3 ms·
Amusing that security.googleblog.com itself is using a TLS certificate ultimately signed by GeoTrust Inc, which is owned by Symantec.
by rand_r 9y ago
Amusing that security.googleblog.com itself is using a TLS certificate ultimately signed by GeoTrust Inc, which is owned by Symantec.
- pfg 9y agoFun fact: one of the "independently-operated and audited subordinate CAs" that is exempt from this is, yep, you guessed it, Google. They've recently acquired a GlobalSign root and are in the process of getting their own roots added to trust stores, but I imagine they'll want to keep chaining back to the widely-trusted GeoTrust root for a few more years. (IIRC Apple is on that exception list too.)
- Ajedi32 9y agoActually, that subordinate CA isn't affected. See: https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md https://chromium.googlesource.com/chromium/src/+/master/net/... And the blog post states: > This will affect any certificate chaining to Symantec roots, except for the small number issued by the independently-operated and audited subordinate CAs previously disclosed to Google.
- bitmapbrother 9y agoFormerly owned. They agreed to sell their certificate business to DigiCert.