Google has put websites signed with WoSign/StartCom SSL certificates on notice that it will no longer trust SSL certificates from the Chinese CA starting in Chrome 61. Google last week said it will fully distrust remaining certificates issued by the CA starting last week. WoSign and its StartCom subsidiary were accused of a number of violations, starting last August when it was learned that the CA was back-dating deprecated SHA-1 certificates in order to side-step restrictions barring certs created with the insecure cryptographic hash function. Mozilla and other browser makers began an investigation of the CA after WoSign was accused of miss-issuing free certificates to one of its customers.
Source: https://threatpost.com/google-to-fully-distrust-wosignstartcom-ssl-certs-in-chrome-61/126729/

