Google logo showing certificate authorities

Google to Distrust Two Certificate Authorities Over Compliance Issues

Google will stop trusting digital certificates issued by two certificate authorities (CA) due to concerning compliance issues.

“These patterns represent a loss of integrity and fall short of expectations, eroding trust in these CA Owners as publicly-trusted certificate issuers trusted by default in Chrome” the company said.

These changes will be reflected in the next release of its popular web browser, Chrome 139, scheduled for release in August 2025.

Certificate authorities distrusted by Google

Google will start distrusting certificates issued by Taiwan’s largest integrated telecom service provider, Chunghwa Telecom, and the Hungarian digital identity company Netlock. The tech giant said it had observed concerning patterns that had undermined the integrity of the certificate authorities, eroding their trust.

“Chrome’s confidence in the reliability of Chunghwa Telecom and Netlock as CA Owners included in the Chrome Root Store has diminished due to patterns of concerning behavior observed over the past year,” the Chrome Security Team stated in a Google Blog post.

The tech giant also accused the certificate authorities of inadequate responses to addressing known security issues and failure to meet improvement commitments.

“Over the past several months and years, we have observed a pattern of compliance failures, unmet improvement commitments, and the absence of tangible, measurable progress in response to publicly disclosed incident reports,” the company claimed.

Subsequently, the inherent risk posed to Chrome users by trusting these certificate authorities outweighed any justifications, the company warned: “When these factors are considered in the aggregate and considered against the inherent risk each publicly-trusted CA poses to the internet, continued public trust is no longer justified.”

However, Google gave no specific details on why it distrusted the two certificate authorities. Possible reasons include failure to revoke misissued certificates and disclose intermediate CA certificates to the Common CA Database.

“Chunghwa Telecom was out of compliance and mis-issued certificates and took longer than required to revoke them. NetLock committed similar out of compliance activities,” noted Jason Soroko, Senior Fellow at Sectigo. “Both CAs repeatedly went past the Baseline-Requirement revocation deadlines, leaving invalid certificates active beyond the allowed window, prompting Chrome to withdraw their default trust.”

Starting July 31, people visiting websites secured with certificates issued by the two certificate authorities will receive “full page interstitial” security warnings.

Subsequently, Google advised website administrators using certificates from the two certificate authorities to migrate to other issuers reasonably quickly to avoid disruptions.

However, enterprise users can override the default Chrome behavior by installing the affected certificates as locally trusted root certificates on their operating system.

“… enterprises can override Chrome Root Store constraints … by installing the corresponding root CA certificate as a locally-trusted root on the platform Chrome is running,” Google explained.

The changes will affect Chrome instances running on Windows, Linux, macOS, ChromeOS, and Android operating systems. However, other browsers such as Mozilla Firefox, Microsoft Edge, and Apple Safari have yet to announce similar measures.

Besides Google, Apple distrusted Netlock’s certificate in November 2024. In the same month, Google Chrome, Apple, and Mozilla also distrusted certificates issued by Entrust.

Like Chunghwa Telecom and Netlock, Google had accused Entrust of failing to meet compliance standards and being affected by security incidents since 2018. More certificate authorities will likely be affected by Google’s crackdown on non-compliance with its new security requirements announced in March 2025.