LICENSEWARE

Entrust public certificate business and TLS distrust

This article is about the browser and operating system distrust decisions affecting Entrust public TLS certificates in 2024 and the sale of the Entrust public certificate business to Sectigo in 2025, as described by Entrust. It is not about Entrust private PKI, which is covered in the Cryptographic Security Platform article, and it is not legal advice.

On This Page

Between mid-2024 and late 2025 the position of Entrust public certificates changed fundamentally. Browser and operating system vendors announced that they would stop trusting certificates issued from Entrust public roots after set dates, Entrust sold its public certificate business to Sectigo, and the Entrust Certificate Services (ECS) portal stopped acting as a public trust certificate authority. For a licence manager the practical effects are about inventory and renewal: which certificates were issued by which authority, when they expire, and which vendor contract now governs replacements. This article sets out the sequence as Entrust itself describes it. It does not describe the underlying browser programme decisions in the browser vendors’ own words, because only Entrust documents are cited.

The Chrome Root Program decision

On 2024-07-01 Entrust’s president and chief executive published a statement that Google had announced it would no longer include Entrust root CA certificates in the Chrome Root Program, so that “the TLS certificates we issue after October 31, 2024, will no longer be trusted within the Chrome Root Store Program”.[1] The statement attributes the recent mis-issuance incidents to “a misinterpretation we made of CA/Browser Forum compliance requirements”, and says Entrust had provided extensions and delays in revocations that the CA/Browser Forum Requirements, which mandate five-day revocation for all mis-issuances, did not support.[1] It lists organisational changes, including moving the CA product compliance team into the global compliance and operations teams and creating a change control board and a technical change review board.[1] A banner on the post notes that browser programs have since updated the timing of when the decisions take effect and refers readers to the TLS Certificate Information Center.[1]

The statement does not say that certificates already issued stop working on the cut-off date. The cut-off concerns certificates issued after the stated date, and the Apple notice, quoted below, states the same for Apple systems.

The Apple change

Entrust’s Apple notice reports that Apple posted an update under which “TLS, S/MIME, Timestamping, and VMC certificates issued from Entrust public roots after November 15, 2024 will no longer be supported on Apple systems”.[2] Certificates issued on or before that date are expected to function until their natural expiry.[2] The notice describes consequences for secure email, which affects only email clients that rely on the Apple Root Store, including Apple Mail, Safari and Outlook 365 on Mac: signed emails may not validate, and recipients may face difficulty exchanging public keys for encryption. For Verified Mark Certificates used with BIMI, recipients on Apple mail domains may no longer see the verified logo, while Gmail recipients are not affected.[2] Entrust said it had arranged with Sectigo to replace S/MIME certificates that do not function as expected.[2]

The sale to Sectigo

On 2025-01-29 Entrust announced the sale of its public certificate business to Sectigo. The press release says the sale lets Entrust focus on identity, issuance and post-quantum ready cryptographic data security, and that the “terms of the agreement are not being disclosed”.[3] The company stated that it would continue to provide private and managed PKI, certificate lifecycle management (CLM) and digital signing, and described its portfolio as including identity and financial card issuance, identity and access management, digital identity verification, digital signing, private certificates, HSMs, and lifecycle management for certificates, keys and secrets.[3] The press release does not itself list the certificate types in the sale; the TLS Certificate Information Center refers to public TLS, S/MIME and code signing certificates in its migration dates.[4]

Transition timeline

The TLS Certificate Information Center records the following dates:[4]

Date Event (as stated by Entrust) 
February 12 (year not stated) Customers who had already configured SSL.com could still issue with SSL.com as issuing CA; others could only select Sectigo 
2025-03-11 Entrust stopped issuing public TLS certificates from Entrust root CAs; certificates issued before that date remain valid until expiry 
2025-05-12 End of issuance for S/MIME and VMC certificates; existing certificates remain valid until expiry 
2025-06-09 and 2025-06-24 Two steps of the Automated Migration Tool released in ECS for direct enterprise customers 
2025-07-14 Entrust eStore retail customers moved to the Sectigo platform 
2025-07-15 Migration tool available to Entrust partners 
2025-09-08 ECS in read-only mode for public trust certificates; Sectigo to migrate remaining accounts automatically 
2025-09-17 Read-only access in ECS ends 
2025-09-18 Migration complete 

The page’s heading dated 2025-09-18 states that Entrust completed the transition and that questions and support requests should go to Sectigo.[4] It adds that Entrust “discontinued Public Trust CA services in the Entrust Certificate Services (ECS) portal”, and that customers can issue Sectigo certificates through the ECS user interface and APIs.[4]

Contract and pricing continuity

Under the heading on continuity, Entrust states: “Sectigo will honor the terms of your existing Entrust contract.”[4] A licence manager should read this as Entrust’s statement of intent. The binding position is whatever the customer’s agreement and any assignment or novation notice say, and the Entrust page does not describe how existing quantities, renewal prices or term dates are carried over. The FAQ list on the same page includes the question “Will my current pricing change?”, but the answers are collapsed behind questions and are not stated in the page text this article relies on.

What to inventory

  1. Certificates by issuer. Identify certificates issued by Entrust public roots before and after 2025-03-11, because those issued before remain valid until expiry while new ones cannot come from Entrust roots.[4]
  2. Certificates used on Apple systems and Chrome. Entrust’s notices attach cut-off dates to issuance, not use, so older certificates remain usable until expiry but cannot be replaced from the same roots.[1][2]
  3. S/MIME and VMC certificates. End of issuance was 2025-05-12, so renewals need another authority.[4]
  4. Accounts and users. ECS public-trust accounts were migrated to the Sectigo certificate manager, so the administrators, organisations and domains need to be confirmed there.[4]
  5. Contract. Confirm the order, renewal and support terms that apply after the transition.

Out of scope

This article does not cover private PKI, PKI as a Service or the Cryptographic Security Platform, which Entrust continues to sell,[3] nor does it describe Sectigo’s own licensing terms, which are not Entrust documents. It does not assess the merits of the browser decisions.

References

  1. Thoughts on the Google Chrome AnnouncementBlog post by Entrust dated 2024-07-01; carries a note that browser programs updated the timing.Effective 2024-07-01. Retrieved 2026-10-08.
  2. Apple Changes Regarding Entrust RootsEntrust notice on Apple root store changes. Undated.Retrieved 2026-10-08.
  3. Entrust Sells Public Certificate Business to Sectigo, Sharpening Focus on Quantum-Ready Cryptographic Data Security SolutionsPress release dated 2025-01-29.Effective 2025-01-29. Retrieved 2026-10-08.
  4. TLS Certificate Information CenterKey dates and continuity statements; states completion on 2025-09-18.Effective 2025-09-18. Retrieved 2026-10-08.

See also

Catalog Rows Cited

4Rules1Programs

Esc