Google Chrome Will No Longer Trust Entrust Certificates
From 31 October 2024 11 November 2024 (updated, extended deadline to give Entrust time to transition their CA to ssl.com), public TLS certificates issued by Entrust with a Signed Certificate Timestamp (SCT) after this date will no longer be accepted by Google Chrome (read more here).
For a Certificate Authority (CA) to be trusted by a browser, it must meet specific requirements defined by the CA/Browser Forum. To ensure ongoing trust, browsers regularly receive audit reports on CA operations and compliance. Transparency is a key factor, and CAs are expected to cooperate with browsers to resolve and prevent issues.
Recently, several root programs have expressed a lack of confidence in Entrust's TLS certificate issuance practices, and their failure to improve when mistakes are identified. As a result, Google has decided to remove trust in Entrust from the Chrome browser.
What does this mean for Entrust certificates?
Public SSL/TLS certificates issued by Entrust with an SCT after 31 October 2024 will no longer be valid in Google Chrome. These certificates will be treated as insecure. TLS certificates with an SCT dated before this date will, however, remain valid for the duration of their lifetime.
Entrust has made an arrangement with ssl.com to continue selling their relatively expensive premium SSL products. They continue selling them at premium prices under their own name, even though the certificates are actually ssl.com certificates (which sells significantly cheaper certificates) rebranded as Entrust. Customers are led along, even though they could easily switch to a different provider at a much lower price that takes security more seriously.
There is a risk that ssl.com will be pressured both by the volume of certificates from Entrust and by the way they have previously conducted their business, which may affect ssl.com as they take over most of the employees in the certificate business.
It is therefore important that anyone using Entrust certificates switches to a different CA as soon as possible.
Switch from Entrust to FairSSL and get 50% off!
At FairSSL, we offer 50% off to customers who want to migrate from a commercial CA that we do not partner with (we carry products from the largest CAs: DigiCert, GlobalSign, Sectigo, AlphaSSL, RapidSSL, GeoTrust, Thawte). Our goal is to ensure a smooth transition where we can, among other things, automatically find all certificates on a domain regardless of issuer, support automatic issuance and automatic DNS validation, pre-validated accounts, and much more.
Contact us to migrate Entrust certificates with +30 days and 50% off!
Or order directly in our portal with a RapidSSL, GeoTrust, Thawte, or DigiCert SSL certificate using the competitor upgrade order type and the text "ENTRUST 50% OFF" in the subject line, and we will reduce the price by 50% at invoicing and add an extra month to the certificate.