I manage SSL operations at Google and, as far I can tell, this is all nonsense.<p>It's too long to deal with point-by-point, but I can do a few:<p>* It's not odd that a cert for * .google.com would be served for google.fr. Check the SANs.<p>* Google does not use EV certificates.<p>* Google's frontends have many IP addresses. Seeing differences at different times and places is normal.<p>* Our leaf certificates really are issued for only a few months.<p>* We will be off SHA-1 by the end of the year but, at the time the article was written, one certainly could have received a SHA-1 signed certificate from us.<p>* <a href="http://clients1.google.com/ocsp" rel="nofollow">http://clients1.google.com/ocsp</a> is our OCSP responder and, yes, you'll get 404 unless you send a correct OCSP request with a Host header.