TL;DR: Mozilla plans to warn on SHA-1 certificates in Firefox and eventually reject them outright, aligning with Microsoft and Google’s earlier deprecation timeline and accelerating the move away from legacy certificate trust, according to DigiCert. The practical lesson is that certificate lifecycle management must surface weak algorithms before browsers do, or user-visible trust failures will arrive first.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “Mozilla to Add SHA-1 Security Warnings”.
Key questions
Q: What breaks in practice when SHA-1 certificates are still in use after deprecation dates?
A: When SHA-1 remains in service past deprecation deadlines, browsers may stop treating sites as fully trustworthy and users can see warnings or blocked access.
Q: Why do browsers deprecate weak certificate algorithms before all systems move?
A: Browsers have to protect users at ecosystem scale, so they cannot wait for every organisation to remediate on its own schedule.
Q: How should teams prioritise certificate replacement when SHA-1 is still present?
A: Start with externally trusted services, then move to internal systems that support authentication, automation, or workload identity.
Practitioner guidance
- Inventory all SHA-1 certificates Identify every certificate, intermediate, and trust chain that still depends on SHA-1 across web, service, and internal environments.
- Prioritise external-facing services first Replace SHA-1 certificates on internet-facing applications before browser enforcement makes the problem visible to users.
- Align renewal work to browser policy Map certificate replacement timelines against known browser deprecation milestones so renewal cycles do not extend beyond the point where trust warnings begin to break access.
Bottom line: SHA-1 deprecation shows that certificate trust is governed by ecosystem policy as much as by cryptographic validity.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Weak algorithm trust is now a lifecycle governance issue, not a cryptography footnote. Once browsers begin warning on SHA-1, the control failure is no longer theoretical. Organisations that only watch expiration dates are governing the wrong variable. The practitioner conclusion is that algorithm strength has to be managed as part of certificate ownership and renewal policy.
A question worth separating out:
Q: How do certificate teams know whether trust deprecation is being managed well?
A: They should be able to show a complete inventory of certificates by algorithm, owner, and replacement status, plus a remediation plan aligned to browser timelines. If weak algorithms still surface late in renewal cycles, trust deprecation is not under control.
👉 Read our full editorial: Mozilla’s SHA-1 warnings show how certificate trust deprecates