HTTPS Certificate Industry to Sunset Weak Domain Validation Methods

Google’s Chrome Root Program and the CA/Browser Forum are phasing out 11 legacy domain control validation methods for HTTPS certificates that rely on weak signals like email, phone, SMS, fax, or postal mail in favor of stronger, automated cryptographically verifiable checks. The change, driven by Ballots SC‑080, SC‑090, and SC‑091, is designed to close loopholes attackers could exploit to fraudulently obtain certificates. The deprecation will be phased in with full security benefits realized by March 2028, pushing the web toward more secure validation methods and improved trust in HTTPS connections. 

https://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities