{"id":7115,"date":"2018-08-21T13:41:04","date_gmt":"2018-08-21T17:41:04","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7115"},"modified":"2021-05-06T10:33:05","modified_gmt":"2021-05-06T14:33:05","slug":"final-distrust-symantec-ssl-certificates","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/final-distrust-symantec-ssl-certificates\/","title":{"rendered":"Attention: Final Google distrust date for Symantec CA SSL certificates is approaching"},"content":{"rendered":"<h2>The beta version of Chrome 70 will arrive around September 13<\/h2>\n<p>Google Chrome\u2019s final distrust of Symantec CA SSL certificates is rapidly approaching. Anyone using the Beta version of Chrome will receive the Chrome 70 update around September 13<sup>th<\/sup>, at this point any website still using an original Symantec CA brand SSL certificate will start to receive browser warnings.<span id=\"newline\"><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7118\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Symantec-DigiCert-1088x725-2-255x300.png\" alt=\"DigiCert purchased Symantec CA\" width=\"255\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Symantec-DigiCert-1088x725-2-255x300.png 255w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Symantec-DigiCert-1088x725-2.png 358w\" sizes=\"auto, (max-width: 255px) 100vw, 255px\" \/>This affects all Symantec CA brand SSL certificates issued before December 1, 2017. And it applies to:<\/p>\n<ul>\n<li>Symantec<\/li>\n<li>Thawte<\/li>\n<li>GeoTrust<\/li>\n<li>RapidSSL<\/li>\n<\/ul>\n<p>The stable version of Chrome 70 is set to arrive around October 16, at which point over 60% of the internet will not be able to reach websites that are still using one of the affected certificates. We are using the Beta release as our deadline to give you a little bit of a buffer in case replacing certificates takes a day or two.<\/p>\n<p>DigiCert, <a href=\"https:\/\/www.thesslstore.com\/blog\/digicert-symantec-acquisition\/\" target=\"_blank\" rel=\"noopener noreferrer\">which purchased the Symantec CA brand following its agreement with Google<\/a>, has been handling the re-issues for Symantec customers and it has done a spectacular job.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<p>There was a lot of concern back in April when <a href=\"https:\/\/www.thesslstore.com\/blog\/symantec-re-issue-thousands-of-ssl-certificates-will-be-distrusted-tuesday\/\" target=\"_blank\" rel=\"noopener noreferrer\">the first group of Symantec CA SSL certificates was distrusted<\/a> that huge swaths of the internet would go down. That didn\u2019t happen, and it\u2019s a testament to the men and women at DigiCert who have worked tirelessly to replace millions (literally millions) of affected SSL certificates.<\/p>\n<p>The April distrust dealt with SSL certificates issued before June 1, 2016. DigiCert started re-issuing at the beginning of December in anticipation. The second distrust date is for all the remaining Symantec CA SSL certificates.<\/p>\n<h2>Will this distrust affect my SSL certificate?<\/h2>\n<p>Here is an easy way to think about this final distrust. Has DigiCert, or the SSL service you purchased your certificate from, re-issued or replaced your Symantec, GeoTrust, Thawte or RapidSSL certificate in the past nine months? If the answer is no, then this distrust is going to affect you.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-6671\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Google-300x300.png\" alt=\"Google logo\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Google-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/Google.png 512w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>The Canary version of Chrome 70, Google\u2019s advanced dev version of Chrome, came out in July. Fortunately, very few people use Canary. The Beta version has a few more users, but the vast majority of people are going to be affected by the stable release around October 16. It\u2019s worth noting that Google rolls its updates out gradually, so it\u2019s really more like the week of the 16<sup>th<\/sup> than the 16<sup>th<\/sup> itself.<\/p>\n<p>The other browsers, Mozilla\u2019s Firefox, Apple\u2019s Safari, Microsoft\u2019s Edge and IE will all distrust Symantec CA certificates along similar timelines, too. So, telling your visitors to use another browser isn\u2019t an option.