{"id":7671,"date":"2018-10-09T12:36:49","date_gmt":"2018-10-09T16:36:49","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7671"},"modified":"2020-11-24T09:27:32","modified_gmt":"2020-11-24T14:27:32","slug":"final-warning-last-chance-to-replace-symantec-ssl-certificates","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/final-warning-last-chance-to-replace-symantec-ssl-certificates\/","title":{"rendered":"Final Warning: Last chance to replace Symantec SSL certificates"},"content":{"rendered":"<h2>Google Chrome 70 will roll out in about a week and all remaining Symantec SSL certificates will be distrusted<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7673\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Beating-a-dead-horse-300x257.jpg\" alt=\"At this point, talking about the Symantec-Google distrust feels like beating a dead horse\" width=\"300\" height=\"257\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Beating-a-dead-horse-300x257.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Beating-a-dead-horse-768x657.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Beating-a-dead-horse.jpg 900w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>This is the last week for website owners using Symantec SSL certificates issued before December 1, 2017 to replace their certificate. Failing to do so will result in your website breaking. <a href=\"https:\/\/www.thesslstore.com\/blog\/final-distrust-symantec-ssl-certificates\/\">Next week Google will roll out Chrome 70<\/a>, which will distrust all remaining Symantec CA brand SSL certificates. <strong>This is only for websites using SSL certificates issued off Symantec\u2019s roots<\/strong>. If you have re-issued or replaced your SSL certificate after December 1, 2017 this does not apply to you.<\/p>\n<p><a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-distrust-symantec-ssl-certificates\/\">If it feels like we\u2019ve covered this topic before<\/a>\u2014<a href=\"https:\/\/www.thesslstore.com\/blog\/final-distrust-symantec-ssl-certificates\/\">we have<\/a>. <a href=\"https:\/\/www.thesslstore.com\/blog\/remove-trust-in-existing-symantec-ssl-certificates\/\">Extensively<\/a>. But this morning when I got to my office my boss wheeled in a large cart with a sheet draped over it and said, \u201cI need you to beat this dead horse.\u201d<\/p>\n<p>So, beat it I will. Here\u2019s a rundown of what\u2019s happening, how we got here and what you need to do if this change impacts you.<\/p>\n<p>Let\u2019s hash it out\u2026<span id=\"newline\"><\/span><\/p>\n<h2>Why do Symantec SSL Certificates Need to be Replaced?<\/h2>\n<p>Sit back and let me tell you the tale of a Certificate Authority and a browser and how two companies nearly broke the internet. Ok, that might be a bit grandiose\u2014but you try writing about this for the 15<sup>th<\/sup> time and see how creative you get.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<p><a href=\"https:\/\/www.thesslstore.com\/blog\/symantec-google-working-together-to-solve-mis-issuance-errors\/\">Back in 2015 Symantec ran afoul of Google for the first time<\/a> after issuing some bad test certificates. We tend to downplay the severity of this first mistake, but it was pretty major. Google found that Symantec had been issuing unauthorized SSL certificates domains owned by Google, Opera and three other organizations. The scandal <a href=\"https:\/\/arstechnica.com\/information-technology\/2015\/10\/still-fuming-over-https-mishap-google-gives-symantec-an-offer-it-cant-refuse\/\">caused Symantec to fire a number of employees and Google required Symantec to begin adding all the certificates it issued to Certificate Transparency logs<\/a>. At that point in time only EV certificates were required to be logged.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-7676\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Icon2-e1539102494974-300x300.jpg\" alt=\"Symantec CA brand SSL certificates\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Icon2-e1539102494974-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Icon2-e1539102494974.jpg 399w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>A year later, Symantec got in trouble for mis-issuing a new batch of test certificates. While Symantec claimed it was just 33 certificates Google estimated it was more like 30,000. <a href=\"https:\/\/www.thesslstore.com\/blog\/google-and-symantec\/\">When Google investigated further it unearthed lax oversight over validation in some regions, too<\/a>.<\/p>\n<p>In college sports, the worst allegation that the NCAA (US college sports&#8217; governing body) can level at a program is a loss of institutional control. That\u2019s basically what Google alleged after the second set of mis-issuances in 2016.<\/p>\n<p>Now, this is where the opinion tends to split. From the browsers\u2019 perspective (not just Google, but Mozilla, Apple and Microsoft, too) these mistakes undermined faith in Symantec\u2019s entire PKI. How could any Symantec SSL certificate be trusted knowing that there was such lax oversight over the validation required for issuance. By that logic, Symantec had to be distrusted.