Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity

    Google Sets Deadline to Replace Symantec Website Certificates

    By
    Jaikumar Vijayan
    -
    September 13, 2017
    Share
    Facebook
    Twitter
    Linkedin
      Chrome Symantec Certificate Deadline

      Google this week announced a final timetable for withdrawing support in the Chrome browser for websites that use Symantec-issued authentication certificates.

      The timetable gives organizations that are using Symantec authentication certificates to replace them or risk having their sites flagged as unsafe by the Chrome browser after the final deadline passes.

      In an announcement on Google’s Security Blog, members of the Chrome security team posted a timeline indicating the exact dates by which site operators will need to obtain new certificates from any certificate authority that is trusted by Chrome.

      Google’s schedule gives site owners up to March 15, 2018 to replace Symantec Transport Layer Security (TLS) certificates that were issued before June 1, 2016. By mid-September next year, those sites with Symantec certificates dated after June 1, 2016 will need to replace them as well with new ones from either Symantec or any other certificate issuing vendor.

      Starting with release 70 of Chrome on Sept 13, 2018, the browser will distrust all existing Symantec- issued TLS certificates.

      This week’s blog post is designed to give website owners actionable information about the steps that Google has said it will take after an investigation earlier this year prompted questions about Symantec’s diligence in issuing certificates to site owners.

      As a so-called Certificate Authority (CA), Symantec is one of several companies worldwide entrusted with the responsibility for issuing the cryptographic certificates, which are used to authenticate websites.

      Browsers such as Chrome use these certificates to verify the identity of websites and to make sure that a site, which purports to belong to a specific internet domain, actually does belong to it. Sites that are properly authenticated and deemed safe usually have a green padlock or some other similar icon in the URL bar.

      Improperly issued certificates can have critical consequences and among other things allow threat actors to spoof legitimate sites. A threat actor that managed to obtain a mistakenly issued digital certificate for Google.com for instance could spoof a Google site that would be trusted implicitly by all major browsers. This would allow the threat actor to use the spoofed site to distribute malware to website visitors.

      In January, security engineers at Mozilla, the organization behind the Firefox browser publicly reported what they described as serious irregularities in Symantec’s handling of the certificate issuance process. The researchers noted that they had come across several instances where Symantec had wrongly issued certificates for specific domains without any authorization from the domain owners.

      A subsequent investigation by Google showed that Symantec had improperly allowed four third parties to access its digital certificate issuance infrastructure and issue certificates on its behalf. Google claimed its investigation showed that Symantec in its role as a CA had allowed 30,000 certificates to be improperly issued, even as Symantec itself pegged the number at 127.

      The disclosures this year about problems with Symantec’s certificate issuing process marked the second time since October 2015 that the company was caught doing the same thing. In the 2015 incident, Symantec admitted that it had improperly issued a total of 23 test certificates covering five organizations, including Google and Opera.

      Google has claimed that its decision to distrust—or deprecate—all Symantec’s certificates stems from the company’s systemic failure to follow industry norms. Google has said the only way Chrome will be allowed to trust Symantec certificates again is if the certificates are issued from a completely new infrastructure and with proper oversight.

      At least partly as a result of the pressure from Google, Symantec in August sold its digital certificate business to DigiCert for just under $1 billion and a 30 percent stake in the common stock of the company.

      Current plans call for DigiCert to start issuing new certificates to Symantec customers starting later this year. Google says DigiCert is one of the authentication certificate authorities that Chrome will continue to trust after Sept. 13, 2018.

      Jaikumar Vijayan
      Vijayan is an award-winning independent journalist and tech content creation specialist covering data security and privacy, business intelligence, big data and data analytics.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×