I’m not sure how you want to communicate this to the community but the 600 lbs. 
gorilla on the internet (Google) moved the 90 day certificate date up on its 
own without agreement from the CA/Browser Forum.

Darryl Baker, GSEC, GCLD  (he/him/his)
Sr. System Administrator
Distributed Application Platform Services
Northwestern University
4th Floor
2020 Ridge Avenue
Evanston, IL  60208-0801
[email protected]<mailto:[email protected]>
(847) 467-6674<tel:+18474676674>

From: <[email protected]> on behalf of Ted Pham <[email protected]>
Reply-To: "[email protected]" <[email protected]>
Date: Thursday, October 1, 2026 at 4:10 PM
To: "[email protected]" <[email protected]>
Subject: Re: [cert-users] certificate lifetime changes

Hi all,

Expanding on what Don and others have said.

In this context, "Google" refers to the Google Chrome Root Program. They 
updated their policies to be stricter to encourage adoption of the new CA/B 
Forum standards and avoid delaying published lifecycle change dates (e.g. like 
the client authentication EKU change date was delayed). Those new policies 
apply to certificates signed by the new root and intermediate certificates 
submitted to the program and the operation of the CAs that perform the issuance.

CERTInext submitted the new InCommon intermediate certificates to the Google 
Chrome Root Program soon after the InCommon transition announcement went public 
in early April. And that's when CERTInext was informed that Google wanted TLS 
server certificates signed by the new intermediate to be 90 day ones (i.e. more 
aggressive than CA/B Forum standards). We all gave strong feedback that this 
was not feasible for our community especially with having to transition CA 
platforms. That led CERTInext to appeal to Google. And Google granted an 
extension allowing 6-month certificates until the end of 2026.

Ted Pham
Information Security Office
Carnegie Mellon University


On Thu, Oct 1, 2026 at 4:11 PM Don Rhodes 
<[email protected]<mailto:[email protected]>> wrote:
For #2, you are correct, Google was applying stricter guidelines to NEW CA's. 
Incommon/CertiNext was able to negotiate the 2026-12-31 date instead of day 1 
when we all switched over.


On Thu, Oct 1, 2026 at 3:43 PM James Clark 
<[email protected]<mailto:[email protected]>> wrote:
Hello. From earlier list discussion, my understanding is:

- After Dec 31, 2026 InCommon CERTInext certs will have a maximum 90 day 
lifetime.
- This is earlier than the CA/B date of March 15, 2027, and is driven by Google 
policy.

Two questions:

1. Is there a document listing all future lifetime changes through 2029, 
including transition dates and details such as DCV reuse periods?

2. Other CAs still cite the March 2027 date. Why does Google policy affect 
CERTInext differently - stricter rules for newer CAs?

Thanks.
jc


--
James Clark
Director of Information Security
The University of Chicago
773.702.1322<tel:(773)%20702-1322> / 773.702.2378<tel:(773)%20702-2378> (2-CERT)
security.uchicago.edu<https://urldefense.com/v3/__http:/security.uchicago.edu__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZzzajrKQg$>
To unsubscribe from this list, send a message to 
[email protected]<mailto:[email protected]> with the subject: unsubscribe 
cert-users

Questions? Need assistance? 
https://urldefense.com/v3/__https://incommon.org/certificates/support-for-certificates/__;!!J5Kq4r0IJLSOGzF5uA!oHvMcae2ItIhDD73a7WwQ-Vn5YGMj9e3Odiw07ONEP4E_Uh4TTNtNq_QlZtdEsLyn28V0t8-o7P76XhZJ2BY$<https://urldefense.com/v3/__https:/incommon.org/certificates/support-for-certificates/__;!!J5Kq4r0IJLSOGzF5uA!oHvMcae2ItIhDD73a7WwQ-Vn5YGMj9e3Odiw07ONEP4E_Uh4TTNtNq_QlZtdEsLyn28V0t8-o7P76XhZJ2BY$>



--
--... ...--
Don Rhodes
Associate Director of Infrastructure Services
Information Technology Services - Colgate University
315-228-1000<tel:(315)%20228-1000>
www.colgate.edu<https://urldefense.com/v3/__http:/www.colgate.edu__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZyhxRA1Zg$>

Disclaimers in email are legally meaningless 
http://www.economist.com/node/18529895<https://urldefense.com/v3/__http:/www.economist.com/node/18529895__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZxq4EJ79Q$>
To unsubscribe from this list, send a message to 
[email protected]<mailto:[email protected]> with the subject: unsubscribe 
cert-users

Questions? Need assistance? 
https://incommon.org/certificates/support-for-certificates/<https://urldefense.com/v3/__https:/incommon.org/certificates/support-for-certificates/__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZz_h9aoJQ$>

To unsubscribe from this list, send a message to [email protected] with the 
subject: unsubscribe cert-users

Questions? Need assistance? 
https://urldefense.com/v3/__https://incommon.org/certificates/support-for-certificates/__;!!Dq0X2DkFhyF93HkjWTBQKhk!RIkGz_Nq3eII_I2HlSJ5wr_ocnhTtIkD1M5zMgmjt9uvzJAdGCUiFJkPIqPmdu-ngVY0xAS4wJpdWO1JbZz_h9aoJQ$
 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to