Certificate authority risk review
SSL Certificate Brands to Avoid in 2026
A certificate brand should not be rejected because it changed owners. This list focuses on documented browser distrust, repeated CA compliance failures, and private-key handling incidents that can affect real buyers.
Evidence cutoff: August 5, 2026. Each conclusion below is limited to the named historical PKI, trust chain, seller practice, or product use case. It is not a claim that every certificate associated with the same brand name is currently invalid or untrusted.
Review our negative-review methodology or send current contrary evidence to [email protected].
Short answer
For new public TLS purchases in 2026, we would avoid certificates that still depend on the affected Entrust or AffirmTrust roots, any listing that genuinely uses the retired Symantec public PKI, and sellers whose current private-key handling cannot be independently verified after a serious historical incident. We also would not choose RapidSSL as the default paid certificate for a business-critical site when its own website recommends upgrading to GeoTrust for stronger support, management tools, and warranties. Acquired product brands are evaluated by their current issuing CA, not by their old owner.
SSL certificate brands and sellers to avoid
Outdated certificate recommendations are irresponsible
Entrust no longer operates the public certificate business it sold to Sectigo in 2025, while Symantec's Website Security and public PKI business has belonged to DigiCert since 2017. Their names may still appear in old product catalogs, reseller listings, and comparison articles, but a historical brand name is not the same thing as the current certificate issuer.
A website that continues to recommend an "Entrust certificate" or "Symantec certificate" as though the original company still independently issues and supports it, without identifying the current issuing CA, trust chain, migration status, and support owner, is giving readers outdated and irresponsible advice. A responsible recommendation must explain what certificate and support relationship the buyer will actually receive today.

1. Not recommended for new affected TLS deployments
Entrust
Scope: Entrust and AffirmTrust legacy public TLS chains
Chrome distrust is the reason for caution
Google said publicly disclosed incident reports showed a pattern of concerning behavior, compliance failures, unmet improvement commitments, and insufficient measurable progress. Chrome 131 began blocking affected certificates whose earliest Signed Certificate Timestamp is after November 11, 2024.
Sectigo announced its purchase of Entrust's public certificate business in January 2025. That acquisition is not the reason for this recommendation; the Chrome root-program action is. A product still marketed with the Entrust name should be checked for its actual issuer, root chain, and transition terms before purchase.
2. Retired certificate infrastructure
Symantec
Scope: legacy Symantec-issued public TLS certificates only
Avoid the retired PKI, not today's DigiCert operation
Google documented numerous certificates issued by the former Symantec PKI that did not comply with industry baseline requirements. Chrome ultimately removed trust in the old infrastructure. DigiCert acquired the Website Security and PKI business and moved current operations to DigiCert infrastructure.
This distinction matters: current GeoTrust, Thawte, and RapidSSL products issued through DigiCert are not automatically unsafe because of their previous ownership. What should be avoided is any obsolete listing that claims to use the retired Symantec issuing infrastructure.

3. Purchase channel risk
Trustico
Scope: certificate reseller and private-key handling
A seller risk rather than a CA-brand risk
Trustico is a reseller, not the final certificate authority. In 2018, an incident involving approximately 23,000 private keys led DigiCert to revoke the affected certificates. Subscriber private keys should not be retained or transmitted by a seller in normal certificate issuance.
Because this was a serious key-handling event, we would not recommend the channel without current independent evidence explaining how key generation, storage, deletion, and audit controls now work. The underlying CA product should be evaluated separately from the reseller.
4. Not recommended for business-critical use
RapidSSL
Scope: paid DV and Wildcard certificate selection
Its official upgrade path points customers to GeoTrust
RapidSSL says its certificates remain secure, browser-trusted, and quickly issued, so this recommendation is not based on a browser distrust event. However, the title and description of the official RapidSSL homepage tell customers to upgrade their TLS/SSL and Wildcard certificates to GeoTrust for greater warranties, tools, support, and security.
The official comparison gives RapidSSL DV and RapidSSL Wildcard a $10,000 warranty, compared with $500,000 for GeoTrust DV, and marks management tools and support only for GeoTrust. The same page promotes 24/7 technical support, warranties of up to $1.5 million, and DigiCert CertCentral as reasons to upgrade.
When a brand's own website directs customers to another product for the operational features that matter to a business, we do not recommend RapidSSL as the default paid choice for commercial websites, ecommerce, or important production services. For a simple DV-only use case with no support or management requirements, buyers should compare its total cost with current automated and free alternatives before paying for it.
Brands we do not reject solely because they were acquired
Certificate businesses change owners frequently. These names need clear ownership labels, but an acquisition alone is not a security failure.
| Brand name | Current certificate owner | How to evaluate it |
|---|---|---|
| GeoTrust, Thawte | DigiCert | Check the current DigiCert chain, price, validation level, and support |
| Comodo, PositiveSSL, InstantSSL, EssentialSSL, EnterpriseSSL | Sectigo | Treat these as Sectigo product lines rather than independent CAs |
| SecureTrust / VikingCloud certificate business | SSL.com | Verify the migrated SSL.com account, issuer, and renewal path |
What to choose instead
Start with an actively trusted issuing CA and then compare validation level, domain coverage, renewal pricing, support, key storage, and automation. DigiCert, Sectigo, GlobalSign, SSL.com, and Let's Encrypt all serve different use cases; inclusion here is not a blanket endorsement of every product or reseller.
Frequently asked questions
Are all Entrust certificates untrusted?
No. Chrome's action is based on the certificate's trust chain and earliest Signed Certificate Timestamp. The default distrust applies to affected Entrust and AffirmTrust roots for certificates with an earliest SCT after November 11, 2024. Buyers should verify the actual issuer and chain instead of relying only on the product name.
Are GeoTrust and Thawte unsafe in 2026?
Not solely because they were formerly part of Symantec. Their current public certificate operations are supported by DigiCert. The old Symantec infrastructure was distrusted, but that does not automatically make certificates issued from DigiCert's current trusted infrastructure unsafe.
Is RapidSSL technically untrusted?
No. RapidSSL says its certificates remain browser-trusted and secure. Our concern is product value and operational fit: its own website recommends upgrading to GeoTrust for larger warranties, support, management tools, and CertCentral. That makes RapidSSL difficult to recommend as the default paid option for a business or important production service.
Does an acquisition make an SSL brand untrustworthy?
No. An acquisition is an ownership and support change, not evidence of a security failure. The important checks are the current issuing CA, browser trust, certificate policy, validation process, support path, and renewal terms.
Sources and further reading
- 1.Google: Sustaining Digital Certificate Security - Entrust Certificate DistrustAccessed August 5, 2026
- 2.Sectigo acquires Entrust's public certificate businessAccessed August 5, 2026
- 3.Google: Chrome's Plan to Distrust Symantec CertificatesAccessed August 5, 2026
- 4.DigiCert welcomes Symantec Website Security customers and productsAccessed August 5, 2026
- 5.RapidSSL official site: upgrade TLS/SSL and Wildcard certificates to GeoTrustAccessed August 5, 2026
- 6.The Register: Trustico private-key and certificate revocation incidentAccessed August 5, 2026
- 7.Sectigo: Comodo CA Is Now SectigoAccessed August 5, 2026
- 8.SSL.com: VikingCloud certificate transitionAccessed August 5, 2026
This article is an editorial risk review, not a claim that every certificate bearing a historical brand name is technically invalid. Browser trust and ownership can change; verify the current issuer and chain at purchase time.