When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath
Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

Key points
- In June 2024, Google's Chrome browser stopped trusting new security certificates issued by Entrust, a major digital identity company.
- Four certificate authorities have been removed from browsers since 2011, and each time recovery fell to individual IT teams with no national coordination plan.
- The CA/Browser Forum, the industry body that sets rules for certificate issuers, passed a new rule in July 2025 requiring issuers to test mass-revocation plans annually, but that rule does not bind the companies that rely on those certificates.
- The arrival of post-quantum cryptography standards means every organisation faces a forced migration of the security foundations underpinning the internet, on a timetable set by regulators and researchers, not by business calendars.
- No single agency currently owns cross-sector coordination when a major certificate authority loses browser trust.
Google pulled the trigger quietly. In June 2024, the Chrome browser team announced it would stop accepting new security certificates from Entrust, a company that acts as a digital identity authority for thousands of websites and online services. A certificate, in plain terms, is the digital document that lets your browser confirm a website is who it claims to be. Browsers ship with a pre-approved list of companies allowed to issue these documents. Remove one from that list, and every site relying on that company's certificates starts showing security warnings to visitors.
The Chrome decision followed years of compliance failures by Entrust. The technical call was correct. What nobody had a plan for was the morning after.
Why does this matter to ordinary people?
When a bank, hospital, or retailer suddenly loses its browser-trusted certificates, its website throws warnings, its transaction systems can stop authenticating, and customers get locked out. This is not a theoretical scenario.
Consider a regional bank whose only certificate supplier gets dropped by Chrome. The bank cannot issue new valid certificates. Its IT team scrambles to switch providers, but the supplier is overwhelmed with similar requests. Within hours, online banking is unreachable and regulators are calling. A competitor that used two different certificate suppliers notices nothing.
The history here is instructive. DigiNotar, a Dutch certificate authority, was breached in 2011 and issued more than 500 fraudulent certificates before browsers removed it; the company did not survive. Symantec's certificate business was wound down in 2017 after years of rule-breaking. TrustCor was dropped in 2022. In every case, individual IT teams swapped certificates before most customers noticed. Four clean recoveries. No national coordination needed.
That track record is the trap. It suggests the problem is solved. It is not. It has just not been tested at scale.
What is making this harder to manage?
Two forces are widening the risk.
First, governments and standards bodies are pushing organisations to migrate to post-quantum cryptography, meaning new mathematical methods for encrypting data that can resist attacks from future quantum computers. The U.S. National Institute of Standards and Technology published its approved post-quantum standards, known as FIPS 203, 204, and 205. Every organisation using the internet will have to upgrade. The schedule is not optional.
Second, artificial intelligence tools lower the cost for criminals to find weaknesses in certificate systems, run large-scale manipulation attempts against certificate authority staff, and probe the pipelines where certificates are signed and issued. Events that were once rare become more plausible.
The CA/Browser Forum passed a rule, known as Ballot SC-089, in July 2025 requiring every publicly trusted certificate issuer to maintain and annually test a plan for mass certificate revocation, meaning the ability to rapidly cancel thousands of certificates at once. That is a meaningful step. But it binds the issuers only. The hospitals, banks, and logistics companies that would absorb the disruption have no matching requirement to plan or rehearse.
| Event | Year | Certificates affected | Organisation fate |
|---|---|---|---|
| DigiNotar breach | 2011 | 500-plus fraudulent | Company closed |
| Symantec wind-down | 2017 | Millions migrated | Business sold off |
| TrustCor removal | 2022 | Undisclosed | Removed from roots |
| Entrust distrust | 2024 | New issuance blocked | Ongoing |
What should organisations do now?
Three steps are realistic this quarter, as the original analysis published in Dark Reading argues.
Build a full inventory of every certificate your organisation uses and who issued it. You cannot replace what you cannot find, and most teams are still missing this list.
Assign one person with clear authority to own certificate continuity and the power to pull colleagues in quickly when something breaks.
Run a tabletop exercise, meaning a structured rehearsal where staff talk through a scenario step by step: your primary certificate supplier is dropped by browsers in 30 days. Walk every system through it, write down where it breaks, and then run the same exercise against the post-quantum migration, because that one is already on the calendar. Using more than one certificate supplier means a distrust event becomes a switch rather than a rebuild from scratch.
No agency currently coordinates this across sectors. Until one does, the planning falls to individual organisations.