<\/p>\n<p>The other camp, which was largely consistent of the commercial CA industry, didn\u2019t have a problem so much with the distrust as with <a href=\"https:\/\/www.thesslstore.com\/blog\/remove-trust-in-existing-symantec-ssl-certificates\/\">the potential impact to customers and end users<\/a>. The average site owner doesn\u2019t pay any attention to the goings on of the digital certificate industry. And Symantec is one of the few brands with crossover brand recognition owing to its highly-popular Norton Antivirus product. Outside of the SSL\/TLS industry Symantec enjoys a sterling reputation, that\u2019s part of what\u2019s buoyed its market share.<\/p>\n<p>Customers shouldn\u2019t be punished for choosing Symantec, especially given that they didn\u2019t have any idea about these issues in the first place. And even though Google <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-final-action-symantec\/\">attempted to give extended timelines<\/a> for replacement, that\u2019s still effectively what happened\u2014Symantec\u2019s customers were punished.<\/p>\n<h2>DigiCert Saves the Day<\/h2>\n<p><a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-final-action-symantec\/\">The original plan between Google and Symantec<\/a> called for issuance to be passed on to a managed CA until Symantec could rebuild its own PKI. However, that was never really a tenable solution. Fortunately, <a href=\"https:\/\/www.thesslstore.com\/blog\/digicert-symantec-acquisition\/\">DigiCert stepped in and purchased the Symantec CA in the Fall of 2017<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7679\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/digicert-ssl-pki-solutions-300x300.jpg\" alt=\"DigiCert logo\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/digicert-ssl-pki-solutions-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/digicert-ssl-pki-solutions.jpg 364w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>In the long run, that\u2019s probably the best thing that could have happened.<\/p>\n<p>It\u2019s still worth pointing out what an undertaking this was though. DigiCert didn\u2019t just purchase the rights to trademarks and brands, it acquired talent and infrastructure, too. Then it had to scramble to integrate new personnel, integrate various processes and systems and scale up all aspects of its operation \u2013 support, account management, sales \u2013 to incorporate Symantec&#8217;s customer-base with its own.<\/p>\n<p>And all of this needed to be finished up by the beginning of December so that it could start re-issuing millions (literally, millions) of certificates before Google\u2019s deadlines.<\/p>\n<p>That\u2019s a near Herculean effort, and aside from one or two cases \u2013 outliers \u2013 the internet hasn\u2019t broken.<\/p>\n<p>So, hats off to DigiCert.<\/p>\n<h2>What Symantec CA Brand SSL certificates are going to be distrusted?<\/h2>\n<p>Ok, so let\u2019s get down to brass tacks. The final Google-Symantec distrust doesn\u2019t just affect Symantec SSL certificates, it also affects the Symantec subsidiary brands, too.<\/p>\n<ul>\n<li>Symantec<\/li>\n<li>GeoTrust<\/li>\n<li>Thawte<\/li>\n<li>RapidSSL<\/li>\n<\/ul>\n<p>This is the <a href=\"https:\/\/www.thesslstore.com\/blog\/final-distrust-symantec-ssl-certificates\/\">final distrust<\/a>, so any SSL certificates issued off any of those CAs\u2019 roots will break. Here\u2019s the best way to figure out if this will affect you: <strong>Was your SSL certificate issued after December 1, 2017<\/strong>?<\/p>\n<p>Since December, DigiCert has been issuing for Symantec and its subsidiaries off its own roots (the DigiCert roots). So, as long as your Symantec CA brand SSL certificate was issued or re-issued after December 1, 2017, you\u2019re in the clear.<\/p>\n<p>Here\u2019s how to check: regardless of what browser you\u2019re using, click on the padlock icon in the address bar of your browser and navigate to the certificate details. Now, check the Begins On date:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7672\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Certificate-TSS.jpg\" alt=\"Checking Issuance Date in the SSL Certificate Details\" width=\"603\" height=\"645\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Certificate-TSS.jpg 603w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Certificate-TSS-280x300.jpg 280w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/p>\n<p>Or, if you want, <a href=\"https:\/\/www.thesslstore.com\/ssltools\/symantec-reissue-checker.php\">we have a tool that can check for you<\/a>.<\/p>\n<p>If you\u2019re using a Symantec CA brand SSL certificate issued before December 1, 2017 and you haven\u2019t re-issued or replaced it yet, you have about a week before your website breaks.<\/p>\n<h2>What happens when an SSL certificate is distrusted?<\/h2>\n<p>This is tough to explain without at least a basic working knowledge of Public Key Infrastructure. Every computer system keeps a Root Store. This store contains a set of trusted Root CA Certificates. When a CA issues an SSL certificate, it signs it with one of its private keys. If that digital signature can be traced back to one of the roots in the system\u2019s trust store, the system will trust the certificate.