iTnews

Google dumps Symantec SSL certificate in Chrome, Android

By Juha Saarinen on Dec 14, 2015 6:51AM
Google dumps Symantec SSL certificate in Chrome, Android

No longer trusted.

Google has decided to cull a Symantec root certificate used to secure internet communications, the company revealed.

Starting 2 December Australian time, Symantec's Class 3 Public Primary Certificate Authority (CA) root certifcate is no longer trusted by Google in its Chrome web browser, Android mobile operating system and other products.

Google software engineer Ryan Sleevi explained over the weekend Symantec intended to use the root certificate for reasons other than creating publicly trusted credentials. The certificate also no longer complies with the industry Certificate Authority/Browser Forum baseline requirements for best practice, Symantec said.

As a result of the above, Sleevi said "Google is no longer able to ensure that the root certificate, or certificates issued from this root certificate, will not be used to intercept, distrupt, or impersonate the secure communications of Google's products or users".

Symantec would not reveal the other uses for the root certificate. According to Sleevi, Symantec said it is aware of the risk to Google users and requested the online giant takes preventative action and remove and distrust the root certificate.

The Symantec Class 3 Public Primary CA root certiicate is widely trusted not just by Google products, but also by Microsoft's Windows operating system. Apple OS X versions before 10.11 also trusted the Symantec certificate.

Sleevi said that Symantec's failure to comply with the CA/browser forum requirements for publicly trusted certificates represented "an unacceptable risk to users of Google products".

In October this year, Google demanded that Symantec undergo audits to ensure the company follows best industry practices and is fit to run a certificate authority.

Earlier this year, Symantec fired an unknown number of employees for wrongly issuing a large number of fake digital certificates which could be used to authenticate and impersonate Google and other internet domains.

Update: Symantec told iTnews the certificate removal had been initiated by itself, not Google.

“In keeping with industry standards and best practices, Symantec notified major browsers in November, including Google, that they should remove or untrust a legacy root certificate from their lists called the VeriSign Class 3 Public Primary Certification Authority G1 (PCA3-G1),” a spokesperson for the security vendor said.

"We advised this action because this particular root certificate is based on older, lower-strength security that is no longer recommended, hasn’t been used to generate new certificates in several years, and will now be repurposed to provide transition support for some of our enterprise customers’ legacy, non-public applications. 

"By announcing that they will be blocking this root certificate, Google has indicated that they intend to do exactly as we requested, a step that other browsers started taking in 2014,” the spokesperson said.

Update II: The first paragraph of the story has been amended to better reflect that Google will only distrust one Symantec root certificate.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
certificategooglesecurityssltlsssltlscertificatessymantec

Partner Content

Tick off the ransomware bandits
Promoted Content Tick off the ransomware bandits
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
How a 'micro data centre' enables your business, your way
Promoted Content How a 'micro data centre' enables your business, your way
Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Juha Saarinen
Dec 14 2015
6:51AM
0 Comments

Related Articles

  • Google adds phishing protection to Workspace apps
  • F5 BIG-IP systems vulnerable to remote takeover
  • Google's VirusTotal service vulnerable for over eight months
  • Record number of same-old zero days detected in 2021
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

Telstra to open its 5G network to wholesale customers

Telstra to open its 5G network to wholesale customers

Active Directory defaults lead to no-fix PrivEsc vulnerability

Active Directory defaults lead to no-fix PrivEsc vulnerability

Westpac promotes its head of technology to mortgage role

Westpac promotes its head of technology to mortgage role

Digital Nation

As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.