HTTPS Certificate Industry to Sunset Weak Domain Validation Methods
Google’s Chrome Root Program and the CA/Browser Forum are phasing out 11 legacy domain control validation methods for HTTPS certificates that rely on weak signals like email, phone, SMS, fax, or postal mail in favor of stronger, automated cryptographically verifiable checks. The change, driven by Ballots SC‑080, SC‑090, and SC‑091, is designed to close loopholes attackers could exploit to fraudulently obtain certificates. The deprecation will be phased in with full security benefits realized by March 2028, pushing the web toward more secure validation methods and improved trust in HTTPS connections.
https://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html
Comments
Post a Comment