A seemingly technical change can have far-reaching consequences for Europe’s digital trust ecosystem. Following Google’s proposal to reduce the maximum validity of TLS certificates, including QWACs, to 90 days, ESD raises concerns about its impact on identity-based website authentication, competition and the objectives of eIDAS. ESD argues that rules affecting EU-regulated trust services should not be determined unilaterally through proprietary browser policies, particularly where they may conflict with European standards and favour particular technological or business models. Changes of this significance should be based on demonstrated security needs and developed through transparent, consensus-based processes that respect Europe’s regulatory framework and digital sovereignty.
Google Returns to Anti-Competitive Behavior by Limiting All Certificates to 90 Days Only – Will This Kill Identity Certificates and Make eIDAS Obsolete?
Technical Rules Should Not Override Europe’s Trust FrameworkCertificate Policies Must Support Security, Competition and European Digital Sovereignty.
Leave a Reply