I’m not sure how you want to communicate this to the community but the 600 lbs. gorilla on the internet (Google) moved the 90 day certificate date up on its own without agreement from the CA/Browser Forum.
Darryl Baker, GSEC, GCLD (he/him/his) Sr. System Administrator Distributed Application Platform Services Northwestern University 4th Floor 2020 Ridge Avenue Evanston, IL 60208-0801 [email protected]<mailto:[email protected]> (847) 467-6674<tel:+18474676674> From: <[email protected]> on behalf of Ted Pham <[email protected]> Reply-To: "[email protected]" <[email protected]> Date: Thursday, October 1, 2026 at 4:10 PM To: "[email protected]" <[email protected]> Subject: Re: [cert-users] certificate lifetime changes Hi all, Expanding on what Don and others have said. In this context, "Google" refers to the Google Chrome Root Program. They updated their policies to be stricter to encourage adoption of the new CA/B Forum standards and avoid delaying published lifecycle change dates (e.g. like the client authentication EKU change date was delayed). Those new policies apply to certificates signed by the new root and intermediate certificates submitted to the program and the operation of the CAs that perform the issuance. CERTInext submitted the new InCommon intermediate certificates to the Google Chrome Root Program soon after the InCommon transition announcement went public in early April. And that's when CERTInext was informed that Google wanted TLS server certificates signed by the new intermediate to be 90 day ones (i.e. more aggressive than CA/B Forum standards). We all gave strong feedback that this was not feasible for our community especially with having to transition CA platforms. That led CERTInext to appeal to Google. And Google granted an extension allowing 6-month certificates until the end of 2026. Ted Pham Information Security Office Carnegie Mellon University On Thu, Oct 1, 2026 at 4:11 PM Don Rhodes <[email protected]<mailto:[email protected]>> wrote: For #2, you are correct, Google was applying stricter guidelines to NEW CA's. Incommon/CertiNext was able to negotiate the 2026-12-31 date instead of day 1 when we all switched over. On Thu, Oct 1, 2026 at 3:43 PM James Clark <[email protected]<mailto:[email protected]>> wrote: Hello. From earlier list discussion, my understanding is: - After Dec 31, 2026 InCommon CERTInext certs will have a maximum 90 day lifetime. - This is earlier than the CA/B date of March 15, 2027, and is driven by Google policy. Two questions: 1. Is there a document listing all future lifetime changes through 2029, including transition dates and details such as DCV reuse periods? 2. Other CAs still cite the March 2027 date. Why does Google policy affect CERTInext differently - stricter rules for newer CAs? Thanks. jc -- James Clark Director of Information Security The University of Chicago 773.702.1322<tel:(773)%20702-1322> / 773.702.2378<tel:(773)%20702-2378> (2-CERT) security.uchicago.edu<https://urldefense.com/v3/__http:/security.uchicago.edu__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZzzajrKQg$> To unsubscribe from this list, send a message to [email protected]<mailto:[email protected]> with the subject: unsubscribe cert-users Questions? Need assistance? https://urldefense.com/v3/__https://incommon.org/certificates/support-for-certificates/__;!!J5Kq4r0IJLSOGzF5uA!oHvMcae2ItIhDD73a7WwQ-Vn5YGMj9e3Odiw07ONEP4E_Uh4TTNtNq_QlZtdEsLyn28V0t8-o7P76XhZJ2BY$<https://urldefense.com/v3/__https:/incommon.org/certificates/support-for-certificates/__;!!J5Kq4r0IJLSOGzF5uA!oHvMcae2ItIhDD73a7WwQ-Vn5YGMj9e3Odiw07ONEP4E_Uh4TTNtNq_QlZtdEsLyn28V0t8-o7P76XhZJ2BY$> -- --... ...-- Don Rhodes Associate Director of Infrastructure Services Information Technology Services - Colgate University 315-228-1000<tel:(315)%20228-1000> www.colgate.edu<https://urldefense.com/v3/__http:/www.colgate.edu__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZyhxRA1Zg$> Disclaimers in email are legally meaningless http://www.economist.com/node/18529895<https://urldefense.com/v3/__http:/www.economist.com/node/18529895__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZxq4EJ79Q$> To unsubscribe from this list, send a message to [email protected]<mailto:[email protected]> with the subject: unsubscribe cert-users Questions? Need assistance? https://incommon.org/certificates/support-for-certificates/<https://urldefense.com/v3/__https:/incommon.org/certificates/support-for-certificates/__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZz_h9aoJQ$>
To unsubscribe from this list, send a message to [email protected] with the subject: unsubscribe cert-users Questions? Need assistance? https://urldefense.com/v3/__https://incommon.org/certificates/support-for-certificates/__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZz_h9aoJQ$
--------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