<\/p>\n<p>What Google and the other browsers have done to distrust Symantec CA brands is <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-remove-a-root-certificate\/\">remove their roots<\/a> from the various Root programs, and thus the root stores. Now when a client is presented with an SSL certificate that should chain back to one of the removed Symantec CA brand roots, it won\u2019t be able to trace it back to one of the roots in its trust store and will issue a browser warning about the site.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7674\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Google-Distrust-Symantec-Warning.png\" alt=\"Interstitial warning issued for distrusted Symantec certificates\" width=\"1398\" height=\"922\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Google-Distrust-Symantec-Warning.png 1398w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Google-Distrust-Symantec-Warning-300x198.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Google-Distrust-Symantec-Warning-768x507.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/Google-Distrust-Symantec-Warning-1024x675.png 1024w\" sizes=\"auto, (max-width: 1398px) 100vw, 1398px\" \/><\/p>\n<p>One of the biggest misnomers throughout all of this deals with Google\u2019s root program. The obvious assumption is that Google Chrome would use the Google root program, but that\u2019s not the case. While Mozilla\u2019s Firefox browser relies on the Mozilla root program, Google Chrome actually uses the root store that is present on whatever operating system it\u2019s running on (Apple, Microsoft, etc.). The Google root program is for the Android OS.<\/p>\n<p>So how can Google distrust a root in Chrome before the root programs distrust it? Blacklists. Google filters roots against its own blacklist, which allows it to distrust roots without running its own root program for Chrome.<\/p>\n<h2>What do I need to do if my SSL certificate is going to be distrusted?<\/h2>\n<p>Don\u2019t panic. There\u2019s still about a week before Google rolls out Chrome 70. But you do need to act now, Chrome is the most used browser in the world, with well over 50% market share.<\/p>\n<p>If your website is using an affected SSL certificate, you have a couple of options:<img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-7675\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/TSS-Logo.jpeg\" alt=\"\" width=\"225\" height=\"225\" \/><\/p>\n<ol>\n<li><span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.thesslstore.com\/support\/\">You can contact us<\/a><\/span>. I typically try to avoid being openly sales-y in this space, but we have been in the SSL\/TLS business for over a decade and we\u2019ve built out the infrastructure to help you quickly re-issue or replace your Symantec CA brand SSL certificate(s).<\/li>\n<li><span style=\"color: #ff6600;\"><a style=\"color: #ff6600;\" href=\"https:\/\/www.digicert.com\/replace-your-symantec-ssl-tls-certificates\/\">Contact DigiCert<\/a><\/span>. While we\u2019re platinum elite partners with DigiCert and can handle your needs for you, you can also go directly to DigiCert for re-issuance\/replacement.<\/li>\n<\/ol>\n<p>And given the fact that many of these SSL certificates will need to be renewed within a few months of re-issuance, <a href=\"https:\/\/www.thesslstore.com\/blog\/digicert-increases-renewal-window-to-7-months\/\">DigiCert has also extended the window for renewals<\/a>. Now site owners can renew and carry up to seven months over to their new certificate. This should help reduce administrative burdens considerably.<\/p>\n<p>And one last thing, the Symantec CA brands are trustworthy once again now that they are being run by DigiCert. All Symantec CA brand SSL certificates \u2013 Symantec, GeoTrust, Thawte &amp; RapidSSL \u2013 chain back to the DigiCert trusted roots as of December 1, 2017.<\/p>\n<p>So, one last time: this is your final chance to replace any original Symantec CA brand SSL certificates issued before December 1, 2017 before your website breaks. Don\u2019t wait on this.<\/p>\n<p><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7276\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" width=\"1559\" height=\"407\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w\" sizes=\"auto, (max-width: 1559px) 100vw, 1559px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Chrome 70 will roll out in about a week and all remaining Symantec SSL certificates will be distrusted This is the last week for website owners using Symantec SSL&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7677,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[3993,131,139],"class_list":["post-7671","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-distrust","tag-google","tag-symantec","post-with-tags"],"views":22274,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Text-Sign-Showing-Final-Notice-254731975.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7671"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7671\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/7677"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}