Google Chrome accused Symantec of granting more than 30,000 digital certificate certificates that did not meet the quality standards
Google recently announced it would not accept all EV certificates issued by Symantec after discovering more than 30,000 invalid EV certificates issued by Symantec in the last few years.
Extended validation EV certificate is a special form of verification by digital certificate authentication (CA) providers. Getting this certificate will increase website reliability for users. Before issuing a certificate, the certificate issuer must fully verify the legal existence of the legal status of any organization or individual in the host country. Each CA has its own standards and verification procedures, but all must ensure it is rigorous and accurate.
Symantec's EV number certificates will no longer be recognized by Chrome browser for at least a year until Symantec fixes its certificate-issuing processes to comply with quality standards.
The move came into effect immediately after Ryan Sleevi, a software engineer of the Google Chrome group, made the announcement on Thursday in Google's online forum.
Sleevi said: "The fact that Symantec has issued certificates that do not meet the quality standards also entails certain troubles, causing us to completely lose our faith in the policies and practicality of the certificates. granted by Symantec in the last few years ".
One of the important parts of the SSL system is trust, but if the certificate authentication service providers cannot verify existence and legally identify before granting EV certificates to domain names then it is The trust of those certificates will be greatly reduced.
The Google Chrome team began investigating on January 19 and found that Symantec's standards and verification procedures in recent years have been dishonest, which could be threatening The integrity of the TLS system is used to authenticate and secure data and connect via the Internet.
According to this move, the Google Chrome team has proposed the following decisions as a punishment directed at Symantec:
1. EV certificates issued by Symantec as of today will be downgraded to less secure domain authentication certificates, meaning that the Chrome browser will immediately stop displaying the authenticated domain name. in the address bar for at least a year.
2. To limit the risk of other unreliable certificates, all newly issued certificates must have a validity period of no more than 9 months (effective from Chrome 61 release) if desired. be trusted in Google Chrome.
3. Gradually reduce the validity of Symantec's certificates for recent Chrome versions, specifically:
- Chrome 59 (Dev, Beta, Stable): valid for 33 months (1023 days)
- Chrome 60 (Dev, Beta, Stable): valid for 27 months (837 days)
- Chrome 61 (Dev, Beta, Stable): valid for 21 months (651 days)
- Chrome 62 (Dev, Beta, Stable): valid for 15 months (465 days)
- Chrome 63 (Dev, Beta): valid for 9 months (279 days)
- Chrome 63 (Stable): valid for 15 months (465 days)
- Chrome 64 (Dev, Beta, Stable): valid for 9 months (279 days)
This means starting with Chrome 64, scheduled for release in early 2018, Chrome browser will only trust Symantec's certificates issued within nine months (279 days) or less.
Google believes that this move will ensure that web developers are aware of dishonesty and under quality standards for certificates issued by Symantec, to avoid future unfortunate situations. .
The war between Symantec became even more intense when the company claimed that Google's allegations were exaggerated and caused misunderstandings.
Symantec responded to Google's move saying: "We vehemently oppose the action Google has taken to Symantec's SSL / TLS certificate in Chrome browser. This action by Google is really too surprising for them. I, and we believe that blog posts are a irresponsibility of Google ".
"Google has assumed that only the certificates issued by Symantec are not qualified, while Google's discovery involves many other CAs."
You should read it
- Symantec introduced a data protection solution
- How to uninstall Symantec Endpoint Protection (SEP)
- Beware of a trick that takes advantage of Google Wave
- Solutions to help businesses confidently delete data
- Symantec launched antivirus software for Windows Mobile
- Symantec warns of a new worm variant
- Symantec updated a series of antivirus software
- Symantec patched vulnerabilities in antivirus software
May be interested
- What is Root Certificate? How is it used for online monitoring?the abuse of root certificates is not just a problem in kazakhstan. internet users around the world should know about how this security tool is used to monitor online.
- Managing certificates in Exchange - Part 2in this section we will introduce the requirements that need to be considered when working with certificates.
- How to view SSL certificate details on Chrome browser?on previous chrome versions, as of chrome 55, users can view certificate details of a website by clicking on the blue lock icon in the address bar. but it seems that this function has disappeared, which makes many users feel confused.
- Following the trail of Internet Explorer 6, does Google Chrome fail?although in the early days, google was the king of web standards for many other browsers, but recently, they themselves ignored these standards and forced users to choose chrome.
- 7 types of certificates significantly increase your incomethe certificates below will help beautify your qualification profile, which can even help significantly improve your income. surprisingly, you can get them without even having to step out of the house, because all 7 certificates are available online.
- What is OCSP (Online Certificate Status Protocol)? Advantages and disadvantages of OCSPocsp (online certificate status protocol) is an internet protocol (ip) used to determine the revocation status of x.509 digital certificates.
- Update Windows and FireFox right away to hackeffects from hacker intrusion system diginotar company steals 531 security certificates that are spreading and causing concern for many countries. software vendors like microsoft quickly ...
- Managing certificates in Exchange - Part 1in part 1 of this series, we will give you an overview of the different components of exchange that use certificates.
- How to Install an SSL Certificatean ssl certificate (short for secure socket layer) is a way that websites and services are authenticated to encrypt the data sent between them and their customers. ssl is also used to verify that you're connected to the correct service you want (for example, am i really signed in to my email service provider or is this just a phishing copy?). if you are providing a website or service that requires a secure connection, it may be necessary to install an ssl certificate to verify your trust. take a look at the following article to learn how.
- Some Samsung devices experience email, VPN errors due to missing Microsoft Intune certificatesmicrosoft just said that some samsung devices that have signed up for microsoft intune with a work account will experience email and vpn connection problems after upgrading to android 12. the cause of the problem is a lack of certificates.