Google finally gets strict about web server certificates

Google finally gets strict about web server certificates

Computerworld

Published

Historically, when companies roll out new capabilities, they start out lenient to encourage usage. Take facial biometrics for example. When they first went into use, the initial settings were chosen to make it easier for the biometrics to work. Yes, it meant more imposters would get a green light, but it sharply limited friction for legitimate users. 

Google and many certificate authorities used a similar playbook with web server certificates, allowing them to be used for all kinds of authentication functions instead of just the web server function they were designed for.

That all ends, in theory, on June 15, 2026, 

Full Article