TLS Standards
September 15, 2026: the remaining SHA-1 use in public Web PKI reaches its sunset
The CA/Browser Forum sunset for remaining SHA-1 certificate and CRL usage in public Web PKI is 15 September 2026.
sslcertificates.io Editorial · Published 2026-09-21 · Fact-checked 2026-09-21 · Topic window 2026-09-15
15 September 2026 is the CA/Browser Forum sunset for remaining SHA-1 use in public Web PKI (certificates and CRLs in the scopes the Baseline Requirements still called out). If you still operate a public SHA-1 artifact, this is not a styling issue.
Most modern public leaves have been SHA-256 for years. The leftovers are old CRLs, forgotten intermediates, and internal tools that still fetch SHA-1 objects “because the script worked.”
Action: inventory signatures, not only notAfter. Do not confuse this sunset with the 200/100/47-day validity schedule — they are different controls.
Source: CA/Browser Forum TLS Baseline Requirements. Fact-checked 21 September 2026.
Sources
Related
Automate the lifecycle this article describes
Inventory, renewals and verified deployment are product surfaces — not adjectives.