Chrome Root Store policy update looking to require an automated option for obtaining certificates (blog.chromium.org)
from Spotlight7573@lemmy.world to technology@lemmy.world on 15 Oct 2023 15:05
https://lemmy.world/post/6836980

Upcoming Policy Changes

One of the major focal points of Version 1.5 requires that applicants seeking inclusion in the Chrome Root Store must support automated certificate issuance and management. […] It’s important to note that these new requirements do not prohibit Chrome Root Store applicants from supporting “non-automated” methods of certificate issuance and renewal, nor require website operators to only rely on the automated solution(s) for certificate issuance and renewal. The intent behind this policy update is to make automated certificate issuance an option for a CA owner’s customers.

#technology

threaded - newest

Sir_Kevin@lemmy.dbzer0.com on 15 Oct 2023 19:28 collapse

Can somebody ELI5?

astray@lemm.ee on 15 Oct 2023 20:07 collapse

Google trough the Chrome Project are pushing certificate authorities to offer automated certificates services to customers to make their use more prolific. Certificate authorities only have value if they are included in the certificate store, so they will do whatever it takes to be in there. Certificate authorities are the organizations we trust to say if a website is secure enough to display the lock in the browser instead of an error.

spacecowboy@sh.itjust.works on 16 Oct 2023 02:21 collapse

Hi I’m 5 years old and I have no clue what you just said.

Spotlight7573@lemmy.world on 16 Oct 2023 02:47 collapse

In order to know that you are talking to the right website on the web, you need someone else that you trust to say they are who they say they are. That is a Certificate Authority. They verify that the example.com you are talking to is the actual example.com through math that’s hard to fake. Currently, the process of performing this verification can be either done manually by a person or automatically through software depending on what the Certificate Authority supports. Chrome is planning on changing their policy to require that an automatic option be available for all Certificate Authorities, without necessarily taking away the manual option from those who still want to use it.

spacecowboy@sh.itjust.works on 16 Oct 2023 03:11 collapse

That was absolutely digestible by a 5 year old like me. Many thanks!