<\/p>\n<p>It is worth pointing out that since DigiCert has purchased and begun issuing for the Symantec CA Brands that they are safe to use again. <strong>DigiCert is universally trusted, one of the most well-respected Certificate Authorities in the digital certificate industry<\/strong>. DigiCert has also tweaked its issuance practices to compensate for site owners who would have had to renew their certificate within a couple months of re-issuing. <a href=\"https:\/\/www.thesslstore.com\/blog\/digicert-increases-renewal-window-to-7-months\/\" target=\"_blank\" rel=\"noopener noreferrer\">There is now a seven-month window for renewals<\/a>, meaning you can knock out the re-issue and the renewal in one fell swoop.<\/p>\n<p>This option is only available for one-year certificates owing to the CAB Forum\u2019s baseline requirements for certificate validity.<\/p>\n<h2>How did Symantec get distrusted?<\/h2>\n<p>If you\u2019re looking for a full synopsis <a href=\"https:\/\/www.thesslstore.com\/blog\/remove-trust-in-existing-symantec-ssl-certificates\/\" target=\"_blank\" rel=\"noopener noreferrer\">you can read it here<\/a>. The short answer is that <a href=\"https:\/\/www.thesslstore.com\/blog\/symantec-google-working-together-to-solve-mis-issuance-errors\/\" target=\"_blank\" rel=\"noopener noreferrer\">dating back to 2015<\/a> Symantec had been called out for some minor mis-issuance issues. In 2016, upon investigating further, <a href=\"https:\/\/www.thesslstore.com\/blog\/google-and-symantec\/\">Google found other evidence of mis-issuance<\/a> and that Symantec was practicing lax oversight over the regional authorities it was outsourcing validation to in various regions.<\/p>\n<figure id=\"attachment_7116\" aria-describedby=\"caption-attachment-7116\" style=\"width: 300px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-7116\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Gun-Control-79229779-300x213.jpg\" alt=\"Symantec vs Google\" width=\"300\" height=\"213\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Gun-Control-79229779-300x213.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Gun-Control-79229779-768x545.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Gun-Control-79229779-1024x726.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Gun-Control-79229779.jpg 2000w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption id=\"caption-attachment-7116\" class=\"wp-caption-text\">Symantec and Google&#8217;s headquarters are across the street from each other, which made for some awkward bus rides to work&#8230;<\/figcaption><\/figure>\n<p>Here\u2019s where there are two differing camps. Symantec, rightfully, points out that there were a total of 33 mis-issued test certificates and that no real-world harm actually occurred as a result of it. Google and the other browsers argued that Symantec\u2019s mis-issuance problems were systemic and by extension, they could no longer trust the certificates Symantec CA brands were issuing.<\/p>\n<p><a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-final-action-symantec\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google and Symantec reached an agreement over the Summer of 2017<\/a> that Symantec would shift issuance of certificates to a managed CA while it rebuilt its PKI. In the meantime, Symantec\u2019s roots would be distrusted, which in turn distrusts all of Symantec\u2019s certificates. That was what facilitated Symantec selling its CA to DigiCert for nearly a billion dollars and a 30% share.<\/p>\n<p>Since then, DigiCert has scaled up its operations and started issuing for Symantec.<\/p>\n<h2>What do I need to do if my SSL certificate is about to be distrusted?<\/h2>\n<p>Contact the SSL service you purchased from, or DigiCert, and there are mechanisms already in place to help replace or renew your certificate.<\/p>\n<p>If you purchased your SSL Certificate(s) from The SSL Store, <a href=\"https:\/\/www.thesslstore.com\/client\/symantecreplacementorders.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">click here to log into your account and view your impacted order(s).<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The beta version of Chrome 70 will arrive around September 13 Google Chrome\u2019s final distrust of Symantec CA SSL certificates is rapidly approaching. Anyone using the Beta version of Chrome&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7117,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[3628,131,139],"class_list":["post-7115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-digicert","tag-google","tag-symantec","post-with-tags"],"views":34953,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-Sankt-petersburg-Russia-June-243894217.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7115"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/7117"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}