When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath
Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

Key points
- In June 2024, Google's Chrome browser stopped trusting new security certificates issued by Entrust, a major digital identity company.
- Four certificate authorities have been removed from browsers since 2011, and each time recovery fell to individual IT teams with no national coordination plan.
- The CA/Browser Forum passed a rule in July 2025 requiring issuers to test mass-revocation plans annually, but that rule doesn't bind the companies that rely on those certificates.
- Post-quantum cryptography standards mean every organisation faces a forced migration of the security foundations underpinning the internet, on a timetable set by regulators, not business calendars.
- No single agency currently owns cross-sector coordination when a major certificate authority loses browser trust.
Google pulled the trigger quietly. In June 2024, the Chrome browser team announced it would stop accepting new security certificates from Entrust, a company that acts as a digital identity authority for thousands of websites and online services. A certificate is the digital document that lets your browser confirm a website is who it claims to be. Browsers ship with a pre-approved list of companies allowed to issue these documents. Remove one, and every site relying on that company's certificates starts showing security warnings to visitors.
Years of compliance failures by Entrust preceded the Chrome decision. The technical call was right. Nobody had a plan for the morning after.
Why does this matter to ordinary people?
When a bank or retailer suddenly loses its browser-trusted certificates, its website throws warnings, its transaction systems can stop authenticating, and customers get locked out. This isn't a theoretical scenario.
Consider a regional bank whose only certificate supplier gets dropped by Chrome. It can't issue new valid certificates. Its IT team scrambles to switch providers, but the supplier is overwhelmed with similar requests. Within hours, online banking is unreachable and regulators are calling. A competitor that used two different certificate suppliers notices nothing.
The history here is instructive. DigiNotar, a Dutch certificate authority, was breached in 2011 and issued more than 500 fraudulent certificates before browsers removed it; the company didn't survive. Symantec's certificate business was wound down in 2017 after years of rule-breaking. TrustCor was dropped in 2022. In every case, individual IT teams swapped certificates before most customers noticed. Four clean recoveries. No national coordination needed.
That track record is the trap. It suggests the problem is solved. It hasn't been tested at scale, though, and the conditions that made those past events survivable are eroding.
What is making this harder to manage?
Two forces are widening the risk.
First, NIST has published its post-quantum cryptography standards, meaning new mathematical methods for encrypting data that can resist attacks from future quantum computers, as FIPS 203, 204, and 205. Every organisation using the internet will have to upgrade. The schedule isn't optional, and planned migrations will get interrupted by sudden ones.
Second, artificial intelligence tools lower the cost for criminals to find weaknesses in certificate systems, run large-scale manipulation attempts against certificate authority staff, and probe the pipelines where certificates are signed. Rare events become more plausible.
The CA/Browser Forum passed a rule, known as Ballot SC-089, in July 2025 requiring every publicly trusted certificate issuer to maintain and annually test a plan for mass certificate revocation, meaning the ability to rapidly cancel thousands of certificates at once. Meaningful, but it binds issuers only. The enterprises and sectors that would absorb the disruption have no matching requirement to plan or rehearse. We first covered the DigiCert intrusion that sharpened this debate in our 17 July report on the CylindricalCanine break-in, which showed how quickly a compromised certificate giant becomes everyone's emergency.
| Event | Year | Certificates affected | Organisation fate |
|---|---|---|---|
| DigiNotar breach | 2011 | 500-plus fraudulent | Company closed |
| Symantec wind-down | 2017 | Millions migrated | Business sold off |
| TrustCor removal | 2022 | Undisclosed | Removed from roots |
| Entrust distrust | 2024 | New issuance blocked | Ongoing |
What should organisations do now?
Three steps are realistic this quarter, as the original analysis published in Dark Reading argues.
Build a full inventory of every certificate your organisation uses and who issued it. You can't replace what you can't find, and most teams are still missing this list.
Assign one person with clear authority to own certificate continuity and the power to pull colleagues in quickly when something breaks.
Run a tabletop exercise, meaning a structured rehearsal where staff talk through a scenario step by step: your primary certificate supplier is dropped by browsers in 30 days. Walk every system through it and write down where it breaks. Then run the same exercise against the post-quantum migration, because that one's already on the calendar. Issuing from more than one certificate supplier means a distrust event becomes a switch rather than a rebuild from scratch.
No agency currently coordinates this across sectors. The beat reporter's read: the four past recoveries are being treated as proof of resilience when they're actually proof of luck at a scale nobody has yet had to match. Until a named coordinator exists with a named playbook, every organisation is effectively self-insured against a risk it probably can't see in its own inventory.



