Generic CC0 editorial illustration

Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical mail, phone calls, or emails, we are closing potential loopholes for attackers and pushing the ecosystem toward automated, cryptographically verifiable security. To…

Editorial note. This page preserves feed metadata and a bounded excerpt for discovery. It does not reproduce the publisher's complete article.

Open the complete publication at Google Security Blog →

Record details

  • Local record: 5ea3583178bac56647bb
  • Source feed: Google Security Blog
  • Published: 2025-12-10T20:00:00Z