Our own take on the certificate authority and browser policy news that actually matters — CA/Browser Forum ballots, Let's Encrypt changes, Sectigo and DigiCert announcements, Chrome trust-store updates, CA compliance incidents, and industry analysis, explained in plain language.
Two separate CP/CPS violations — one involving the same clientAuth EKU issue rippling across the industry this year, another over a missing OCSP extension — forced back-to-back mass revocations.
A security researcher's Bugzilla report documented active certificates issued to EU-sanctioned entities including Sberbank and VTB — and HARICA initially declined to revoke them.
Chrome Root Program Policy v1.6 enforcement started June 15 — new public TLS certificates with both server and client authentication purposes are no longer trusted by default.
The world's largest certificate authority is targeting a late-2026 staging rollout for MTCs — the same post-quantum architecture Google and Cloudflare proposed earlier this year.
New roots, general availability for short-lived certificates, and the default classic ACME profile switching over — all landing in the same week.
Chrome and Firefox stopped trusting DigiCert's older G1 root certificates on April 15 — a change that reaches every brand under the DigiCert umbrella, not just certificates sold directly under the DigiCert name.
A new feature in Sectigo Certificate Manager lets enterprises issue and manage post-quantum certificates inside their existing workflows — without new infrastructure or tools.
TechRadar Pro's analysis connects a specific date to the first 200-day certificates issued under this year's new validity rules: many of them expire in early October, all around the same time.
March 15 marked the first enforcement milestone of the CA/Browser Forum's phased plan to shrink maximum TLS certificate validity from 398 days down to 47 by 2029.
Certbot 5.3 and 5.4 add flags for requesting certificates that secure a bare IP address rather than a domain name — a capability Let's Encrypt enabled for general use earlier this year.
As of February 11, Let's Encrypt's default certificate profile no longer includes the TLS Client Authentication EKU — a change driven by Chrome's root program policy, not a Let's Encrypt-specific decision.