Skip to main content
banner image
venafi logo

Top 6 Reasons to Switch Certificates Authorities—Symantec Isn’t the First and Won’t Be the Last

Top 6 Reasons to Switch Certificates Authorities—Symantec Isn’t the First and Won’t Be the Last

distrust symantec certificates
January 4, 2018 | Mike Dodson

Based on a relatively long string of errors made by Symantec certificate authorities (CAs), major browser makers Google and Mozilla have stated that they will revoke the trust of certificates issued by Symantec or certificates that chain to a Symantec root. That includes the widely known Thawte, VeriSign, Equifax, GeoTrust and Rapid SSL brands. Both Google and Mozilla have published timelines for this distrust, which will trigger untrusted connection errors for all impacted certificates as early as April, 2018. But sadly, Symantec’s mistakes are not all that uncommon in the industry.

As the largest issuer of extended validation (EV) certificates, perhaps Symantec’s foibles are more visible than other CAs. But Symantec is certainly not the only CA to fall prey to human error or policy failures. There are a number of ways in which CAs can inadvertently compromise the security of certificates that they issue. And this, in turn, will impact the trust of the machine identities that protect your organization.



I’ll outline the six major CA errors that can impact the trust of certificates below.



The trust model on which the internet is currently (and has been) designed has many single points of failure and each CA is one of them. Every time a CA breaks the trust we place in them, regardless whether it’s intentional or accidental, someone on the internet is harmed. And the next time it happens, it maybe you or your organization. You need to be prepared to act quickly if your certificates are impacted in any way.

In the next post, we’ll talk about how to minimize the chances of your organization being impacted by a breach of CA trust.

Learn more about machine identity management. Explore now.


Related blogs

Like this blog? We think you will love this.
Featured Blog

Exposed TLS Certificates Force PKI Lead to Quit: How Badly Managed PKI Poses Serious Risk [Case Study]

'I'm out of here' — PKI lead  That’s th

Read More
Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

Subscribe Now

See Popular Tags

You might also like

TLS Machine Identity Management for Dummies

TLS Machine Identity Management for Dummies

Certificate-Related Outages Continue to Plague Organizations
White Paper

CIO Study: Certificate-Related Outages Continue to Plague Organizations

About the author

Mike Dodson
Mike Dodson

Mike is VP of World-Wide Customer Security Strategy and Solutions at Venafi. With an MS in Engineering and nearly 20 years experience, his skillsets include data analysis, taking products to market, aligning business and technical requirements, UI/UX design and public speaking.

Read Posts by Author
get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon
Venafi Risk assessment Form Image

Sign up for Venafi Cloud

Venafi Cloud manages and protects certificates

* Please fill in this field Please enter valid email address
* Please fill in this field Password must be
At least 8 characters long
At least one digit
At last one lowercase letter
At least one uppercase letter
At least one special character
* Please fill in this field
* Please fill in this field
* Please fill in this field

End User License Agreement needs to be viewed and accepted

Already have an account? Login Here

get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more