March 15, 2029 is the final step of ballot SC-081v3's schedule: maximum TLS certificate validity falls to 47 days and domain validation reuse to just 10 days. Without automation, renewals become a weekly operational burden.

PKI News
Certificate authority actions, TLS updates, and FixMyCert analysis
A continuously maintained feed of certificate authority actions, TLS/SSL certificate-validity changes, browser root-program updates, and post-quantum developments — plus first-party FixMyCert analysis on what each change means for your infrastructure.
73
Articles
0
Sources
2
Priority Items
20
FixMyCert Analysis
An autonomous AI agent turned a single code-execution foothold into a network-wide breach by harvesting standing cloud and cluster credentials and moving laterally across internal clusters. The identity lesson is precise: short-lived, attested workload identities (SPIFFE/SPIRE) remove the static credential an attacker harvests and replays. They would not have stopped the break-in, but they would have contained it. Here is what workload identity would and would not have changed.
S/MIME BRs v1.0.15 also closes the issuance path for legacy intermediates: from September 15, 2027, CAs may not issue Subscriber certificates from any Subordinate CA whose RSA modulus is under 3072 bits. Certificates already issued are not revoked — renewals simply arrive under a different intermediate, which matters wherever that chain was pinned or manually installed. This is separate from the 2026 rule requiring newly created CA keys to be 4096-bit.
S/MIME BRs v1.0.15 (ballot SMC017v2, published July 30, 2026) raise the minimum RSA key size for Root and Subordinate CA certificates from 2048 to 4096 bits. The trigger is the key creation date, not certificate issuance — key material generated on or before September 15, 2026 remains usable under the 2048-bit minimum. Subscriber certificates are unaffected.
On September 21, 2026, NIST CMVP moves all remaining active FIPS 140-2 certificates to Historical status. Modules keep running, but federal procurement requires FIPS 140-3 going forward.
From January 1, 2027, US National Security Systems must begin acquiring CNSA 2.0-compliant products — the procurement trigger in NSA's post-quantum timeline.
SP 800-131A Rev 3 would end approved federal use of 112-bit security strength on December 31, 2030 — affecting RSA-2048, ECC P-224, and 3DES. Still an initial public draft: published October 2024, comment period closed December 2024, no final issued. Plan the RSA-2048 upgrade path against the date, but treat it as draft guidance.
March 15, 2028 completes the sunset of every legacy DCV method under SC-080, SC-090, and SC-091 — email-based, phone-based, and crossover methods are all gone. Only modern DNS, HTTP, and ACME-based validation remains.
Per MRSP v3.1, CA operators with TLS-enabled roots must obtain Detailed Controls Reports (DCRs) for audit periods starting on or after July 1, 2027 — a significant step up in audit transparency.
Ballot CSC-32 makes the reserved policy OID mandatory in code signing certificates under Code Signing BRs v3.11.0 §7.1.6.4, effective September 15, 2026.
NSA's CNSA 2.0 timeline calls for operating systems to support and prefer quantum-resistant algorithms by December 31, 2027.
IR 8547 sets out NIST's expected approach: RSA, ECDSA, DH, and ECDH disallowed and removed from NIST standards after December 31, 2035. Still an initial public draft — published November 2024, comment period closed January 2025, not yet final — so directional rather than binding.
The Microsoft Trusted Root Program's PQC TLS Pilot V1.0 lets approved CAs operate one ML-DSA-87 pilot root — the first root-store on-ramp for post-quantum TLS certificates.
NSA's CNSA 2.0 timeline calls for VPNs, routers, and traditional network equipment to support and prefer quantum-resistant algorithms by the end of 2026.
Microsoft Trusted Root Program Requirements v1.2 apply to root certificates submitted on or after July 1, 2026: new roots must be single-purpose and capped at 10 years validity.
By July 1, 2027, CAs in Mozilla's program must fully comply with MRSP CP/CPS content and quality requirements (item 2 and §§3.3.1–3.3.6).
Under MRSP v3.0, all CA operators must finish migrating from dual-purpose roots to dedicated TLS-only or S/MIME-only hierarchies by December 31, 2028.
OMB Memo M-26-15 (Execution of the Migration to Post-Quantum Cryptography) requires executive agencies to submit PQC migration plans to OMB and ONCD by October 22, 2026.
From September 15, 2027, Chrome enforces its Root Store consolidation: CA owners are capped at two self-signed roots, per the plans submitted in June 2026 (Chrome Root Program Policy v1.8 §1.2.1).
Ballot SC-090 prohibits all email-based DCV methods (constructed email, email to DNS CAA/TXT contacts, and more) from March 15, 2028. Certificates validated via email approval must move to DNS- or HTTP-based methods.