certificate profile no longer includes the TLS Client Authentication EKU — a change driven by Chrome's root program policy, not a Let's Encrypt-specific decision.