Google appears to be trying to become a completely independent company, as it announced the launch of its own root certificate authority.
With this new move, Google will stop relying on intermediate certificate issuing companies, specifically the GIAG2 it has been using until now.
“As we look ahead to the evolution of both the internet and our own products, it’s clear that HTTPS will continue to be a core technology. That’s why we’ve made the decision to expand our current Certificate Authorities to include the operation of our own root certificate authority,” says Ryan Hurst, Google’s product manager.
Thus was born Google Trust Services, a company that will issue certificates on behalf of Google and Alphabet.
This whole process will take time, however. Integrating new root certificates into products and waiting for the relevant versions of those products to be developed takes a lot of time. So Google acquired two existing Root Certificate Authorities, GlobalSign R2 and R4, which will allow the company to start issuing independent certificates much faster.
In the meantime, Google will continue to use its existing GIAG2 certificates for now at least.
“If you are developing products that intend to connect to a Google service, you should use the above root certificates. That way, even if we release our own certificates, you can still choose to have them work with third-party certificates.”
Google advises developers seeking to connect their applications to the company's services to include a broad set of trusty roots in their products.
