GeoTrust Universal CA is disabled on Windows from August 27 — unlike a NotBefore distrust, every certificate under it fails, whatever its issue date. Inventory GeoTrust chains now; Baltimore expired in 2025 and is cleanup.

PKI News
Certificate authority actions, TLS updates, and FixMyCert analysis
A continuously maintained feed of certificate authority actions, TLS/SSL certificate-validity changes, browser root-program updates, and post-quantum developments — plus first-party FixMyCert analysis on what each change means for your infrastructure.
77
Articles
0
Sources
3
Priority Items
20
FixMyCert Analysis
March 15, 2029 is the final step of ballot SC-081v3's schedule: maximum TLS certificate validity falls to 47 days and domain validation reuse to just 10 days. Without automation, renewals become a weekly operational burden.
An autonomous AI agent turned a single code-execution foothold into a network-wide breach by harvesting standing cloud and cluster credentials and moving laterally across internal clusters. The identity lesson is precise: short-lived, attested workload identities (SPIFFE/SPIRE) remove the static credential an attacker harvests and replays. They would not have stopped the break-in, but they would have contained it. Here is what workload identity would and would not have changed.
CNAME-delegated domain validation that renews cleanly today can start failing on November 15 with no change on your side, as SC-101v2 makes the ADN derivation algorithm mandatory. Check your delegations now.
From September 15, every CA Owner's CP/CPS must explicitly state adherence to the CCADB Policy — and June's Chrome attestation does not satisfy it, because that one names the Chrome Root Program Policy. Schedule the revision now.
From September 15, certificates issued under 19 fully distrusted roots fail Windows validation — existing ones keep working, so this breaks renewals, not production. More roots are hit for specific uses only: check per-EKU.
Apple Root Program Policy v2.0 took effect August 1, 2026: every Subordinate CA certificate must now carry an EKU and must not assert anyExtendedKeyUsage. From July 1, 2027 each Sub-CA must be dedicated to a single Trust Purpose.
NIST's Round 3 page now lists HAWK as withdrawn by its submission team, following a key-recovery weakness disclosed July 28, 2026. HAWK was a candidate, never a standard — FIPS 203, 204 and 205 are unaffected.
Let's Encrypt disclosed on August 10, 2026 that its CP/CPS lacked the explicit Chrome Root Program and CCADB compliance attestation required from June 15, 2026. The gap is in the policy document, not in issuance practice.
Ballot SC103 would move EKU profile requirements for cross-certified Subordinate CAs out of CCADB policy and into the TLS Baseline Requirements. Per the July 30, 2026 SCWG minutes it remains in discussion, with no vote scheduled and no effective date.
S/MIME BRs v1.0.15 also closes the issuance path for legacy intermediates: from September 15, 2027, CAs may not issue Subscriber certificates from any Subordinate CA whose RSA modulus is under 3072 bits. Certificates already issued are not revoked — renewals simply arrive under a different intermediate, which matters wherever that chain was pinned or manually installed. This is separate from the 2026 rule requiring newly created CA keys to be 4096-bit.
S/MIME BRs v1.0.15 (ballot SMC017v2, published July 30, 2026) raise the minimum RSA key size for Root and Subordinate CA certificates from 2048 to 4096 bits. The trigger is the key creation date, not certificate issuance — key material generated on or before September 15, 2026 remains usable under the 2048-bit minimum. Subscriber certificates are unaffected.
The Microsoft Trusted Root Program's PQC TLS Pilot V1.0 lets approved CAs operate one ML-DSA-87 pilot root — the first root-store on-ramp for post-quantum TLS certificates.
IR 8547 sets out NIST's expected approach: RSA, ECDSA, DH, and ECDH disallowed and removed from NIST standards after December 31, 2035. Still an initial public draft — published November 2024, comment period closed January 2025, not yet final — so directional rather than binding.
Microsoft Trusted Root Program Requirements v1.2 apply to root certificates submitted on or after July 1, 2026: new roots must be single-purpose and capped at 10 years validity.
NSA's CNSA 2.0 timeline calls for VPNs, routers, and traditional network equipment to support and prefer quantum-resistant algorithms by the end of 2026.
From January 1, 2027, US National Security Systems must begin acquiring CNSA 2.0-compliant products — the procurement trigger in NSA's post-quantum timeline.
Ballot CSC-32 makes the reserved policy OID mandatory in code signing certificates under Code Signing BRs v3.11.0 §7.1.6.4, effective September 15, 2026.
OMB Memo M-26-15 (Execution of the Migration to Post-Quantum Cryptography) requires executive agencies to submit PQC migration plans to OMB and ONCD by October 22, 2026.
On September 21, 2026, NIST CMVP moves all remaining active FIPS 140-2 certificates to Historical status. Modules keep running, but federal procurement requires FIPS 140-3 going forward.