The Chrome 134 beta (and Firefox parallel) now render certificate lifetime in the address bar with a subtle amber indicator for certs expiring within 30 days. This is a UX shift, not a security model change.
Impact on client trust:
1. Users conditioned to green=good may perceive amber as warning
2. Shared hosting customers on auto-renew may still see amber during renewal windows
3. EV certs with 90-day lifetimes (trending) will show amber 1/3 of their life
Pro tip: Test your own sites in Chrome Canary before clients notice.
Heads up: The indicator triggers on notAfter field only, not installation date. A cert installed yesterday with 14 days remaining shows amber immediately.
I have been running Canary since February 10 and documented twelve sites showing amber. Eleven were expected (short-lived certs). One was a surprise.
Steps to verify your own exposure:
1. Download Chrome Canary or Firefox Nightly
2. Navigate to your HTTPS properties
3. Check address bar right of lock icon
4. Click certificate → view validity period
Who else is testing this? I am particularly interested in behavior with mixed content and subresource integrity failures.